Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Aug 2017

How to remove Nuclear ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

BTCWare continues spreading as Nuclear ransomware

Ransom note by Nuclear ransomware virus

Nuclear ransomware is a new version of BTCWare virus that actively spreads in Hungary, Italy,[1] and Iran. Crypto-malware uses a combination of RSA and AES encryption and appends .[black.world@tuta.io].nuclear extension. Criminals provide a ransom note in HELP.hta file and ask to contact black.world@tuta.io for more information.

The Nuclear virus works similarly to the original version of the malware. It might also launch the attack compromising Remote Desktop services.[2] On the affected device, the virus might modify or make new Registry entries in order to boot at system startup.

The virus might also delete Shadow Volume Copies of the targeted files. Therefore, decryption with third-party software might not bring the best results. Nevertheless, BTCware is decryptable, Nuclear ransomware is not yet. Thus, it’s better to have backups after ransomware attack.

Malware targets around 100 different file types, including MS Office documents, various types of images, audio and video files, archives, etc. During data encryption, Nuclear ransomware appends a new suffix to these data. Due to the .[black.world@tuta.io].nuclear file extension, users lost access to the personal data.

Following data encryption, ransomware delivers a ransom note in HELP.hta file where criminals ask to contact them via provided email address within 36 hours. Victims have to pay the ransom in Bitcoins. However, the exact price for the recovery is unknown. Thus, it might vary based on the amount and importance of the targeted files.

Authors of the .Nuclear file virus wants to prove victims that they actually have working decryptor. People can send up to 3 files that are smaller than 1Mb and do not include any important information. Crooks will send back encrypted files for free. However, we want to point out that it might be the only files restored by crooks.

Cyber criminals are not reliable, and this generous move might be just a trick to swindle your money. For this reason, we highly recommend focusing on Nuclear virus removal instead of data recovery. The original version of the virus is decryptable. Thus, it’s just the matter of time when the official decryptor will be released for this variant.

Therefore, in order to remove Nuclear ransomware virus from the PC, you have to obtain a reputable security software, such as FortectIntego, and run a full system scan. If malware blocks access to antivirus or anti-malware, you might find the instructions below handy.

The picture of Nuclear ransomware virus

The file-encrypting virus attacks by exploiting Remote Desktop service

Viruses that belong to BTCWare family spread using Remote Desktop service and takes advantage of weak passwords. In this way, ransomware can get access to the computer and install malicious payload. Therefore, protection of this ransomware family is simple. You either have to set a strong password or disable this Windows service.[3]

However, Nuclear malware executable, known as payload.vir, might also be installed when a user clicks on the malicious email attachment, download bogus program or update, clicks on malware-laden ads, and using other ransomware distribution methods.

Removal of the Nuclear ransomware

Nuclear ransomware removal is performed using reputable malware elimination program. We recommend using either FortectIntego or MalwarebytesMalwarebytes. These security tools can identify and delete all malicious components from the system safely and quickly.

However, it may not be so easy to remove Nuclear ransomware. The virus might be resistant and stop you from installing the necessary software. Though, to avoid these issues, you should run your PC in Safe Mode with Networking first. The detailed explanation is presented below.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.