Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2018

How to remove Tornado ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Tornado ransomware appends .[dongeswas@tutanota.com].Tornado file extension to encrypted files

Showing Tornado ransomware

Tornado virus belongs to the crypto-malware[1] category of computer viruses since it infects random PC's and targets to encrypt personal files and, later on, demand a ransom. Once the virus is executed onto the system, it renders most of the file types useless by locking them with RSA[2] encryption algorithm. Consequently, all encrypted files get the .[dongeswas@tutanota.com].Tornado file extension. If the encryption is executed successfully, Tornado ransomware creates a .txt file in each folder, which contains at least one encrypted file.

The text file stands for a ransom note where ransomware developer “greets” the victim and outlines the current situation in which he or she is currently in. Although the text in Tornado ransom note may slightly vary, here's the initial version found by ransomware researchers:

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail: helpcrypt@airmail.cc.You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.In case of no answer in 48 hours write us to theese e-mails: supphelp@cock.li

Tornado is similar to many other file-encrypting ransomware regarding encryption and ransom transfer methods applied. Its developers ask the victim to contact them via email (helpcrypt@airmail.cc or supphelp@cock.li) ASAP to ask for a unique decryption code. The sooner the contact is established, the smaller the ransom is expected to be.

Currently, it's not clear how many Bitcoins[3] the Tornado ransomware virus demands, but it may vary from 0.5 to 3 Bitcoins depending on how many hours the victim hesitates to contact with the extortionists. However, it's not advisable to pay the ransom even if it's not that big. There's no guarantee that criminals do have a working decryption code or that they are going to send it to you once you transfer the ransom.

Tornado removal is the best option you have. At the moment of writing, 40 AV engines out of 66[4] are capable of detecting and immunizing this cyber threat. Thus, a reputable anti-virus with updated security definitions, for example, FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes will remove Tornado virus from the system. In many cases, Tornado ransomware is considered to be a variant of BTCWare ransomware because most AV engines identify them in the same way. However, the ransowmare analysts did not approve that.

The bad news is that Tornado removal will swipe all encrypted files away. The good news is that cyber security experts have already found Tornado decrypter that you can download from the Internet for free. If, however, it fails to work, there's a couple of alternative data recovery methods that you can use. 

Tornado ransomware removal tutorial

Ransomware is executed via malicious email attachments

Although there's a handful of diverse virus distribution strategies, including drive-by-download, remote desktop flaws, malicious websites, ads, etc., malspam remains the most frequently used ransomware distribution technique.

Those who haven't received spam emails should be aware of various letters from unknown senders, which claim to deliver important documents (invoices, receipts) or files like .docs, .txt, .jpg, and similar. Usually, people have to enable Macros to open the malicious attachment, and that's where the trick lies. Enabling Macros drops the executable file of the ransomware, which immediately starts scanning the system and locking personal files stored on it.

Therefore, cyber security experts from novirus.co[5] strongly recommend people to pay close attention to the email messages that you open and, if you are not familiar with the sender, do not open the attachment. Double-check doubtful messages for grammar and type mistakes because authorities will never send an official message that contains errors in the name or subject. By the way, messages without body text should never be treated as serious. Empty text box signals spam immediately. If you noticed that your inbox is full of spam, you should report the senders as spam.

Tornado ransomware removal guide

Ransomware virus can hardly be removed manually due to the multiplicity of malicious files. Therefore, the only reliable way to remove Tornado ransomware virus is to run a full system scan with FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes program. Otherwise, you may leave some of the malicious files, which may download other malware to the system.

Ransomware researchers were quick to find the Tornado decrypter. Therefore, right after the removal of the virus, you will be able to recover all locked files by launching it.

If Tornado decrypter failed to recover some of the important files, try to apply alternative decryption methods that you can also find at the end of this post.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.