Unrans threatens to increase the ransom if victims don’t pay by the given deadline

Unrans is a file-encrypting malware that might target not only computers but servers as well. After the infiltration and data encryption using AES cryptography, the malicious program delivers a RansomText.txt file that includes a link to Tor-website.[1] Here victims are asked to pay 0.5 Bitcoins for data recovery.
In the Tor payment website, authors of the Unrans ransomware provide a Bitcoin wallet[2] address where victims are asked to transfer the money. The ransom note also includes a timer that shows when the size of the ransom will increase, so victims are urged to make a transaction quickly.
Additionally, crooks also offer to restore one file which is smaller than 5MB for free encryption. Victims have to send their unique ID number which is provided in the RansomText.txt file and test file to krom.mork@openmail.cc. Authors of Unrans virus promise to respond with the encrypted file.
The ransom note gives further instructions. Once the payment is made, victims will get a decryption key and have to download Unrans.ps1 decryptor from the payment website. However, security experts do not recommend following these instructions because this may lead to money loss.
Nevertheless, creators of Unrans malware give a guarantee that they have a decryption software; this may be the only one file that you manage to get back. Ransomware-type cyber threats are created for illegal money-making purposes. Thus, once they get your money, the goal is completed.
Therefore, after the cyber attack, we highly recommend focusing on Unrans removal. Malware makes critical changes to the system. As a result, the system becomes sluggish and insecure. In some cases, malicious programs can open a backdoor to other cyber threats. Thus, security measures have to be taken.
You should remove Unrans ransomware using professional malware removal program, for instance FortectIntego. We do not recommend trying to locate malicious components manually because it may lead to the irreparable damage to the system. Meanwhile, reputable security software can wipe out dangerous components safely.

Methods used to spread crypto-malware
There are many ways how ransomware can get installed on your computer. However, most of the time it sneaks inside the system when you are tricked into opening a malicious email attachment. Usually, it looks like a safe and legitimate file, for instance, Microsoft Word document. However, once clicked, it downloads malware payload to the system.
Additionally, ransomware can get inside the system using these strategies:
- malvertising;
- fake updates;
- illegal downloads;
- exploit kits;
- RDP attacks.
Security specialists from bedynet.ru[3] remind to be careful with email attachments and avoid questionable content. Do not click suspicious ads and do not use unknown download websites. Always install programs from the official developer’s sites.
Keeping software updated is also necessary because security vulnerabilities can be exploited to launch the attack. Additionally, you should protect your PC with an antivirus and create backups.
Removal of the Unrans virus
Unrans removal has to be completed with the help of reputable malware removal software, such as FortectIntego or MalwarebytesMalwarebytes. As we have already mentioned, malware can affect various system processes and download malicious components to the system. Thus, it needs complex removal.
However, in order to remove Unrans without any problems, you should reboot the system to Safe Mode with Networking first (instructions below). This will help to disable the virus and run security software. If you boot the system normally, malware might block your attempts to run anti-malware tool.
Once you get rid of the virus, you can recover your data from backups. Below you can also find additional recovery methods that might help if you do not have copies of your files. However, researchers haven’t released Unrans decryptor yet. Thus, data recovery without backups might not be very successful.
Did this guide help?
Be the first to comment