Nury ransomware is the file-locker virus that demands payments for the alleged decryption tool

Nury ransomware virus is an intruder that creates major problems for the device by encrypting user files and then further damaging the computer by running other processes or disabling programs. The infection can use an army-grade algorithm to render documents, images, and audio files unusable when the original file code is changed.[1] There are many other tricks that criminals use to get people to pay for supposed decryption that virus creators promise.
Unfortunately, these locked files cannot be recovered at all because the threat comes from the Djvu ransomware family, which releases new versions every week. The virus is designed to corrupt the device and locks the files in the first place, but there are other problems associated with the Nury file virus infection.
The ransomware marks the altered data using a unique appendix .nury. This is where the name of this version comes from. These appended pieces cannot be opened or recovered without the decryption tool, only replaced with copies from backups.
After all the processes related to data encryption have been carried out, the virus loads the _readme.txt file into various folders and on the desktop. This file is a direct message from the virus creators demanding a ransom in exchange for a possible decryption tool. The sum starts at $490 but can be doubled after 72 hours.
However, it is not advisable to trust the promises of cyber criminals as they may lie and files that have been encrypted by the Nury ransomware may remain locked and even permanently corrupted. Unfortunately, there are no official tools available to help, and there are no programs currently being developed by credible researchers. This is why removing the threat is recommended rather than contacting the people behind this infection.
Damage caused by ransomware
| Name | Nury ransomware |
|---|---|
| Type | Cryptovirus, file-locker virus |
| Family | STOP/ Djvu ransomware |
| File marker | .Nury |
| Ransom note | _readme.txt |
| Ransom amount | $490/ $980 in Bitcoin |
| Contact details | support@fishmail.top, datarestorehelp@airmail.cc |
| Distribution | Files attached to spam emails, included in pirating packages spread via torrents and pirating platforms |
| Removal | Removing the infection is best with AV tools |
| Repair | Recover the machine using FortectIntego |
Be aware that the virus creators may trick you into thinking that instead of the promised decryption tool, they may offer other threats that, once on the device, can change the settings so that users are unable to remove the Nury ransomware or restore their files easily.
You need to react as soon as possible when you see a ransom message on your device or when you notice computer speed problems and locked files. This will ensure that the virus has been removed before it causes irreparable damage to your computer system. Other threats can also be loaded to ensure persistence, as experts[2] note.
Removing the infection
Nury ransomware virus is an infection that spreads through various deceptive methods, such as malicious macros included in email attachments through email campaigns. These infections can run in the background, further corrupting the device and ensuring that the virus runs as smoothly and as long as possible.
Such threats are extremely serious and can be considered one of the most dangerous infections. The specific Nury ransomware virus comes from the Djvu ransomware family and is one of the latest releases. More than 500 variants have been released since 2018 when the virus was first detected in cyberspace. All of the recent versions are not decryptable.

The threat can be hidden, and the infection can cause various problems, so it is very important to carry out the removal process properly. The removal of the Nury file virus is best done using a trusted antivirus application that detects[3] threats properly. Trust programs like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Make sure you have fully scanned your device and allow the tool to remove any threats it finds automatically. This is a process that helps to keep your computer safe and improve its performance.
Before you start restoring files, try scanning the device several times. Antivirus tools can point out all programs and files that may be malicious or dangerous. Activate a proper system scan to ensure that all files related to the virus are removed and that the previously active virus is no longer active. Only then can you proceed to attempt to restore the files safely.
Recovering the system data
Once a computer is infected with malware, its system is changed to operate differently. For example, an infection can alter the Windows registry database, damage vital bootup and other sections, delete or corrupt DLL files, etc. Once a system file is damaged by malware, antivirus software is not capable of doing anything about it, leaving it just the way it is. Consequently, users might experience performance, stability, and usability issues, to the point where a full Windows reinstall is required.
Therefore, we highly recommend using a one-of-a-kind, patented technology of FortectIntego repair. Not only can it fix virus damage after the infection, but it is also capable of removing malware that has already broken into the system thanks to several engines used by the program. Besides, the application is also capable of fixing various Windows-related issues that are not caused by malware infections, for example, Blue Screen errors, freezes, registry errors, damaged DLLs, etc.
- Download the application by clicking on the link above
- Click on the ReimageRepair.exe

- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process

- The analysis of your machine will begin immediately

- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.
How ransomware spreads?
The malicious code is usually introduced by an executable file (.exe), which may have been contained in a ZIP folder, embedded in a Microsoft Office document macro, or disguised as another attachment. Threat actors use this tactic to distribute Nury ransomware across platforms and organizations.
Malicious files can also enter your system by installing pirated software. The platforms that distribute it, such as torrent sites and peer-to-peer file-sharing platforms, are unregulated – making it easy for hackers to distribute malware online without any oversight or accountability.
Nury ransomware can be installed by a vector like a trojan horse or a worm that silently infects the machine. The infiltrations might not be noticed, so keeping anti-malware tools or security applications could help avoid installations of serious malware. AV tools can check email attachments and programs before you add them on the computer system.
Almost every download usually contains some kind of malicious code, which is difficult (if not impossible) to identify just by looking at its size. Even experts don't always know what is safe until they have analyzed the downloaded program. Always pay attention to even the smallest details to avoid infections like the Nury file virus.
Recovery of the locked files
Since many users do not prepare proper data backups prior to being attacked by ransomware, they might often lose access to their files permanently. Paying criminals is also very risky, as they might not fulfill the promises and never send back the required decryption tool.
Therefore, we suggest trying regardless of which ransomware attacked your computer. Before you begin, several pointers are important while dealing with this situation:
- Since the encrypted data on your computer might permanently be damaged by security or data recovery software, you should first make backups of it – use a USB flash drive or another storage.
- Only attempt to recover your files using this method after you perform a scan with anti-malware software.
Install data recovery software
- Download Data Recovery Pro.
- Double-click the installer to launch it.

- Follow on-screen instructions to install the software.

- As soon as you press Finish, you can use the app.
- Select Everything or pick individual folders where you want the files to be recovered from.
- Press Next.
- At the bottom, enable Deep scan and pick which Disks you want to be scanned.

- Press Scan and wait till it is complete.

- You can now pick which folders/files to recover – don't forget you also have the option to search by the file name!
- Press Recover to retrieve your files.
Did this guide help?
Be the first to comment