Marlboro ransomware gets defeated in less than 24 hours
Marlboro virus has been spotted by our experts on January 12, 2017. We must mention that this virus has a different name – DeMarlboro ransomware virus. Although this ransomware is not as dangerous as Locky virus [1], getting infected with it gives you a hint that your computer system is unprotected. As soon as it enters the system, it determines whether the system is 32 or 64 bit and uses a particular installer then. The indicated ransomware appends .oops file extension to files that the virus corrupts. However, Marlboro ransomware appeared to be a foolish ransomware variant that uses XOR encryption to lock victim’s files, although in the ransom note, the virus claims to be using RSA-2048 and AES-128 ciphers[2]. The virus leaves a ransom note, which is named _HELP_Recover_Files_.html, filled with data recovery instructions. The virus simply takes files hostage, deletes Volume Shadow Copies[3], and it demands a ransom to set encrypted files free. The ransom note commands the victim to send 0.2 BTC (more or less $155 in Bitcoins) to crooks’ Bitcoin address and then launch Decryptfiles.exe program, which the virus saves to Desktop and Documents folders. Now this is where the developers of Marlboro malware get creative. Instead of pointing the victim to Tor browser’s download site and telling to visit a personal payment website, the crooks simply leave the Marlboro decrypter on victim’s system, which gets activated automatically as soon as the victim transfers the money to criminals’ Bitcoin address[4].

The decrypter presents itself as “a special software – documents decrypter – which allows to recover and return control to all your encrypted files” and, what is even more unusual, the decrypter asks to retype a shown number to verify that the user is a human being. The decrypter then connects to its server to verify the payment, and, if failed, asks the victim to retry in half a hour. If you have been infected with this virus, you must remove Marlboro malware before you try to take any data recovery actions. Use a strong malware removal tool for this task, for instance, FortectIntego or MalwarebytesMalwarebytes. At the end of this post, you can find detailed Marlboro removal guidelines that explain how to deactivate the virus and start the malware removal tool.
Updated on January 13th: Marlboro ransomware is defeated, and a free decryption tool is available. Do not even think about paying the ransom! You can download the decrypter made by Emsisoft researchers here.
Ways of distribution
The virus is obfuscated heavily and approaches victims as a DOCM document[5]. Reportedly, malevolent actors working behind Marlboro ransomware project spread this virus via phishing emails that politely ask the recipient to open attached files. All PC users should be aware of this ransomware distribution technique, because, despite its simplicity and banality, it is so far the most efficient way to infect computer systems with malware. Users should be extremely careful and protect their devices by stocking up data backups and installing anti-malware software on their computers (to block malicious programs from entering the computer system and executing harmful commands). It is believed that the virus spreads via other channels as well, for instance, compromised web ads pointing to websites hosting exploit kits, also Trojan horses and so on. If you were infected with this virus a few minutes ago, turn off the computer immediately and plug out the Internet connection cable from the compromised PC.
How can you remove Marlboro malware before using the decryption tool?
Unless you are willing to pay the ransom, you should remove Marlboro virus as quickly as you can. Just do not act hastily – read Marlboro removal instructions presented below this post to learn how to start your computer in a Safe Mode with Networking to be able to run your anti-malware or antivirus software. Otherwise, the virus might block your attempts to launch the malware removal tool (to avoid detection). Please do not try to remove Marlboro ransomware on your own because the virus makes various modifications in Windows Registry, as well as system files (.dll files), not to mention the dozen of files that it drops on the computer system.
Did this guide help?
4 comments
Sirrr
Got infected, but also got the virus removed and files decrypted. Thanks a lot.
Zigmus
Demarlboro. Thats how the ransomware is called. I found a folder with this name
Rembo
Why is it named like that? Ransomware names make no sense.
Dany
Malware authors make no sense at all.