Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2018

How to remove Unlock92 2.0 ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Unlock92 2.0 is a ransomware virus that encrypts various types of files

Unlock92 2.0 is a file-encrypting virus that uses RSA-2048[1] cryptography to lock files on the affected device. Malware emerged in 2016 as a version of Unlock92 ransomware. The virus appends .CRRRT, .CCCRRRPPP, . block and .cdrpt file extensions to the targeted documents, multimedia, archives, databases, and other important data.

Summary
Name Unlock92 2.0
Family Unlock92 ransomware
Type Ransomware
Release 2016
Targeted OS Windows
Mostly affected country Russia
Cryptography RSA-2048
File extensions .CRRRT, .CCCRRRPPP, . block and .cdrpt
Distribution Malicious email attachments
Data recovery Impossible without backups
To uninstall Unlock92 2.0, install FortectIntego and run a full system scan

The main target of the Unlock92 2.0 ransomware seems to be Russian-speaking computer users. This assumption has been made due to the ransom note. Soon after data encryption, malware drops a ransom note in ORID.jpg file which becomes a new computer’s wallpaper. The ransom note is written in the Russian[2] language:

Ваши файлы зашифрованы с использованием криптостойкого алгоритма RSA-2048.
Если хотите их вернуть отправьте один из зашифрованных файлов и файл keyvalue.bin на e-mail: unlock92@india.com
Если вы не получили ответа в течение суток то скачайте с сайта www.torproject.con браузер TOR и с его помощью зайдите на сайт:
http://fnjmegsn7tbrrnkl.onion – там будет указан действующий почтовый ящик. Без браузера TOR зайти на этот сайт невозможно.
Попытки самостоятельного восстановления файлов могут безвозвратно их испортить!

Unlock92 2.0 ransom note

Authors of the Unlock92 2.0 virus ask to send one encrypted file to unlock92@india.com and wait for their response. After that, victims are asked to download a TOR[3] browser and access specific website, where they can learn more about data recovery.

Unlock92 2.0 payment site

However, we do not recommend contacting them and following their instructions. You will be asked to pay a specific amount of Bitcoins for the data decryption software, but it doesn’t mean that crooks actually have it or are willing to let you use it even if you pay the ransom.

Unfortunately, malware researchers haven’t cracked ransomware’s code and haven’t released a free decryption software. However, victims report that Unlock92 2.0 fails to delete Shadow Volume Copies[4], so they were able to decrypt the majority of their files with ShadowExplorer and similar tools. Hence, there’s a chance to get back your files.

Unlock92 2.0 encrypted files

However, before you proceed with data recovery, you need to remove Unlock92 2.0 from the computer. While malware resides on the PC, it can encrypt files again and again after the system reboot. Additionally, if you think about plugging in the external drive with backups, you might get this device affected too.

Unlock92 2.0 removal requires scanning the computer with a reputable anti-malware software like FortectIntego or SpyHunterCombo Cleaner. Before downloading, installing, updating or running security software, you should reboot the device to Safe Mode with Networking as explained at the end of the article.

Unlock92 2.0 ransomware virus example

Malicious spam emails are used to spread ransomware's executable

Developers rely on the popular malware distribution method – malspam. This method allows sending a bunch of emails that inform about various issues, such as, failure to deliver a parcel, necessity to check invoice details, etc. Criminals often pretend to be from popular companies or organizations and copy their credentials. So, fraudulent emails might be hard to recognize.

Additionally, these messages from crooks include a link or button that leads to the infected website or has an attachment. As soon as a victim opens an attached Word, PDF or ZIP archive, malware executable is dropped and immediately activated on the computer.

Unlock92 2.0 malware

Therefore, it is highly recommended to stay attentive and does not rush opening any file appeared in your inbox. It’s important to check email’s credibility:[5]

  • Check the information about the sender;
  • Make sure that the email is actually used by the organization/company the sender claims to be;
  • Look up for grammar, spelling or use of English mistakes;
  • Check the attachment with online virus scanners without downloading it;
  • Make sure that the letter has the same design and credentials, e.g., logo or signature.

Uninstall Unlock92 2.0 ransomware virus and try alternative recovery methods

Unlock92 2.0 removal is completed with anti-malware software. We want to specify that free security programs usually are too weak for cleaning malicious components from the system. Hence, you should invest in professional software that can get rid of malware-related components but can protect from cyber threats in the future too.

There are plenty of tools that can help to remove Unlock92 2.0, but we suggest using either FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. However, if ransomware blocks access to your chosen anti-malware, you should follow the instructions below in order to disable the virus.

Once your anti-malware or anti-virus deletes ransomware-related files, you can recover corrupted files from backups or try third-party recovery solutions. We have explained them below.

Did this guide help?

2 comments

  1. Unlocktintin

    It seems like true nightmare having your files taken away from you...

  2. Enrish800

    Ugh. I had no important files on my pc but it was truly a pain to get rid of it

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.