NMO ransomware is the virus that locks files by encrypting them and demands money for the alleged recovery option

NMO ransomware is a virus that relies on scare tactics that help to encourage people to pay the ransom demands and fall for the claims from cybercriminals. The malware executes the payload once it is silently dropped on the machine. Once the ransomware virus is active, the encryption[1] procedure can start, and the chosen file gets encoded – the original code is altered, and those files get appended .NMO extension with the contact email and victims' ID.
The virus focuses on this process because then the ransom can be demanded via the info.txt file that is placed on the desktop. NMO ransomware virus uses encryption to get leverage and an opportunity to scare people into transferring their funds for the promised tools.
However, the threat is not decryptable even with the tool that creators possibly have. Criminals care about your money, and these claims can be just to convince you. Paying, nevertheless, is not an option, and people should ignore these messages, criminals, and their activities.
The powerful ransomware
NMO ransomware virus is the threat coming from the Dharma ransomware family. This is not a promising fact because newer threats can be poorly coded and are often decryptable or reverse engineered. This is not the case with versions of these major file virus threat families.
| Name | NMO ransomware |
|---|---|
| Type | File locker virus, cryptovirus |
| Family | Dharma virus |
| Ransom note | info.txt |
| Contact emails | dr.nemo@tutanota.com; mr.helper@gmx.com |
| File marker | .NMO an includes the unique victims' ID and the email belonging for the cybercriminals |
| Removal | Threat removal tools can help to stop the active virus |
| Repair | Run FortectIntego to stop the damage and repair affected system files |
The virus encrypts videos, audio files, and documents that are potentially valuable, and the infection can claim to have the only solution of recovery – the offered payment. NMO ransomware is the product form cybercriminals, and these attackers urge people to contact them as soon as possible to recover these affected files.
This is not recommended by experts[2] because threat actors can send you additional malware and demand additional sums. The distribution of the threat can also involve the installation of other infections, so you need to remove the NMO ransomware virus as soon as possible.
The infection affects files on the machine directly and can damage system data to keep the persistence up. This is the reason to remove the threat as soon as possible. Any NMO file virus messages should be ignored, including the pop-up with instructions, the ransom file with encouragement to contact criminals, and any suspicious alerts.
The pop-up appears on the screen with the message:
YOUR FILES ARE ENCRYPTED
ZAQ
Don't worry, you can return all your files!
If you want to restore them, write to the mail: dr.nemo@tutanota.com YOUR ID –
If you have not answered by mail within 12 hours, write to us by another mail:mr.helper@gmx.comATTENTION!
We recommend you contact us directly to avoid overpaying agentsDo not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
Removing the infection
NMO ransomware virus can control various processes on the machine to keep the virus running and persistent. These functions include other malware like trojans, worms, and other threats that can be used for spreading the ransomware payload in the first place. You need to stop all of these infections.
The detection[3] rate of the AV tools shows that tools like anti-malware programs can help with the proper NMO ransomware virus removal procedure. Anti-malware programs like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes can run a thorough system check and indicate possibly malicious files and programs.
Note that this is not the method for file recovery or virus decryption. This is the removal of the infection that is active on the machine. Once the threat is terminated, you can deal with the consequences of the NMO ransomware infection. The file recovery can be successful with backups that you store on external devices or with the proper software.

Restore system data
Once a computer is infected with malware, its system is changed to operate differently. For example, an infection can alter the Windows registry database, damage vital bootup, and other sections, delete or corrupt DLL files, etc. Once a system file is damaged by malware, antivirus software is not capable of doing anything about it, leaving it just the way it is. Consequently, users might experience performance, stability, and usability issues, to the point where a full Windows reinstallation is required.
Therefore, we highly recommend using a one-of-a-kind, patented technology of FortectIntego repair. Not only can it fix virus damage after the infection, but it is also capable of removing malware that has already broken into the system thanks to several engines used by the program. Besides, the application is also capable of fixing various Windows-related issues that are not caused by malware infections, for example, Blue Screen errors, freezes, registry errors, damaged DLLs, etc.
- Download the application by clicking on the link above
- Click on the ReimageRepair.exe

- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process

- The analysis of your machine will begin immediately

- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

Finding the decryption option
NMO ransomware virus is the one developed by dangerous cybercriminals and cannot be decrypted easily because of the advanced coding and persistence. The infection needs to be removed properly from the machine, and then files can be recovered using the software for that or alternate methods.
However, sometimes these threat families get to be analyzed, and researchers manage to release decryption tools for these variants. NMO ransomware uses powerful encryption and keys that are used for decryption cannot be obtained from criminals that easily.
There are several algorithms that can be used to lock data (whether for good or bad reasons); for example, AES uses the symmetric method of encryption, meaning that the key used to lock and unlock files is the same. Unfortunately, it is only accessible to the attackers who hold it on a remote server – they ask for a payment in exchange for it. This simple principle is what allows ransomware authors to prosper in this illegal business.
Even though this NMO file virus is from the Dharma family, there are plenty of failures that can be observed within the code of some novice malware developers. For example, the keys could be stored locally, which would allow users to regain access to their files without paying. In some cases, ransomware does not even encrypt files due to bugs, although victims might believe the opposite due to the ransom note that shows up right after the infection and data encryption is completed.
Therefore, regardless of which crypto-malware affects your files, you should try to find the relevant decryptor if such exists. Security researchers are in a constant battle against cybercriminals. In some cases, they manage to create a working decryption tool that would allow victims to recover files for free.
Once you have identified which ransomware you are affected by, you should check the following links for a decryptor:
- No More Ransom Project
- Free Ransomware Decryptors by Kaspersky
- Free Ransomware Decryption Tools from Emsisoft
- Avast decryptors

If you can't find a decryptor that works for you, you should try the alternative methods we list below. Additionally, it is worth mentioning that it sometimes takes years for a working decryption tool to be developed, so there are always hopes for the future.
NMO ransomware virus can damage many parts of the machine beside the data that is locked. You need to remove the virus properly with anti-malware tools like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner and fully scan the machine, so the computer is virus-free again and can be used as before.
These issues with detection rates or success when removing the virus can be affected the damage made in the settings of the computer. For those issues, you need FortectIntego and applications particularly known for system repair functions. This is the way to recover the machine before those files could get recovered with alternate options. Do not skip the NMO ransomware removal at any cost.
Was this guide helpful?
Be the first to comment