Termit ransomware – computer virus demanding a ransom after it encrypts all non-system data

Termit ransomware is a crytovirus that encodes all victims' personal data (video/audio files, documents, archives, etc.) with an army-based algorithm and appends the data with a .termit extension making the files inaccessible. The virus belongs to the nefarious DCRTR ransomware family. After it is done with the encryption, it then creates ransom note ReadMe_Decryptor.txt, which is placed into all affected folders.
The ransom demanding note is very short. Developers of Termit ransomware just urge the victims not to try and modify the affected files because that would ruin them. They're nice enough to offer a demonstration of decryption, i.e., users can send one file of no more than 500 kb to the cybercriminals, and they would decrypt it, proving that the decryption is possible. Two emails (ashtray@outlookpro.net, askebeger@protonmail.com) and an instant messaging service Jabber ID (askebeger@xmpp.jp) is provided to make contact.
| Name | Termit ransomware, .termit cryptovirus |
|---|---|
| type | Malware, Ransomware |
| family | DCRTR ransomware family |
| appended file extension | All non-system files are appended with .termit extension |
| ransom note | ReadMe_Decryptor.txt can be found in all contaminated folders |
| criminal contact details | Three contacts are provided. Two emails: ashtray@outlookpro.net, askebeger@protonmail.com; and a Jabber ID – askebeger@xmpp.jp |
| distribution | Infectious email attachments, torrent websites |
| removal of ransomware | Dependable anti-malware software should be used to remove Termit ransomware |
| system fix | Foolproof system tweaking FortectIntego tool should be used to restore any corrupted system files or altered system settings |
Even though paying the ransom to the cybercriminals might seem like the only feasible option to regain your files, it is strongly recommended not to contact the perpetrators. By giving in to the demands, victims are encouraging future attacks[1]. In addition to that, there's no guarantee that after paying the ransom, the victims will receive what's promised to them. Don't rush – we're here to help. Read through this article and try using our recommended removal, data recovery, and system fix options.
First things first, experts[2] advocate eliminating the threat immediately after detection. To automatically remove Termit ransomware from infected computer systems, use SpyHunterCombo Cleaner or MalwarebytesMalwarebytes apps. This software will not only locate, isolate, and delete the malware but prevent such threats in the future.
DCRTR ransomware family members are known for altering the targeted devices system files and settings to help them do their dirty deeds. So, following a successful Termit ransomware removal, it is highly recommended to tune-up your system to avoid your device from acting irregularly, like crashing, overheating, etc. A dependable FortectIntego tool will do the trick.
The short ransom note from the creators of Termit ransomware reads:
For decryption write here – ashtray@outlookpro.net (Write only in English)
If you do not receive an answer write here – askebeger@protonmail.comJabber contact for online communication (not always available, but I will answer as I see) – askebeger@xmpp.jp (xmpp.jp – registration, web client – hxxps://web.xabber.com )
Don't modify the files – you will ruin them. Test decryption < 500 kb (not databases and important files, only for demonstration of decryption)

Malware spreading techniques and means to avoid infections
The internet is full of malware hidden in plain sight. The most popular means the developers of malware are using to infect unsuspecting computer users' devices are with spam email campaigns[3] and malicious files camouflaged as pirated software installers or updater kits on torrent websites.
Some people prefer attempting to risk their online security by downloading pirated programs instead of relying on official, licensed software. And cybercriminals love to exploit that. They disguise their creations as so-called “cracks” (illegal activation toolkits for licensed software), game cheat codes, etc. Right after a download of such “helpful” software is done, an infection starts immediately. Soon to be victims might get any kind of malware – from ransomware to trojan horses[4]. To avoid dealing with the cybercriminals, losing your money and your data, support the developers of your sought-after software by buying it directly from them.
Spam campaigns are another popular way for cyberthieves to achieve their goals. During such campaigns, thousands of emails are sent out to unsuspecting computer users all over the world. Malware is usually hidden either in mischievous hyperlinks or infected email attachments. Prior to opening any email, make sure you know the sender. Scan all email attachments with a reliable anti-malware software before downloading them.
Guidelines for Termit ransomware removal from an infected machine
As mentioned in the first paragraph of this article, Termit ransomware removal is of utmost importance. Experts advise using reliable anti-virus SpyHunterCombo Cleaner or MalwarebytesMalwarebytes software to automatically find and delete the virus and all its allocated files. Furthermore, powerful anti-malware apps like these will safeguard your passageways on the internet in the future.

Regrettably, after you remove Termit ransomware, your files won't magically unlock. We sure hope you had backups of your sensitive data. That way, after performing a system tune-up with the FortectIntego tool, you can just retrieve your data from them. If you didn't have backups, then export all contaminated files to an offline storage and wait for a decryption tool to be made. Check back with us as we constantly update our readers with the most recent findings.
Was this guide helpful?
Be the first to comment