Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jul 2019

How to remove Sodin ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Sodin ransomware is the version of a cryptovirus that supposedly is linked with GandCrab creators

Sodin ransomware virus 

Sodin ransomware is the cryptovirus that encrypts files found on the machine and marks them with .mc9530 marker, so it can also be called .mc9530 virus. However, this is the version of Sodinokibi ransomware that is supposedly related to GandCrab because it was made available on the dark web forums and serves as ransomware-as-a-service.[1] 

This ransomware comes to the system by exploiting Windows vulnerabilities like CVE-2018-8453[2] and then Sodin ransomware virus aims to change the default file extension to a .mc9530 appendix and make data useless this way. The purpose of this encryption is to have a reason for a ransom demand that can go up to thousands of dollars in the form of cryptocurrency like Bitcoin. The main area that this virus target is Asia, Taiwan, Hong Kong, and South Korea in particular, but there is a risk to get affected by this cryptovirus for anyone in the world. This is a dangerous threat that can lead to permanent data damage or even money loss because the lowest amount of ransom demand is $2500 in Bitcoin.

Name Sodin
Type Ransomware
Family Sodinokibi ransomware
File marker .mc9530
Distribution Exploiting system vulnerabilities, infected spam email attachments
Ransom note mc9530-readme.txt
Ransom amount May differ from $2000 to $5000 in Bitcoin
Elimination Get a reliable anti-malware tool and remove Sodin ransomware. Clean virus damage with FortectIntego

Sodin ransomware infects the system and extorts money from the victim that wants to have files working normally again. The encryption process changes the original code of data in various formats. Photos, documents, videos, audio files, PDFs, and even archives get affected by this virus. The only type of data that ransomware is not encrypting is system files.

However, Sodin ransomware affects various system files and general settings of the machine to make needed changes and ensure the persistence of this malware. Malicious files or programs get installed on the machine to run processes of blocking the antivirus tools and security tools or features. 

Also, Sodin ransomware can delete Shadow Volume Copies to keep the user from recovering the encrypted files and create new or alter existing registry keys to make the malware run every time your computer gets rebooted. You need a thorough system check to end those additional processes and terminate the ransomware entirely.

Nevertheless, all those changes happen after the primary Sodin ransomware attack – file encryption. The virus may start with a system check to make sure that the machine was not encrypted before. Then files get selected and encrypted immediately. Once that is done, the mc9530-readme.txt file appears on the desktop and in every folder containing the encoded data.

Sodin ransomware ransom message reads the following:

—=== Welcome. Again. ===— a
[+] Whats Happen? [+] Your files are encrypted, and currently unavailable. You can check it: all files on you
computer has expansion] mc953@.
By the way, everything is possible to recover (restore), but you need to follow our
instructions. Otherwise, you cant return your data (NEVER).
[+] What guarantees? [+] Its just a business. We absolutely do not care about you and your deals, except getting
benefits. If we do not do our work and liabilities – nobody will not cooperate with us.
Its not in our interests.
To check the ability of returning files, You should go to our website. There you can
decrypt one file for free. That is our guarantee.
If you will not cooperate with our service – for us, its does not matter. But you will
lose your time and data, cause just we have the private key. In practise – time is much
more valuable than money.
[+] How to get access on website? [+] You have two ways:
1) [Recommended] Using a TOR browser!

a) Download and install TOR browser from this site: https://torproject.org/

b) Open our website:
http: //aplebzu4/wgazapdqks6vrcv6zcnjppkbxbr6éwket f56nf6aq2nmyoyd. onion/6750647830BDB096
2) If TOR blocked in your country, try to use VPN! But you can use our secondary
website. For this:

a) Open your any browser (Chrome, Firefox, Opera, IE, Edge)

b) Open our secondary website: http://decryptor. top/6750647830BDBO96
Warning: secondary website can be blocked, thats why first variant much better and more
available.
When you open our website, put the following data in the input form:
Key:
[REDACTED]

Sodin ransomware developers shouldn't be trusted, so avoid contacting them, especially for the file recovery. This is a false promise that can lead to a more damaged device than encrypted files in the first place. Remember that these people are cybercriminals and experts[3] note now malicious these extortionists are.

Sodin ransomware

We know how important these files that got encrypted are for you but focus on Sodin ransomware removal first, before worrying about data recovery. If you try to restore files with backups, you can damage your data permanently when ransomware encrypts files on the external device through the still affected system.

Get the anti-malware tool and scan the machine thoroughly. Then remove Sodin ransomware once it gets detected by the program and indicated as malicious alongside other applications or files. A thorough check on the computer should show various issues besides the malicious programs, so after the virus elimination, your machine runs better.

For additional check and insurance, we recommend rechecking the machine with a tool like FortectIntego that can delete Sodin ransomware virus damage and fix corrupted Windows files, for example. For data recovery, later on, we have a few suggestions below the article.

Sodin ransomware can be related to GandCrab developers, and even cybersecurity researchers expect a rise in attacks from this threat, so beware and clean the machine as soon possible, keep the system virus-free to avoid damage or other malware. Kaspersky officials even stated:

We expect a rise in the number of attacks involving the Sodin encryptor, since the amount of resources that are required to build such malware is significant. Those who invested in its development definitely expect it to pay off handsomely.

.mc9530 virus

Vulnerable servers and other system flaws get exploited by the virus to get on the computer

The most common method or ransomware distribution is file attachments containing various malicious files like PDFs, documents or links to a direct download of the payload. Such emails come to email boxes and trick people into the opening and downloading the attachment by showing legitimate names of companies and services like DHL, FedEx.

This ransomware, in particular, is not that common when it comes to the distribution of this threat because the common method is to require interaction with a malicious file to open the document attached to the email, so malicious macros get triggered and launch the cryptovirus script. In this case, the executable file that is downloaded to launch the ransomware comes when the virus exploits system or server flaws.

Check the system and remove Sodin ransomware files from the system with anti-malware tools

To avoid falling victim to Sodin ransomware virus, you should ensure that your software is patched and updated regularly and the Windows operating system flaws cannot get exploited. You can do so by updating all the programs yourself or keeping system tools which help to optimize the machine automatically.

Another automatic process that we recommend relying on is the initial Sodin ransomware removal. You should get the professional anti-malware program and scan the system entirely to eliminate all the associated files, applications, and disable suspicious processes.

Programs like [d1[, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes can remove Sodin ransomware completely, clean virus damage and indicate all the corrupted files, useless programs or data that may be malicious. Running an occasional system scan with such programs can improve the performance of your PC significantly.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.