Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2017

How to remove NxRansomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

NxRansomware virus is back with malicious intentions

The illustration of NxRansomware ransom note

NxRansomware was first developed as an open-source ransomware project by G.B. Moralez. It was freely accessible on GitHub in 2016 for research purposes[1]. The developer explicitly prohibited people from exploiting this file-encrypting virus for malevolent purposes. However, researchers have spotted a malicious version of this malware spreading as a GoogleUpdate1.exe file on the cyberspace in December, 2017. 

The NxRansomware uses an AES and RSA encryption ciphers which are widely used by ransomware developers. Files strengthen by these algorithms are nearly impossible to break without a specific decryption key, and criminals demand to pay $300 in Bitcoins for it.

The ransom note of NxRansomware is delivered in I'll Make You Cry 😀 😀 window and states the following:

What has happened To your Computer?

Your computer has been encrypted
It's better to pay ransom
Or we are going to make you feel sorry
Then nobody will help you out

According to the researcher, the virus is extremely dangerous and cause tremendous damage. NxRansomware is written in .Net Framework + C&C System, and is called as the next generation of ransomware. One of the objectives of this ransomware is to prove that it is possible to write a file-encrypting virus using the .Net Framework.

Apart from that, NxRansomware malware was initially created in order to understand ransomware operation principles. The researcher aimed to build a modern Command and Control (C&C) system and a safe communication channel between the virus and C&C server without using SSL certificates[2].

NxRansomware virus

Fortunately, the researcher of this next generation crypto-malware has shared the open-source code with the developers of security software so they could prepare for the possible threats caused by the evolving ransomware projects. Thus, NxRansomware removal is not that complicated with the help of the antivirus tool.

NxRansomware virus attacks the most popular file types such as MS Office and OpenOffice documents, PDF and text files, various image, audio, video and other multimedia files, databases, archives, and more. It seems that G. B. Moralez managed to develop a hazardous cyber infection and now criminals take advantage of the scientific invention to obtain illegal profits.

However, you can remove NxRansomware with FortectIntego or another professional security software. It is still necessary to make sure that it is powerful enough to deal with ransomware attacks. Note that you should never pay the ransom since there are alternative ways how you can recover encrypted files.

Ransomware spreads as a fake Google Update file

Like most of the ransomware-type viruses, this one is distributed as an obfuscate Google Update file. Note that there numerous other deceptive software upgrades which hold the executables of the malware inside as well. Hackers might either sent them via spam emails or put in peer-to-peer file sharing networks. 

Ransomware can be placed as an attachment in email letter which urges to open it. Be aware that usually, criminals imitate famous companies and brands to trick gullible people into believing the legitimacy of the message. Likewise, once the attachment is opened, it drops the .exe file and infects the computer with ransomware.

Also, peer-to-peer networks are full of fake software updates which are malicious. Since crooks are able to create ransomware payloads which mimic the appearance of legitimate programs, most people get deluded and manually infiltrate file-encrypting viruses on the systems.

Likewise, you should pay close attention to the files you attempt to open or download. Never get software from unauthorized developers in highly suspicious pages. Additionally, in case of a dubious email from the well-known company — contact the firm yourself and validate the email.

The fastest way to finish NxRansomware elimination

Since this particular ransomware is highly sophisticated, it is impossible to eliminate it manually. To remove NxRansomware, you must employ a professional security software which would be able to detect this next generation computer threat. We suggest using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. LosVirus.es[3] experts guarantee that they are reliable and trustworthy.

Start NxRansomware removal by:

  1. Reboot your computer into Safe Mode;
  2. Download the security software;
  3. Scan your PC files thoroughly.

Did this guide help?

3 comments

  1. Hendron

    I hope hackers wont decide to use this code...

  2. Grant

    This looks like a serious piece of malware. Researcher did an excellent job!

  3. dot

    Well, its been a year since this code has been posted on Github, and I havent heard about virus based on NxRansomware. I bet its too difficult for the hackers to copy it.

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.