Remove .Bz Ransomware Virus (+File Recovery)

The encrypted files may not be the only damage done to you. parasite may still be hiding on your PC. To determine whether you've been infected with ransomware, we recommend downloading SpyHunter.

Download SpyHunter Anti-Malware

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

How irritating is this problem? (11 votes, average: 5.00)

This page aims to help you remove .Bz Ransomware Virus for free. Our instructions also cover how any .Bz file can be recovered.

The ransomware will encrypt your files and add .bz extension to them.


After the ransomware is done encrypting your files, it will leave a _readme.txt file with instructions.

.Bz is a Ransomware cryptovirus that exists to make money for its criminal creators via online blackmailing. This computer threat uses the help of a very complex file encryption algorithm to secretly lock the personal files of the victims, which are stored on the infected machine. After the malware renders the files inaccessible, it typically generates a ransom-demanding message which demands that a ransom is paid in exchange for the locked data’s decryption.

According to security experts, .Bz File Virus infects its victims with the help of different malicious transmitters such as deceitful online messages, different attachments, spam emails, fake ads, misleading links, torrents and illegal webpages. That’s why, even if you are careful and try to avoid sketchy web locations and shady web content, there is absolutely no guarantee that you won’t bump into a Ransomware carrier when you least expect it. Just one click on one of the numerous transmitters may be enough to secretly activate the harmful payload of this malware and, unfortunately, you may not even have a clue about what has happened until all the files that you store on your PC get locked by its complex encryption. Normally, threats like .Bz, .Fedasot.Sarut don’t show visible symptoms of their presence until they complete their criminal agenda and that’s why they are very difficult to detect and remove. The victims typically notice that they have been attacked by a Ransomware after it has completed the encryption process and has placed a ransom-demanding message on their screens.

The ransom payment and what to do about it

The criminals behind .Bz File Virus normally require that a payment in BitCoins is made to a given cryptocurrency wallet. They insist that the ransom gets transferred as soon as possible and threaten that if they don’t receive the money within a given deadline, they will destroy the decryption key that can recover the encrypted files and this way make the latter inaccessible forever. If you agree to pay, however, they promise to send you that special decryption key and let you reverse the complex encryption that has been applied to your data.

In case you think that this is the best and the fastest way to deal with .Bz Ransomware and regain the access to your valuable information, however, you should better think again. Trusting the criminals with your money not only directly sponsors their blackmail scheme but also it can in no way guarantee the future of your computer and your files. The crooks may simply disappear once they get the money and you may never hear from them again, let alone receive the decryption key they promise. Or, they may decide to take their blackmailing game to the next level by asking you to pay more money after you’ve made the first transfer. There is also a high possibility that they may trick you by sending you another well-camouflaged malware that can further damage your computer instead of a decryption solution for your files. That’s’ why it is really not a good idea to trust anything they promise or give you. Instead, we suggest you focus on removing the existing cryptovirus infection and then explore some alternative methods of recovering your information. If you don’t know where to start, you can run a deep scan with the professional .Bz removal tool on this page and take a look at the removal guide below and the file-recovery suggestions that we have listed there.


Name .Bz
Type Ransomware
Danger Level High (Ransomware is by far the worst threat you can encounter)
Symptoms Very few and unnoticeable ones before the ransom notification comes up.
Distribution Method From fake ads and fake system requests to spam emails and contagious web pages.
Data Recovery Tool Currently Unavailable
Detection Tool

Remove .Bz Ransomware Virus


Some of the steps will likely require you to exit the page. Bookmark it for later reference.

Reboot in Safe Mode (use this guide if you don’t know how to do it).



We get asked this a lot, so we are putting it here: Removing parasite manually may take hours and damage your system in the process. We recommend downloading SpyHunter to see if it can detect parasite files for you.

Press CTRL + SHIFT + ESC at the same time and go to the Processes Tab. Try to determine which processes are dangerous. 


Right click on each of them and select Open File Location. Then scan the files with our free online virus scanner:

Drag and Drop Files Here to Scan
Maximum file size: 128MB.

This scanner is free and will always remain free for our website's users. You can find its full-page version at: https://howtoremove.guide/online-virus-scanner/

Scan Results

Virus Scanner Result

After you open their folder, end the processes that are infected, then delete their folders. 

After you open their folder, end the processes that are infected, then delete their folders. 

Note: If you are sure something is part of the infection – delete it, even if the scanner doesn’t flag it. No anti-virus program can detect all infections.


Hold the Start Key and R –  copy + paste the following and click OK:

notepad %windir%/system32/Drivers/etc/hosts

A new file will open. If you are hacked, there will be a bunch of other IPs connected to you at the bottom. Look at the image below:

hosts_opt (1)

If there are suspicious IPs below “Localhost” – write to us in the comments.

Type msconfig in the search field and hit enter. A window will pop-up:


Go in Startup —> Uncheck entries that have “Unknown” as Manufacturer.

  • Please note that ransomware may even include a fake Manufacturer name to its process. Make sure you check out every process here is legitimate.


To remove parasite on your own, you may have to meddle with system files and registries. If you were to do this, you need to be extremely careful, because you may damage your system.

If you want to avoid the risk, we recommend downloading SpyHunter
a professional malware removal tool.

More information on SpyHunter, steps to uninstallEULAThreat Assessment Criteria, and Privacy Policy.

Type Regedit in the windows search field and press EnterOnce inside, press CTRL and F together and type the virus’s Name. 

Search for the ransomware  in your registries and delete the entries. Be extremely careful –  you can damage your system if you delete entries not related to the ransomware.

Type each of the following in the Windows Search Field:

  1. %AppData%
  2. %LocalAppData%
  3. %ProgramData%
  4. %WinDir%
  5. %Temp%

Delete everything in Temp. The rest just check out for anything recently added. Remember to leave us a comment if you run into any trouble!


How to Decrypt .Bz files

We have a comprehensive (and daily updated) guide on how to decrypt your files. Check it out here.

If the guide doesn’t help, download the anti-virus program we recommended or try our free online virus scanner. Also, you can always ask us in the comments for help!

Leave a Comment