Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2016

How to remove Parisher ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Learn how Parisher virus operates:

Parisher virus is malicious software created to implement illegal activities on the target computer. It is a new version of the infamous Mobef ransomware, and its aim is to make victim’s files inaccessible and demand the victim to pay a ransom in order to get them back. This malicious program is designed to scan victim’s computer for preset file types, and encrypt each of them with an irreversible cipher. In fact, this process can be reversed only with a unique decryption key, which cyber criminals suggest purchasing. To purchase the decryption key, victims have to contact the ransomware author via parisher@protonmail.com, parisher@inbox.lv, parisher@mail.bg or parisher@india.com. According to the ransom note this virus displays on computer’s screen, the list of all encrypted files can be found in a .log file that is stored in C:\Windows directory as [6 random digits].log. The ransom note can be entitled as 1NFORMAT1ONFOR.YOU or HELLO.0MG, and you can see the information it presents below.

After contacting cyber criminals, we have discovered that they ask for 5 BTC in exchange for providing the decryption tool. We find such ransom enormously huge – it is more or less 3150 USD dollars, and we doubt that all victims can allow themselves to pay such an immense amount of money. We recommend you not to pay the ransom, no matter if such sum is large or small for you. We do not believe that criminals provide the decryption tool – most likely they just want to collect money and mind their own business, so it is unlikely that they spend time sending out decryption tools to people who pay up. If your PC has been compromised by Parisher ransomware, search for backups and before you use them, remove Parisher virus from the system with anti-malware tools like FortectIntego or SpyHunterCombo Cleaner. Full Parisher removal guidelines are given under this article. Parisher virus on researcher's computer

How did this ransomware manage to reach my computer system?

Ransomware mostly travels via email in the form of deceitful email attachments that appear as typical documents or archives and raise no suspicion at first. Once opened, they might ask you to enable Macros or other functions, which will allow executing the malicious script hidden in the file. You should never download or open email attachments if you do not personally know the sender of it. Such files can destroy all records, precious memories, and bring months of work to naught. However, there are different ransomware distribution techniques that might have been used to infect your PC, for example, your computer could get infected after visiting a malicious website that contained an exploit kit. Exploit kits scan individual computer programs and find security vulnerabilities in them, and then use them to install malware on the target system.

How to remove Parisher malware?

To remove Parisher virus as well as all files related to it, such as HELLO.0MG and LOKMANN.KEY933, run a system scan with anti-malware software – it will automatically detect all malicious files and eliminate them fully. Please do not try to complete Parisher removal by yourself, unless you are an advanced IT expert or a programmer and understand how malicious programs work and where they typically place malicious files. It is hard to remove such viruses even if you have some computing skills, so better leave this task to automatic malware removal program.

4 comments

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.