How to Remove .CoV extension virus Ransomware?

What is .CoV extension virus?

.CoV Extension Virus
.CoV Extension Virus

.CoV extension virus is identified as severe malicious computer threat created to encrypt users’ data and files to make money for hacker. It gets in the PC for robbing money from users. As long as it comes in, all the documents and files will be in danger. It will add a malicious extension to each of your files and then you cannot open any of them at all.

.CoV extension virus will display a ransom note to tell you how to buy its decryption key. At that moment, it seems that only in this way can you get your files back. However, we don’t recommend you to buy this key because you may scammed. Many ransomware cases have proved that victims should never trust the hacker, they just took victims’ money and did not offer real decryptor. So we believe that what you should do is to get .CoV extension virus removed. And then seek help from legitimate data recovery company.


.CoV extension virus Removal Process

Step 1 – Uninstall malicious programs from Control Panel.

Ransomware may infect your system after you install some malicious programs. To avoid being re-infected, first you should uninstall malicious programs from your computer:

  • 1. Type “control panel” in the Search Box of Taskbar and select Control Panel
  • 2. Click Uninstall a program:
  • 3. Select programs which may be related with .CoV extension virus and click Uninstall:

how to uninstall .CoV extension virus

how to uninstall .CoV extension virus

how to uninstall .CoV extension virus

If you are unable to confirm which programs are malicious, we recommend downloading SpyHunter anti-malware to fully scan infected PC and find out all malicious programs:

   ↓ Download SpyHunter Anti-Malware

*offer – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.


Step 2  Find and remove malicious registry entries of .CoV extension virus or malicious program.

NoteIn case any suspicious files or unwanted program cannot be removed manually, it is often caused by malicious registry files. Therefore, to get rid of such stubborn items, you need to find and remove malicious files in the Registry Editor. Check the steps below:

1.Type “Registry Editor” in the Search Box of Taskbar and select Registry Editor:

get rid of .CoV extension virus

2. Select Edit menu and click Find button >> Type virus’s name into it and click Find Next :

get rid of .CoV extension virus

get rid of .CoV extension virus

3. Right click on the malicious files and click Delete (Do Not Click Delete unless you can confirm that the files is related with malware):

delete .CoV extension virus manually

If you are not able to confirm which registry files are malicious, do not take risk to delete any file, or your system may be damaged.

To avoid the risk, we recommend downloading SpyHunter Anti-malware to scan infected PC and find out all malicious registry files:

   ↓ Download SpyHunter Anti-Malware

*offer – The SpyHunter Trial version includes, for one device, a one-time 7-day Trial period for SpyHunter 5 Pro (Windows) or SpyHunter for Mac. Check Terms & Conditions of SpyHunter Free Trial , EULA and Privacy/Cookie Policy.


Step 3 Try to Recover Files with Legitimate Decryption Tools

Do not pay any money to recover your files. Even if you were to pay the ransom, there is no guarantee that you will regain access to your files.

The right way to recover your files is to count on legitimate decryption tools. Here are websites of popular cybersecurity community, you can try the decryption tools shared on their sites:

EmsiSoft Decryptor (Free)

EmsiSoft is working on developing free decryptor for the newest ransomware. Currently it provide user with over 40 free and useful decryptors. Please visit https://decrypter.emsisoft.com/ to find and download the decrypter you need.


Avast Free Ransomware Decryption Tools

Avast free ransomware decryption tools can help decrypt files encrypted by the many types of ransomware. Go to this Avast page and download the decyptors for the latest ransomware.


Kaspersky Free Ransomware Decryptors

Kaspersky russian lab now provides many free decryptors. Visit Kaspersky page here and have a try .


 NoMoreRansom Decryptors

The No More Ransom Project provides free decryption tools for lots of ransomware. Have a try on these tools at this page: https://www.nomoreransom.org/en/decryption-tools.html