Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2020

How to remove HOTEL ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

HOTEL ransomware – new file-locking virus from the Phobos family

HOTEL ransomware

HOTEL ransomware is a cryptovirus that demands a ransom for the files that it encrypts right after gaining access to a computer. This virus belongs to the Phobos ransomware family that has been delivering new versions like this one since October of 2017. All members of this lineage use the army-based AES[1] coding algorithm to lock all non-system files.

When HOTEL virus is encrypting all the personal files (documents, archives, pics, and so on) of the victim, it appends them with a three-part extension specific to its ransomware family – appointed user ID in brackets, criminal contact details in brackets, and the .HOTEL extension. When encryption and renaming are completed, all files are inaccessible.

After the first phase of .HOTEL file virus purpose is completed, two types of ransom notes are generated – one as a pop-up window (info.hta) and lots of text files (info.txt) that are placed in all affected folders that the victim would have to look hard to find them. With these notes, ransomware developers try to instruct and intimidate their victims into meeting their demands.

name HOTEL ransomware, .HOTEL file virus
type Ransomware
Family Phobos ransomware
Ransom note Two types of notes are created, a pop-up window and tons of text files in all affected folders
Appended file extension All non-system files receive a triple extension that consists of appointed user ID in brackets, contact details of the criminals in brackets, and .HOTEL appendix
criminal contact details Victims that are willing to establish contact will have to install instant messaging service ICQ on their computers or cell phones and reach out using @RIXOSHORSE
Virus removal Malware like ransomware should be removed with the help of a professional anti-malware app so all its allocated files are also deleted
System fix After HOTEL ransomware elimination it's highly recommended to run a full system scan with the FortectIntego system tune-up tool to find and fix any system changes that the virus might have done

With the pop-up ransom note (info.hta), the creators of Hotel ransomware inform their victims all of their files were locked because of a major IT security issue, and the only way to get their files back is by purchasing a decryption tool from the hackers. To do that, the victims would have to install an instant messaging service app called ICQ.

The cybercriminals provide detailed instructions on how to get that app either on a computer or a cell phone because that's the preferred communication method. To establish contact, the victims would have to send their appointed user ID to the developers of HOTEL ransomware to an ICQ ID @RIXOSHORSE (hxxps://icq.im/RIXOSHORSE).

Also, free decryption is offered to the users, meaning that they can send up to 5 files (no more than 4Mb in total) to be unlocked for free. This would establish some fake trust between the cybercriminals and the victims by proving that a necessary decryption tool exists. The last part is all about what not to do – not to rename files or try any third-party decryption software because that could lead to permanent data loss.

The ransom demanding note text files (info.txt) of HOTEL ransomware can be found in all folders that have encrypted files within them. These notes are a bit humorous but essentially contain the same message as the pop-up window (both notes are displayed at the end of this paragraph).

HOTEL ransomware virus

Paying the ransom to distributers of the HOTEL virus and regaining access to the encrypted files might seem like the easiest way out of this nightmare, but that's the worse thing any cyberattack victim could do. The FBI explains[2] that when such criminals get paid, it motivates them to expand their whole operations (attacks) and search for new ways to infect everyday computer users' devices with more sophisticated malware.

All malware should be dealt with immediately, and the best way to do it is by removing it with a powerful anti-virus app. We recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes to remove HOTEL ransomware from infected computers. If kept regularly updated, these apps could prevent malware from gaining access to the device.

When HOTEL ransomware removal is finished, experts[3] suggest performing a full system scan with a system tune-up tool like the FortectIntego app, to locate and restore any corrupted system files and settings that the cryptovirus has modified to help with its purpose.

Info.hta pop-up window ransom note contains this message:

ATTENTION!!!!
Unfortunately for you, a major IT security weakness left you open to attack, your files have been encrypted with ciphers more advanced than those used for diplomatic communications, you can spend days and months searching for a magical way to decrypt your files, but rest assured we are the only people who can help you recover your files, there is no free tool
If you want to restore them, install ICQ software on your PC hxxps://icq.com/windows/ or on your mobile phone search in Appstore / Google market “ICQ”
Write to our ICQ @RIXOSHORSE hxxps://icq.im/RIXOSHORSE
Write this ID in the title of your message –
Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 4Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

HOTEL ransomware creators send this message within the ransom note text file, titled info.txt:

If you are the IT manager and you are reading this, that means that you messed up, you were asleep at the wheel. Contact us and we can resolve this situation without major complication, if you are the owner of the company and you are reading this than the decision is yours, throw your hard drives in the trash or contact us and pay a nominal fee to recover your data, but know that your security practices have failed you and either way something needs to be done
If you want to restore them, install ICQ software on your PC hxxps://icq.com/windows/ or on your mobile phone search in Appstore / Google market “ICQ”
Write to our ICQ @RIXOSHORSE hxxps://icq.im/RIXOSHORSE
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.

Ransomware spreading techniques used by the hackers

Various malware is spread out throughout the world wide web, from annoying adware to dangerous ransomware like Lisp or Weui. Cybercriminals use various techniques to deliver their creations but the most common means by which ransomware is distributed are spam emails and file-sharing platforms.

HOTEL virus encrypted files

Everyday computer users should be aware of these methods and try and avoid downloading anything from torrent sites, including pirated software, game cracks, and alike. Hackers tend to disguise ransomware as some new soft crack or anything similar that would lure the unaware users.

Spam emails might contain either hyperlinks to malicious sites or infected attachments. Please be aware and open emails only from trusted senders. Never open any shady-looking hyperlinks and never download any email attachments without scanning them with anti-malware software first.

Removing HOTEL ransomware with the help of professional anti-malware tools

As we mentioned before, any malware should be removed immediately. Manual elimination of the HOTEL virus could be a tall task even for experienced computer users, so we recommend leaving this dirty business to the professionals.

Remove HOTEL ransomware with reliable anti-malware apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, so you can be sure that all its components are eradicated. A trustworthy anti-virus program is a must these days, for the reason that it could protect computer systems from virus infiltration in the first place.

Ransomware is known for making modifications in the system registry and other core system settings, so when HOTEL ransomware removal is completed we suggest using the FortectIntego tool to undo any of the changes that the virus might have done.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.