Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Aug 2017

How to remove Mole02 ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Mole02 – a new file-encrypting virus from CryptoMix family

The ransom note by Mole02 ransomware virus

Mole02 is a recently discovered ransomware[1] virus that seems to belong to CryptoMix family. The virus might be an updated version of Revenge and Mole ransomware viruses. Currently, the virus is under investigation. However, it’s already known that it uses a combination of RSA and AES ciphers, appends .MOLE02 file extension and drops a ransom note in the _HELP_INSTRUCTION.TXT file.

Malware is executed from Mole02.exe. On the affected machine it contacts its Command and Control (C&C) server, and once it responds, ransomware starts malicious tasks. Mole02 ransomware is capable of modifying the system and creating entries in Windows Registry. It also injects malicious codes into legitimate system processes, queries the Internet cache and sensitive IE settings, and makes other critical changes.

However, the most important task for the ransomware is data encryption. According to the ransom note, it uses RSA-2048 and AES-128 encryption algorithm. It seems that the virus aims at the majority of files and stays away only from the crucial system files. It appends .MOLE02 file extension to each of the encoded data and prevents victims from accessing their files. Unfortunately, Mole02 removal does not help to recover encrypted files.

In order to make data recovery more complicated, the virus deletes Shadow Volume Copies and backups. In this way, cyber criminals want to be the only ones who can offer the decryption possibility. Following data encryption, malware downloads are ransom note called _HELP_INSTRUCTION.TXT. It gives information that victims have to pay the ransom in Bitcoins using Tor browser. The size of the ransom is currently unknown. Thus, it may differ based on the size of encrypted files.

The picture of Mole02 ransomware virus

Therefore, currently, the only way to restore files encrypted by Mole02 are backups. Otherwise, chances to get back access to the documents and pictures are not very high. However, this situation should not motivate you to follow hackers’ orders and pay the ransom. No one can guarantee that cyber criminals will keep their word and help you to decrypt files. Once they receive the money, they may ask for more, install additional malware or keep you waiting for the decryptor.

Instead of risking to lose your money, you should remove Mole02 from the device. Ransomware elimination is performed using reputable malware removal program, such as FortectIntego. For detailed instructions, scroll down to the end of the article.

Dissemination methods of the ransomware virus

The specific ways how Mole02 ransomware spreads are unknown. It seems that criminals rely on traditional distribution methods, such malicious spam emails, malvertising, fake downloads, and updates.

Malicious emails remain the most popular way to spread malware. Such letters have infected attachments[2] or links. Once a victim clicks on a dangerous content, the payload is downloaded and executed on the system.

Mole02 might also enter the system when a user clicks on a malicious ad. Malvertising is gaining more and more attention between cyber criminals. This method allows placing infected ads even on popular and legitimate sites. Thus, it becomes easy to trick people into clicking hazardous ads without suspecting anything wrong.

Installation of bogus software, such as unknown antivirus, various PC optimization tools from a file-sharing site, and other content from insecure online sources may also lead to ransomware attack.

Thus, in order to keep your computer and files safe from being encrypted, you should take all necessary precautions when browsing the Web and backup your files.

Removal of the Mole02 ransomware virus

Before starting Mole02 removal, you may need to reboot the computer to Safe Mode with Networking. For the elimination, you will need to install or update your current security program, but malware might stop you from doing it. To avoid this problem, you should run your PC in Safe Mode. Then, you will be able to access your preferred security program and run a full system scan. You can remove Mole02 automatically with FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.