Worm ransomware is a file locking virus that uses extortion tactics after locking all the data on the host machine

Worm ransomware is a new variant of Paradise virus – a relatively old strain that is also used as a Ransomware-as-a-Service (RaaS). This version was analyzed by a security researcher Michael Gillespie at the end of October 2019.[1] Just like its predecessors, malware is designed for money extortion after locking all personal files on the infected machine.
Worm ransomware enters computers by using one of the multiple distribution methods (such as spam email attachments, software vulnerabilities,[2] fake updates, software cracks, etc.) and starts a scan that looks for pictures, videos, documents, databases, and other personal data. After that, Worm virus encrypts each of the files by using RSA cipher and marks them with [id]-[victim ID].[corpseworm@protonmail.com].worm appendix.
Victims can also spot a ransom note #_ABOUT_YOUR_FILES_#$=$$.html, which is dropped on the desktop and all the affected folders. The content of the message states that users have to pay a ransom in Bitcoins if they want their data back. While there is no Worm ransomware decryptor developed yet, victims are advised staying away from file locking malware developers.
| Name | Worm ransowmare |
| Type | Cryptovirus |
| Malware family | Worm virus is a variant of Paradise ransomware |
| File extension | All pictures, videos, photos, music and other files are appended with .worm extension. An example of an encrypted file: picture.jpg[id-GYMXkaDq].[corpseworm@protonmail.com].worm |
| Ransom note | #_ABOUT_YOUR_FILES_#$=$$.html ransom note is dropped on the desktop and all the folders where the locked files are located |
| Contact | corpseworm@protonmail.com or telegram @helprestore |
| Detection |
44 engines detect the dropper as malicious on Virus Total (10/30/2019) |
| Infiltration means | Hackers typically use several distribution methods, including spam emails, exploits, software cracks, repacked installers, fake updates, unprotected RDP connections, etc. |
| File decryption | Only possible via backups or third-party recovery software |
| Removal | Scan your machine in Safe Mode with reputable anti-malware software in order to terminate all malicious entries made by malware |
| Recovery | To fix virus damage and avoid possible reinstallation of Windows OS, use FortectIntego to recover from ransomware infection |
As soon as users interact with a malicious dropper if Worm ransomware, several files are dropped into %AppData%, %UserProfile%, and Desktop folders. From there, several processes are launched, the Windows registry is modified, and all automated Windows backups are deleted with the help of vssadmin.exe Delete Shadows /All /Quiet command. The changes to the system are made for the file encryption process to be performed uninterrupted and to complicate encrypted file recovery after Worm ransomware removal.
Soon after that, the Worm virus scans the computer's hard drive and all the connected drives, looking for files to encrypt. In most of the cases, the most commonly-used file types are targeted, such as .pdf, MS Office files, videos, and others. Users then cannot open the data anymore, although system files are spared for malware to operate (the goal or Worm ransomware authors is not to corrupt victims' machines but rather lock data so that they would pay the ransom). The ransom note, which is dropped into several locations on the computer, states the following:
All your files was encrypted!
«Paradise» R Team!
Ur unique ID
GYMXkaDq
Your personal KEYYOUR FILES HAS BEEN LOCKED!
All your personal data that was stored on this computer have been crypted due a security problem.
To restore them, write to us by е-mail,.
You have to pay in Bitcoins.
After payment we will send you the special decryption tool that will restore all your files.
NEED PROOF?
Before payment you can send us 1-3 files , and we decrypt it for free.
File size should not exceed 1MB.
Please note that files must NOT contain valuable information.
HOW TO PAY
We accept payments in bitcoins, but you do not need to be able to use bitcoins.
You do not need a bitcoin account.
I will explain how you can pay using ANY currency in any way convenient to you.
Our mails
Mail:
corpseworm@protonmail.com
or
Mail:
telegram @helprestore
Caution!
Do not rename files
Do not try to restore your data using third-party software, it may cause permanent data loss(If you do not believe us, and still try to – make copies of all files so that we can help you if third-party software harms them)
As evidence, we can for free restore one file
Decoders of other users is not suitable to restore your files – encryption key is created on your computer when the program is launched – it is unique.
Even though the attackers claim that no other decryption method is possible, you should not listen to them. It is in their best interest for you to pay the ransom, that is why they are even providing a test decryption service – they are trying to create a false sense of security. However, please remember that they are cybercriminals and might not send you Worm ransomware decryptor as promised.

Instead, remove Worm ransomware and try alternative file recovery methods we provide at the bottom section of this post. While there is no decryptor currently available, you might be successful in restoring at least some of your files using recovery software or other methods. However, remember that you have to terminate the infection first with anti-malware. After that, we also advise you use FortectIntego to fix crippled Windows system files.
Protect your machine from future ransomware infections
Paradise ransomware is one of many file-locking virus families that are dominant currently. For example, Djvu, Phobos, Scarab, and many others are lurking in the wild, actively trying to infect unsuspecting users. The truth is, most of the infections with ransomware happen due to negligence from users' side – they are not careful enough when browsing the internet, updating their software, opening emails, and doing other daily tasks.
The main precautionary measure against ransomware and other malware is caution, as most distribution methods rely on some sort of social engineering.[3] Here are a few tips from security experts from novirus.uk[4] – these will help you to keep your computer away from ransomware:
- Update your OS and all the installed software regularly – do not postpone the updates infinitely;
- Equip your computer with anti-malware and anti-virus software with real-time protection feature;
- Never use a default RDP port and disable the connection as soon as it is not required anymore;
- Treat each unsolicited email as a threat – never open attachments that ask you to enable macro function;
- Enable ad-blocker, firewall, and other additional protection features;
- Use robust passwords for RDP and all other accounts or employ a password manager;
- Watch out for website spoofing: making a copy of a legitimate website is easy, and crooks often do so in order to make users download a malicious executable disguised a legitimate program;
- Never visit torrent or warez sites that host pirated applications or software cracks/keygens.
Be aware that no protection means can guarantee full protection, so you should always ensure that personal files are stored on a remote server or external drive as a backup.

Remove Worm ransomware and then attempt data recovery using third-party tools or other methods
Be aware that, as long as Worm virus is present on your machine, all the incoming files and those on external storage will be encrypted as well. Therefore, make sure you never connect USB Flash drives, external HDDs, or other devices to your computer until you remove Worm ransomware. Unfortunately, the process might sometimes be a little bit complicated, as malware is often set to intercept anti-virus software to prevent its elimination.
However, you can bypass those measures by accessing Safe Mode with Networking – check out the instructions on how to enter it below. Once there, employ a powerful anti-malware program and thoroughly scan the infected computer – successful Worm ransomware removal is almost guaranteed this way. After that, you should employ PC repair so software FortectIntego to fix the damage done by the virus. Finally, you can attempt to recover data as per methods described below. In unsuccessful, make a copy of all compromised files and wait till security experts deploy a working Worm ransomware decryptor.
Did this guide help?
Be the first to comment