Ordinal ransomware scares users with military-grade encryption

The ordinal virus is the name of a new HiddenTear-based crypto-virus. At the moment, it is identified by multiple security applications as Generic.Ransom.Hiddentear.A.F8C468CD, MSIL.Trojan-Ransom.Cryptear.Z, Ransom:MSIL/Ryzerlo.A. Currently, it appends .original file extension. It disguises under main.exe file, though the name of the executable may vary.
The malware does not exhibit any peculiar operation qualities. On another hand, it downloads a specific wallpaper from https://i.imgur.com[1]. The crypto-malware presents its basic GUI and READ Me To Get Your Files Back.txt which suggests following the instructions to unlock the data.
The infection alarms victims that their files have been encoded with AES-256 military-grade encryption. It asks to transfer 1 BTC to the indicated bitcoin address. In case victims run into technical difficulties, they can contact the perpetrators via TEST@protonmail.com. The ransom note alerts victims to transfer data within 7 days.
After the payment, Ordinal malware victims should supposedly get the decryption program and the key. If you haven’t backed up[2] your files in advance, you might consider paying the ransomware. There are very few chances that the perpetrators will play fairly and transfer unaffected or all files. It would be wiser to concentrate on Ordinal removal. FortectIntego or MalwarebytesMalwarebytes will help you get rid of the virus faster. Only when the virus is fully eradicated, proceed to data recovery instructions.
Ransomware promotion tips
Crypto-viruses are likely to be spread via these channels:
- spam emails
- trojans
- corrupted extensions and apps
Concerning the first distribution method, there have been no spotted emails delivering Ordinal ransomware. On the other hand, such possibility should not be overlooked. Especially be wary of emails which carry supposedly very important invoices or other attachments.
Beware of Ordinal hijack when downloading content from hardly secure domains. Recently, browser extensions have become a preferred tool among crypto-coin miner[3] developers, but malware creators as well. Now let us proceed to the last section which discusses the best options to remove Ordinal virus.
Eliminate computer threats
You might need to boot the system in Safe Mode to fully remove Ordinal virus. You might as perform the scan in the normal mode as well if the virus does not shut down the program. After you complete Ordinal removal, proceed to data recovery. You will find a few suggestions below. Though the ransomware note is written in English, residents of Spain[4] should be careful as well.
Was this guide helpful?
Be the first to comment