Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2016

How to remove Ishtar ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

What is known about Ishtar ransomware?

Ishtar ransomware virus seems to be created by a Russian-speaking cybercriminal or a gang because it addresses the victim in the Russian language. This malware example belongs to ransomware category and users should be aware that it is extremely important to defend the PC from such viruses in advance because the damage that ransom-demanding viruses do can hardly be reversed. Ishtar virus encrypts records (photos, videos, documents, music files) with military-grade encryption (combination of AES-256 and RSA-2048) and, differently than other ransomware parasites, does not add certain file extensions to them– it adds an ISHTAR- prefix to every file it encrypts. Once ransomware applies the encryption to a file, it can no longer be opened or edited and becomes useless. Ishtar ransomware then creates and saves README-ISHTAR.TXT on the desktop and also in each folder that holds encrypted data.

Ishtar ransom note

The ransom note is a message from cyber criminals, and it informs the victim about the only possible data recovery method – ransom payment. It also warns not to delete ISHTAR.DATA file, which is stored in %APPDATA% folder, otherwise it will be impossible to decrypt encrypted data. To find out how to pay the ransom, the victim needs to contact criminals, and this can be done by writing to youneedmail@protonmail.com, or via Bitmessage. We highly recommend you to refuse to pay the ransom – you cannot count on criminals and whatever they promise to you might be a lie. Our team recommends you to remove Ishtar ransomware as soon as possible. In our opinion, the best anti-malware tool is FortectIntego, and it can help you with Ishtar removal.

How ransomware viruses attack computers?

Ransomware viruses often reach victims and wreak havoc on their computers only because victims open malicious email attachments. Be very careful when exploring email letters, and stay away from ones that come from unknown senders. You can never know what their real intentions are, so why would you open such malicious emails? Remember that scammers create legitimate-looking messages urging victims to view contents of attached files, so please do not fall for such scams. Frauds often pretend to be sending invoices, bills, reports, medical test results and similar documents. Do not open them!
Malware can also silently be installed after entering a deceptive website that contains an exploit kit. In such case, exploit kit scans the system for vulnerabilities in software (it targets outdated software, most frequently – Java), and use its vulnerabilities to enter victim’s PC. You can protect your computer by keeping all software up-to-date.

How to remove Ishtar ransomware virus?

If you are ready to remove Ishtar virus, make sure you have a proper malware removal tool. If you do not, consider installing one. Ransomware viruses are complex programs and only advanced IT experts can remove them manually, but even experts admit that it is hard to remove ransomware. Use Ishtar removal instructions provided below and deleted this virus from your computer for good. You can try suggested data recovery methods, too.

3 comments

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.