Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2018

How to remove Gedantar ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

Gedantar – a new version of Unlock92 ransomware

Gedantar ransomware drops a ransom note

Gedantar is a ransomware[1] virus that is an updated version of the Unlock92 virus. Malware spreads via malicious spam emails and is executed from Gedantar.exe file. Then it starts data encryption using RSA-2048[2] cryptography and renames files using this pattern: <filename>_<8-rand-chars>.<ext>.

Summary
Name Gedantar
Type Ransomware
Danger level High. Makes system changes and encrypts files
Cryptography RSA-2048
File extension <filename>_<8-rand-chars>.<ext>
Ransom note  <20-rand-chars>.jpg
Distribution methods Malspam, malvertising, bogus software updates and downloads
To uninstallGedantar, install FortectIntego and run a full system scan

Gedantar ransomware aims at popular files in order to make more damage to the users. Hence, after the malware attack, Microsoft Office documents, audio, video or image files, archives, and databases are corrupted.

Following data encryption, malware drops a ransom note called <20-rand-chars>.jpg where cyber criminals ask to send an email to unlckr@protonmail.com or contact them via TOR network if they won’t respond in 24 hours time. The ransom note is written in Russian language, so it is expected to target Russian-speaking computer users[3] the most.

Additionally, Gedantar virus changes affected computer’s desktop where authors of malware deliver the same threatening message:

Ваши файльi были зашифрованы с помощью алгоритма Г5А-2048 Если вы хотите их вернуть то отправьте один из зашифрованных файлов на е-mai1: unIckr@protonmail.com
Если вы не получили ответ в течение суток то скачайте с сайта л.огрго]ес.согл браузер ТОК и с его помощью зайдите на сайт http://n3r2kuzhw2h7x6j5.onion – там будет указан действующий и почтовый ящик.
Попытки самостоятельного восстановления файлов могут безвозвратно их испортить!

However, security specialists do not recommend following the instructions and having business with cybercriminals. They will demand to pay a ransom in cryptocurrency in order to get access to the files. But transferring the money does not guarantee that you will be allowed to decrypt files.


Criminals might threaten into paying more money by telling to delete data, or they might disappear as soon as your payment is transferred to their virtual wallet. Instead of that, you should remove Gedantar from the computer with reputable anti-malware software, like FortectIntego.

We want to discourage you from manual Gedantar removal which might end up with even bigger failure. Ransomware is a complex cyber threat that contains a bunch of malicious files. Additionally, it might affect legit system processes and fixing this damage without professional tools is nearly impossible.

However, in some cases ransomware might prevent installation of security software or block attempts to run it. However, Gedantar can be disabled as well as any other file-encrypting virus. To run automatic elimination, you need to reboot the system to Safe Mode with Networking.

Gedantar ransomware virus expample

Strategies used for ransomware delivery and installation

Ransomware-type cyber threats typically spread via malicious spam emails that include an obfuscated attachment. As soon as a user is tricked to open Word, PDF or ZIP file, malware payload is downloaded and executed on the computer. Therefore, it’s important to check the credibility of each received email before opening an attached file.

Furthermore, ransomware can sneak into the device after clicking on a malicious ad, downloading bogus software or its update. However, in some cases, malware does not require user’s participation and can sneak into the system with the help of exploit kits.

Hence, to avoid infiltration of crypto-malware, you should not only be careful with your clicks and downloads but keep your programs and operating system updated too. Finally, obtaining reputable antivirus and creating backups are important ransomware precautions as well.

Delete Gedantar ransomware virus and try to recover data

Gedantar removal requires rebooting the system to Safe Mode with Networking, downloading malware removal software and running a full system scan. We suggest using one of these tools for virus elimination: FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.

As we have mentioned in the beginning, the virus might be capable of blocking security software to stay longer on the machine. However, if you follow our prepared instructions below, you will be able to get rid of the virus easily.

As soon as you remove Gedantar from the machine, you can use backups or try alternative recovery methods. However, third-party tools might not be as effective as you would expect. Though, you should still try them out.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.