Igal ransomware – a dangerous threat that encodes your pictures, documents, and other files

Igal ransomware is a data-locking computer infection that has the purpose of money extortion. It mostly spreads via software cracks and similar illegal executables designed for Windows operating systems. Once installed, the malware encrypts all personal files located on the system with the help of a sophisticated RSA[1] cipher, appending a .igal extension in the process.
While this process does not permanently corrupt data, it ultimately restricts access to it until a unique key – which is essentially a unique password – is applied. The particular virus is using an online ID method that ensures that each victim gets a uniquely formed key, so the file recovery becomes extremely difficult to achieve without the proper decryption tool.
Unfortunately, the only ones who have access to the required key are the cybercriminals behind the virus. In the ransom note _readme.txt, which is dropped as soon as data is locked, crooks explain that victims need to pay $980 or $490 worth of Bitcoins to retrieve a decryptor that can unlock files. They also leave contact details for negotiation purposes: helpmanager@mail.ch, restoremanager@airmail.cc.
While the attackers might be the only ones who can access the key you need, it might be possible to recover data without paying. Since .this virus belongs to the Djvu strain, alternative decryption tools developed by security experts are available, although they only work for a limited number of victims. There are also additional options to recover data without backups – we provide them below.
| Name | Igal ransomware |
|---|---|
| Type | Ransomware, data locking malware, cryptovirus |
| Malware family | Djvu/STOP |
| Encryption method | RSA – asymmetric encryption cipher |
| Distribution | Files attached to emails or data coming from pirating sites can lead to such infiltration of ransomware |
| File extension | .igal |
| Ransom note | _readme.txt is dropped into each of the affected folders and the desktop |
| Contact | helpmanager@mail.ch or restoremanager@airmail.cc |
| File Recovery | There is no guaranteed way to recover locked files without backups. Other options include paying cybercriminals (not recommended, might also lose the paid money), using Emisoft's decryptor (works for limited number of victims) or using third-party recovery software (low success chance) |
| Malware removal | The only secure way to delete the infection is by employing powerful anti-malware software, such as SpyHunterCombo Cleaner |
| System fix | In some cases, ransomware or other threats might seriously damage Windows systems to the point that the OS needs to be reinstalled. To avoid that, we recommend trying to fix the virus damage instead with tools like FortectIntego |
Ransomware is an especially lucrative illegal business that has been booming in recent years. While this malware variant was first spotted attacking victims in late December 2020, it is not the first version of the extensive Djvu family that has been terrorizing home users for several years now.
The virus, along with its previous variants, such as Omfl, Booa, or Igdm, is just a few of the 260+ that cybercriminals have released in the wild since 2017, making it one of the most prevalent ransomware strains that target regular computer users. Getting infected with one of these parasites can cause significant damage due to possible permanent data loss.
Before ransomware begins the encryption, it performs several changes within the Windows operating system for the process to be successful – here are a few examples:
- Deletes Shadow Volume Copies to ensure that victims can't recover files using built-in Windows functions;
- Alters Windows Registry to establish persistence;
- Drops malicious files into %Temp%, %AppData%, %Roaming%, %Local% and other folders;
- Injects URLs into Windows “hosts” file in order to prevent users from accessing cybersecurity-focused websites;
- Inserts data-stealing modules that can exfoliate passwords, bitcoin wallets, credentials, etc.
Igal ransomware damage can be found in the system
Even though ransomware is an encryption-based threat, infection is not only damaging those files with .jpg, .mp3, .doc, .docx, .png, and other formats. It mainly focuses on such data that is commonly used, but system files and functions get affected too.
Do not forget that malware spreads around via malicious files that get attached to email messages directly or get downloaded in the package from torrent sites, pirating platforms, and so on. Various software license activators, program installation files can be laced with malicious code and lead to ransomware infection. This way the threat finds its way on the PC and ransomware might run in the background for a while until the encryption process is initiated.
Keep in mind that some sections of a Windows system might be damaged during the infection process, affecting its capability to deliver a steady performance. In case you later suffer from lag, crashes, reboots, BSODs,[2], and other computer issues, we strongly recommend you trying the FortectIntego repair tool instead of reinstalling the OS altogether.

If you were unlucky enough to get infected with this virus, you should not panic, as it will not solve anything. Keep in mind that you are not the only one in this situation, and many users are looking for the ransomware removal guide. In this article, we will explain how to take the correct steps in order to mitigate the infection correctly and how to try certain file recovery options that might help you to retrieve at least some of your locked data.
That being said, you will require a robust anti-malware tool in order to eliminate ransomware and all of its modules correctly. SpyHunterCombo Cleaner or MalwarebytesMalwarebytes are perfect for this job, so we highly recommend trying them. However, if you have no backups available you could restore your files from, you should first make a copy of the encrypted ones.
.Igal virus files are not infected, but recovering them might be difficult
The virus targets the most popular file types, such as .doc, .pdf, .zip, .jpg, and many others. Thus, as soon as the encryption is finished, users would see a file previously known as “picture.jpg” as “picture.jpg.igal.” Suchlike data will no longer be available to open or use. At this point, many users would probably look at the ransom note _readme.txt, which explains the following:
ATTENTION!
Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-EtT4dX8q3X
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:
helpmanager@mail.chReserve e-mail address to contact us:
restoremanager@airmail.ccYour personal ID:
According to the ransom note that is delivered as soon as malware infection is complete, only cybercriminals are capable of providing a decryption tool – for a price. To mislead victims and make them believe that malware authors are trustworthy, they also offer test decryption for a single file from the affected system. Industry experts[3] advise avoiding trusting ransomware developers in general.

Several points are important to make here:
- Ransomware encrypted files are not damaged. Instead, they are locked behind a unique key that is tied to each of the user ID that is presented on the ransom note. As soon as victims pay the ransom, the attackers can use that ID to provide a unique key that they store on their systems.
- Access to files will not be reestablished as soon as the ransomware is eliminated with security software. It is simply impossible, as anti-malware is designed to contain and delete the infection.
These two points make ransomware infection a challenging task to tackle and put victims into a rather tough spot. Luckily, paying almost a thousand dollars is not the only way that .igal virus files can be recovered. However, it is important to keep in mind that alternative solutions might not work for everybody.
If you have no backups (which you should), the first thing you should do is to copy over the encrypted files onto a different medium, such as cloud or USB flash. After that, remove malware with anti-virus software, and only then attempt data recovery. There are several options available:
- Emsisoft's decryption tool that might help victims later on – it only works for those whose files were locked with an offline ID, however;
- Third-party recovery software might help your retrieve at least some of the locked files;
- In case the virus failed to delete Shadow Copies, file recovery should be very easy.
To find more details about each of these alternative methods, please check our recovery section located at the bottom of this post.
Malware removal explained
While some ransomware strains self-delete as soon as they perform the file encryption process, others can remain on the system to encrypt the incoming files. When it comes to Djvu variants, many of them inject malicious modules into users' computers that allow data theft, so it is important to perform a full ransomware removal with powerful anti-malware software – we recommend SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. After that, we also advise using FortectIntego to ensure that all system files, Windows registry, and other damaged components are fixed automatically.
In some cases, you might struggle to remove malware from your system easily, especially if malware was bundled with other infections (previous versions were seen being distributed with AZORult banking Trojan). In such a case, you can access Safe Mode and perform a full system scan from there – we explain how below.

After you are sure that the malware is gone from your system, you should also visit the following location on your machine and delete the “hosts” file, so you can access various security-related websites without restrictions once again:
C:\Windows\System32\drivers\etc\
Was this guide helpful?
Be the first to comment