Gedantar – a new version of Unlock92 ransomware

Gedantar is a ransomware[1] virus that is an updated version of the Unlock92 virus. Malware spreads via malicious spam emails and is executed from Gedantar.exe file. Then it starts data encryption using RSA-2048[2] cryptography and renames files using this pattern: <filename>_<8-rand-chars>.<ext>.
| Summary | |
|---|---|
| Name | Gedantar |
| Type | Ransomware |
| Danger level | High. Makes system changes and encrypts files |
| Cryptography | RSA-2048 |
| File extension | <filename>_<8-rand-chars>.<ext> |
| Ransom note | <20-rand-chars>.jpg |
| Distribution methods | Malspam, malvertising, bogus software updates and downloads |
| To uninstallGedantar, install FortectIntego and run a full system scan | |
Gedantar ransomware aims at popular files in order to make more damage to the users. Hence, after the malware attack, Microsoft Office documents, audio, video or image files, archives, and databases are corrupted.
Following data encryption, malware drops a ransom note called <20-rand-chars>.jpg where cyber criminals ask to send an email to unlckr@protonmail.com or contact them via TOR network if they won’t respond in 24 hours time. The ransom note is written in Russian language, so it is expected to target Russian-speaking computer users[3] the most.
Additionally, Gedantar virus changes affected computer’s desktop where authors of malware deliver the same threatening message:
Ваши файльi были зашифрованы с помощью алгоритма Г5А-2048 Если вы хотите их вернуть то отправьте один из зашифрованных файлов на е-mai1: unIckr@protonmail.com
Если вы не получили ответ в течение суток то скачайте с сайта л.огрго]ес.согл браузер ТОК и с его помощью зайдите на сайт http://n3r2kuzhw2h7x6j5.onion – там будет указан действующий и почтовый ящик.
Попытки самостоятельного восстановления файлов могут безвозвратно их испортить!
However, security specialists do not recommend following the instructions and having business with cybercriminals. They will demand to pay a ransom in cryptocurrency in order to get access to the files. But transferring the money does not guarantee that you will be allowed to decrypt files.
Criminals might threaten into paying more money by telling to delete data, or they might disappear as soon as your payment is transferred to their virtual wallet. Instead of that, you should remove Gedantar from the computer with reputable anti-malware software, like FortectIntego.
We want to discourage you from manual Gedantar removal which might end up with even bigger failure. Ransomware is a complex cyber threat that contains a bunch of malicious files. Additionally, it might affect legit system processes and fixing this damage without professional tools is nearly impossible.
However, in some cases ransomware might prevent installation of security software or block attempts to run it. However, Gedantar can be disabled as well as any other file-encrypting virus. To run automatic elimination, you need to reboot the system to Safe Mode with Networking.

Strategies used for ransomware delivery and installation
Ransomware-type cyber threats typically spread via malicious spam emails that include an obfuscated attachment. As soon as a user is tricked to open Word, PDF or ZIP file, malware payload is downloaded and executed on the computer. Therefore, it’s important to check the credibility of each received email before opening an attached file.
Furthermore, ransomware can sneak into the device after clicking on a malicious ad, downloading bogus software or its update. However, in some cases, malware does not require user’s participation and can sneak into the system with the help of exploit kits.
Hence, to avoid infiltration of crypto-malware, you should not only be careful with your clicks and downloads but keep your programs and operating system updated too. Finally, obtaining reputable antivirus and creating backups are important ransomware precautions as well.
Delete Gedantar ransomware virus and try to recover data
Gedantar removal requires rebooting the system to Safe Mode with Networking, downloading malware removal software and running a full system scan. We suggest using one of these tools for virus elimination: FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
As we have mentioned in the beginning, the virus might be capable of blocking security software to stay longer on the machine. However, if you follow our prepared instructions below, you will be able to get rid of the virus easily.
As soon as you remove Gedantar from the machine, you can use backups or try alternative recovery methods. However, third-party tools might not be as effective as you would expect. Though, you should still try them out.
Did this guide help?
Be the first to comment