Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2017

How to remove Ordinal ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

Ordinal ransomware scares users with military-grade encryption

The picture illustrating Ordinal ransomware

The ordinal virus is the name of a new HiddenTear-based crypto-virus. At the moment, it is identified by multiple security applications as Generic.Ransom.Hiddentear.A.F8C468CD, MSIL.Trojan-Ransom.Cryptear.Z, Ransom:MSIL/Ryzerlo.A. Currently, it appends .original file extension. It disguises under main.exe file, though the name of the executable may vary.

The malware does not exhibit any peculiar operation qualities. On another hand, it downloads a specific wallpaper from https://i.imgur.com[1]. The crypto-malware presents its basic GUI and READ Me To Get Your Files Back.txt which suggests following the instructions to unlock the data.

The infection alarms victims that their files have been encoded with AES-256 military-grade encryption. It asks to transfer 1 BTC to the indicated bitcoin address. In case victims run into technical difficulties, they can contact the perpetrators via TEST@protonmail.com. The ransom note alerts victims to transfer data within 7 days.

After the payment, Ordinal malware victims should supposedly get the decryption program and the key. If you haven’t backed up[2] your files in advance, you might consider paying the ransomware. There are very few chances that the perpetrators will play fairly and transfer unaffected or all files. It would be wiser to concentrate on Ordinal removal. FortectIntego or MalwarebytesMalwarebytes will help you get rid of the virus faster. Only when the virus is fully eradicated, proceed to data recovery instructions.

Ransomware promotion tips

Crypto-viruses are likely to be spread via these channels:

  • spam emails
  • trojans
  • corrupted extensions and apps

Concerning the first distribution method, there have been no spotted emails delivering Ordinal ransomware. On the other hand, such possibility should not be overlooked. Especially be wary of emails which carry supposedly very important invoices or other attachments.

Beware of Ordinal hijack when downloading content from hardly secure domains. Recently, browser extensions have become a preferred tool among crypto-coin miner[3] developers, but malware creators as well. Now let us proceed to the last section which discusses the best options to remove Ordinal virus.The image displaying alternative Ordinal virus names

Eliminate computer threats

You might need to boot the system in Safe Mode to fully remove Ordinal virus. You might as perform the scan in the normal mode as well if the virus does not shut down the program. After you complete Ordinal removal, proceed to data recovery. You will find a few suggestions below. Though the ransomware note is written in English, residents of Spain[4] should be careful as well.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.