Reig ransomware – malware infection that threatens thousands of users' files all over the world

Reig is a malicious program that belongs to the ransomware category – a type of malware specializing in money extortion. In order to achieve that, cybercriminals lock all personal files on the infected Windows machine and then hold them hostage until a ransom is paid. Ransomware is regarded as one of the most devastating infections around, so check out this article to deal with it accordingly.
Once installed, the virus quickly performs the necessary system changes to reach its main goal – data locking, which is done with the help of a secure RSA[1] encryption algorithm. After this process, each of the affected files is appended with a .reig extension and can no longer be accessed by the victim.
Cybercriminals leave a ransom note titled _readme.txt, which is placed on the desktop and other directories. In the note, hackers provide contact emails – helpteam@mail.ch, helpmanager@airmail.cc – which should be used by the victims in order to pay the required money in bitcoins. The attackers ask for $490/$980, but you should not rush paying.
Since this virus belongs to the prominent Djvu malware family, there is a chance to decrypt your files successfully with specially designed tools available for free. Therefore, you should not jump to conclusions just yet and check the instructions below.
| Name | Reig ransomware |
| Type | File locking virus, crypto-malware |
| Family | This virus is a version of the well-known Djvu ransomware family |
| Encryption algorithm | RSA |
| File extension | All personal files are appended with .reig extension |
| Ransom note | _readme.txt |
| Ransom size | If the contact is made within the first 72 hours of the infection, users are asked for $490; this price doubles to $980 afterward |
| Contact | helpteam@mail.ch, helpmanager@airmail.cc |
| Data recovery | Files might be recovered with the help of Emsisoft's Decryptor for STOP Djvu under certain circumstances. If that does not help, you can also refer to the below section for more options |
| Malware elimination | Download and install anti-malware software, such as SpyHunterCombo Cleaner, and then perform a full system scan (do not forget to backup the encrypted data before this process if you do not have working file copies ready) |
| System fix | If your computer is crashing, lagging and returning errors after malware termination, repair Windows system with the help of FortectIntego |
Reig virus variant was first spotted in the first half of 2021 and is just one of the hundreds produced by cybercriminals. In fact, this malware family has a long history behind it, and security researchers attempt to battle this most prevalent strain. Unfortunately, it does not seem that the attackers will stop any time soon, as several versions are being released every week, the latest ones being:
Despite the virus appending different extensions, its purpose and functionality remain the same. Even the ransom note is practically identical – it reads:
ATTENTION!
Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-9CYW99VhUR
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:
helpteam@mail.chReserve e-mail address to contact us:
helpmanager@airmail.ccYour personal ID:
As you can see, the attackers provide contact details and all the other relevant information within the ransom note – this is very typical behavior of ransomware authors. Malicious actors claim that they will send the private key required to unlock .reig files in exchange for payment of $980, which is meant to be provided in bitcoin cryptocurrency for anonymity purposes.
Cybercriminals also promise a 50% discount if contact is made within 72 hours – or three days – after the initial attack. In addition, they also provide an opportunity to decrypt one file for free. These are very common techniques that are used by malicious actors to gain victims' trust, increasing the chances they will pay. However, keep in mind that they are criminals, after all, and should never be trusted.

Naturally, your question is what to do now. When it comes to Reig ransomware removal, you should not rush it immediately. If you had no backups available, you should first copy all the encrypted files onto a separate medium, e.g., a flash drive, as malware elimination or alternative recovery methods might permanently damage the encrypted files. To eliminate the infection, we highly recommend SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. FortectIntego could serve you as a supplementary application that could help you fix virus damage, ensuring that Windows operates normally after the termination of malware is complete.
Keep in mind that you will not able to restore your files after you remove the infection itself with anti-malware software. Instead, you can try Emsisotf decryptor or third-party recovery software. For more information, check the bottom section of this post.
Djvu creators use infected software cracks to distribute ransomware
The recovery process after ransomware infection can be lengthy and quite exhausting, consequently resulting in a loss of pictures, documents, videos, and other files. Precisely due to this reason, ransomware is considered to be one of the most devastating malware types around, so there's no surprise that attacks using it are increasing.[2] Cybercriminals simply see ransomware as the most profitable source of illegal income. It remains illegal money extortion, however, and you should not forget that.
Thus, the best way to counter all this is not to get infected in the first place. While many different ransomware types use different methods for propagation (exploit kits, spam emails, etc.), Djvu virus authors prefer using pirated program installers and torrent sites for malware delivery. Unfortunately, they are very successful at that, as hundreds of users get infected every day.
In order to prevent this type of attack in the future, you should check out these tips provided by novirus.uk[3] security experts:
- Equip your computer with a robust security application and never ignore its warnings;
- Do not visit high-risk websites, especially those that host software cracks or pirated program installers (torrents);
- Backup your files on a separate drive or use cloud services such as OneDrive (we provide instructions on how to do that below);
- Patch your computer and all the installed programs with the latest security updates;
- Never open email attachments that ask you to enable macro function (“Allow content”);
- Use strong passwords for all your accounts (never re-use them!) and enable two-factor authentication.
Eliminate ransomware and attempt to recover your data
Probably the first thing that comes to your mind right now is, “Can I remove .reig file extension?.” The answer to this question is rather difficult, as it highly depends on your situation. For example, if you have data backups available on cloud services or an external drive, you do not have anything to worry about. Unfortunately, most ransomware victims fail to back up their data, and after malware begins infiltration, it is too late.

If you belong to that group of people, do not panic, as not everything is yet lost. First of all, copy the encrypted data onto another storage that is not connected to your PC, and then perform a full system scan with SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or another robust security application that would find and delete all the malicious files from your system for a full Reig ransomware removal at once. In order to avoid reinstalling Windows due to sustained malware damage in the future, we recommend using a remediation tool FortectIntego afterward.
Finally, you can attempt data recovery. Emsisoft's decryptor might be able to help you (although most likely not immediately, so you might have to wait a few months) if your files were encrypted with an offline key. To check that, download the tool and use it. Additionally, you should try using recovery software that might restore at least some of your data. For more details, check the guide below.
Was this guide helpful?
Be the first to comment