Christmas ransomware becomes active just before the feast

Christmas ransomware (also known as MerryChristmas ransomware, .Merry file extension virus, MRCR1 or Merry X-Mas! ransomware) is a file-encrypting virus that is more a joke than a serious virus. However, if you are not a tech-savvy person, Christmas virus may ruin your holiday mood by encrypting your files and asking $100 in bitcoin to get them back.
Christmas virus[1] encrypts files with an ordinary cipher[2] that blocks the victim from opening his/hers files. However, encrypted files are distorted in a way that no one can restore them without having a special decryption key. To the damaged files, the virus also appends complementary file extensions, such as:
- .PEGS1,
- .RARE1,
- .MRCR1,
- .RMCM1,
- .MERRY.
Following data encryption, Merry Christmas ransomware leaves a ransom note called “YOUR_FILES_ARE_DEAD.HTA”. The message opens in the web browser and includes information that users have to purchase a specific decryption key to recover their files:
ALL SERVER DATA ENCRYPTED! [or] ALL COMPUTER DATA ENCRYPTED
03 days 22:55:29 0149
TIME AFTER ALL FILES WILL BE DELETED
YOUR ID [removed]
Merry X-Mas!
NOW YOU NEED TO PAY TO RECOVER YOUR DATA
AFTER MONEY TRANSFER YOU WILL RECIEVE THE DECRYPTOR
CONTACTS
TELEGRAM @comodosecurity
EMAIL comodosec@yandex.com
The latest virus version uses a simplified note:
Your Files are Encrypted
Send 100 $ in Bitcoin to Decrypt Your Files
Merry Christmas
In the first example, you can see that the Christmas ransomware does not provide the exact price of the decryption software. It makes us think that virus’ authors ask for different sums of money from individual victims.
What is more, it is very likely that malware is a software developed by Globe[3] virus’ authors, because it provides the same Telegram messenger contact for victims who want to get in touch with the virus’ authors – @comodosecurity. It’s interesting that criminals use a name of a cyber security company, which is not related to this ransomware virus at all.
Paying the ransom for cybercriminals is always not recommended and risky method to recover encrypted data. But when dealing with this ransomware, transferring bitcoins is unnecessary. Security specialists have already cracked malware’s code and created a decryption tool. The Merry Christmas virus decrypter is safe and free to use.
However, before data recovery, you must eliminate malware from the system. At the end of the article, you will find detailed instructions how to remove Christmas virus from the computer using FortectIntego or other reputable malware removal programs.
Merry Christmas ransomware – the predecessor of Christmas virus
Security experts noticed that malware developers started preparing for the festive season early this year. A malicious Christmas.exe[4] file has been seen spreading on the web and bringing Christmas ransomware virus on the computer.
The recently discovered Christmas ransomware is still under investigation. However, it can use a strong encryption algorithm to take various image, audio, video, backups, databases or configuration files to hostage. Following successful data encryption, malware delivers a creepy-looking ransom note:
Christmas Ransomware
Your Files Have Been Encrypted!
To Get Your Files Back Pay 0.03 Worth of Bitcoin
to the Given Address Below!1FrlwkyAvCwxNLT49LkxQdJayLZMCXnZ67
Merry Christmas, He Knows If Your Bad!
Grammar is not the biggest strength of cybercriminals. However, transferring the ransom is not recommended. No one can assure that the virus is decryptable or crooks are willing to share the decryptor with you. Thus, you should remove Christmas ransomware from the computer using reputable antivirus.
As we have told before, Christmas virus is decryptable. Thus, it’s possible that this festive-themed malware will be soon cracked.

Merry X-mas ransomware can also steal sensitive information
Even though the holiday season is over, security experts report that ransomware is still active. On January 2017, the festive-themed ransomware has been noticed spreading DiamondFox malware.[5]
DiamondFox is mostly used for stealing passwords, credit card information and other sensitive data. Additionally, it might computers into DDoS bots or opening Remote Desktop (RDP) connections. Therefore, quick MerryChristmas removal is a must for avoiding privacy-related issues or money loss.
This version of the virus still spreads via malicious spam emails. However, it delivers a different-looking ransom note. Data recovery instructions and contact email address remained the same.
Numerous spam email campaigns spread malware executable
Despite the festive name, malware continues spreading after winter holidays. However, the virus continues spreading via email in the form of a deceptive file, which is named COMPLAINT.pdf.exe. Please pay attention that .pdf is not the real file extension – it is part of the filename, and .exe is the real file extension. Therefore, as soon as the victim opens this file, the virus gets activated and roots into the target computer system.
Additionally, the virus might arrive in a malicious document that contains scrambled text and asks the victim to enable Macros to view contents. Sadly, the scrambled text simply obfuscates a script that downloads and installs the ransomware as soon as the victim enables Macros function.
Therefore, security experts from No Virus[6] remind users to avoid suspicious emails that come from unknown people or companies, especially if you weren’t expecting to receive a letter from them. Cybercriminals use many different techniques[7] that help them to deceive naive victims, so try to keep up with the latest cybersecurity news if you do not want to become a victim of a ransomware attack.
Removal guide of the MerryChristmas ransomware virus
It’s important to remove Christmas ransomware (alternatively known as MerryChristmas ransomware) from the device in order to recover files safely using a decryption tool created by Emsisoft. Virus elimination requires obtaining reputable malware removal tool, such as FortectIntego or MalwarebytesMalwarebytes. However, you might encounter some obstacles.
The virus might prevent from installing, opening or running security software. Thus, you should reboot the PC to Safe Mode with Networking before you start automatic Christmas ransomware removal. You can find the explanation below:
Was this guide helpful?
3 comments