Tron is ransomware that got renewed with a new extension in November 2018

Tron ransomware is a cryptovirus that has been spreading around and locking users' data since April 2018. This dangerous cyber infection belongs to Dharma ransomware family which appears to be especially active this fall because of the recently released versions Audit ransomware, Xxxxx ransomware, and Gamma ransomware. Once inside the system, the virus initiates unauthorized changes and locks personal files using AES encryption algorithm. Currently, Tron ransomware virus has a new version that uses EasyHook payload dropping technique.[1] This variant appends .id-ID.[xtron@cock.li].tron file extension and is targeting English-speaking users. This ransomware virus[2] can also be indicated by the email address xtron@cock.li which can be found in the FILES ENCRYPTED.txt ransom note filled with more details about the attack and required payments.
| Name | Tron |
|---|---|
| Classification | Ransomware |
| Symptoms | Personal files feature .tron file extension and cannot be opened. |
| Related | Dharma |
| File extension | .tron |
| Ransom note | FILES ENCRYPTED.txt; xtron@cock.li |
| Encryption method | AES-256 |
| Danger level | High. Locks files, urges victim to pay the ransom, tries to evade Tron removal |
| Contact info | supportjron@gmail.com; xtron@cock.li |
| Size of redemption | 0.05 BTC |
| Download FortectIntego and run a scan with it to eliminate Tron ransomware virus | |
One of the most popular cyber infection targets users all over the world and based on previous versions of the Dharma family this is a persistent threat. Recently discovered with a new feature – .NET payload dropper. This is a programming framework that makes designing malware easier.
The ransom note is a short message placed in FILES ENCRYPTED.txt file and contains the following:
all your data has been locked us
You want to return?
write email xtron@cock.li or xtron@fros.cc
However, the main information about the payment, encryption and other vital processes displayed in the pop-up window that appears on the screen with payment instructions and the offer to test decrypt one file. Unfortunately, there is no guarantee that it is possible. You shouldn't follow this suggestion and better remove Tron ransomware using reputable anti-malware tools like FortectIntego instead of paying cybercriminals.
The whole ransomware attack starts with system modifications, and cryptovirus can make changes in various parts of the system the minute it gets on the targeted device. According to cybersecurity experts from dieviren.de,[3] if the location of your device falls for the target list, crypto-ransomware enables AES-256 cipher and starts data encryption. It locks all file types that are located in the following folders:
- Recent
- MyPicture
- MyMusic
- MyVideos
- Personal
- Favorites
- CommonDocuments
- CommonPictures
- CommonMusic
- CommonVideos
- CommonDesktopDirektory
- Desktop

It will also corrupt AppData and LocalAppData folders. Each encrypted file will be marked with .tron file extension. It does not drop the ransom note in a typical way. The victim is redirected to the window of instructions when he or she attempts to click on a file encrypted by Tron ransomware virus. The note contains the following information:
All your files are encrypted
What happened to my computer?
Your important files are encrypted. Many of your documents, photos, videos, databases and other files are no longer accessible because they have been encrypted. Maybe you are busy looking for a way to recover your files, but do not waste your time. Nobody can recover your files without our decryption service.
Can i Recover my Files?
Sure, We guarantee that you can recover II your files safely and easily.
But you have not so enough time. You have only have 10 days to submit the payment. Also, if you don't pay in 10 days, you won't be able to recover your files forever.How Do I pay?
Payment is accepted in bitcoin only. For more information, click “How to buy Bitcoin”. Please check the current price of bitcoin and buy some bitcoins. And send the correct amount to the address specified in the window. After your payment you need to write to us on mail. We will decrypt your files.
We strongly recommend you to not remove this software, and disable your anti-virus for a while, until! you pay and the payment gets processed, if your anti-virus gets updated and removes this software automatically, it will not be able to recover your files even if you pay!
Amount 0.05 [ Copy ]
Bitcoin address DzNaZiWzBwUr8ymWHcSzbYGidutRNDuEs [Copy]
EMAIL supportjron @gmail .com [Copy]
[HOW TO BUY BITCOIN]
Tron ransomware virus demands its victims to pay a 0.05 BTC (approximately 400 USD) within ten days. The victim is asked to write an email to supportjron@gmail.com and indicate a personal ID number.
However, we would not recommend communicating with hackers or even more paying the ransom. There's no guarantee that they will provide you with a working Tron decryptor. It might be that they do not store one at all.
In case of attack, we would strongly recommend you to download FortectIntego, SpyHunterCombo Cleaner, MalwarebytesMalwarebytes or another professional anti-virus program, and run a full system scan with it. Beware that outdated anti-virus might lack for definitions and fail to remove Tron ransomware. Therefore, we would strongly recommend you to initiate the removal with an updated security tool only.

Suspicious emails contain high-risk attachments with malware scripts
Hackers know many strategies to disseminate cyber infections on a massive scale. They exploit multiple social engineering techniques,[4] including but not limited to malspam, fake software updates, phishing sites, and so on.
Nevertheless, malicious spam email attachments are the primary method used to spread ransomware for more than a decade. Crooks impersonate authorities or well-known companies and address relevant topics, such as lawns, payments, taxes, and so on. Spam emails can contain either an infected link or an attachment.
Apart from spam emails, be extremely careful with rogue software updates and other questionable offers that show up on suspicious websites in the form of a pop-up. Clicking on misleading ads and other content can trick you into downloading the potentially unwanted program (PUP) if not ransomware.
Remove Tron ransomware using reputable anti-malware tools
Tron ransomware removal is the main thing that should concern you in case most of your files exhibit .tron file extension. Do not fall for converting your money to Bitcoin and sending them to crooks. That may appear to be a total waste of both money and time because criminals may not respond you at all.
To prevent this from happening, we would recommend you to remove Tron ransomware from the system using FortectIntego, SpyHunterCombo Cleaner, MalwarebytesMalwarebytes or another professional malware removal tool and then try to retrieve your data using alternative methods.
If you have backups, you don't have to worry. Get rid of Tron and then recover data using backups. If you don't have backups, try to exploit Volume Shadow Copies, Previous Windows versions or use Data Recover Pro. Follow methods below the article.
Did this guide help?
Be the first to comment