Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2018

How to remove UselessDisk ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

UselessDisk is a bootlocker ransomware that demands to pay 300 USD to boot into Windows

UselessDisk ransomware belongs to the group[ of bootlockers

UselessDisk is a bootloader ransomware virus that can also be recognized as DiskWriter or MBR bootlocker. Ransomware researchers detected it at the end of March 2018 spreading DiskWriter.exe or UselessDisk.exe files. Once installed, it corrupts the Master Boot Record sequence and prevents Windows from booting. Instead, it generates a ransom screen and asks to pay 300 USD via 1GZCw453MzQr8V2VAgJpRmKBYRDUJ8kzco Bitcoin wallet.

Name UselessDisk
Type of malware Ransomware
Sub-type Lock-screen
Related malware DiskWriter and MBR bootlocker
Symptoms Windows does not boot, gets stuck with UselessDisk ransom screen. Ransom demanded
Distribution Malspam campaigns, exploit kits, corrupted RDP configuratios, fake software updates, phishing websites, etc. 
Related files DiskWriter.exe and UselessDisk.exe
Elimination process To get rid of UselessDisk by booting Windows into Safe Mode and running a scan with FortectIntego

As soon as the system is infected with UselessDisk ransomware, the virus overwrites the Master Boot Record (MBR),[1] which is a Windows boot sector located on a hard drive or another core system's location that is crucial for the boot process to be processed. It replaces the system's MBR with its source code and the runs a shutdown -r -t 0 script on Command Prompt using administrative privileges.

Consequently, the system gets stuck at Windows boot and, instead of displaying an endless loop or regular Windows boot screen, it generates the following UselessDisk ransom screen:

Oops, your important files are encrypted.
If you see this text, then your files are not accessible, because they've been encrypted.
Maybe you're busy looking for a way to recover your files,but don't
waste your time. Nobody can recover your files without our decryption service.

In order to decrypt, please Send $300 worth of Bitcoin to this address:
1GZCw453MzQr8V2VAgJpRmKBYRDUJ8kzco

The ransom screen does not contain explicit information on how to recover files encrypted by DiskWriter ransomware. It does not include the name of a virus or a personal victim's ID that would let criminals to recognize who transferred the payment. Crooks provide indicate the amount of the ransom (300 USD) and ask to transfer it in Bitcoins via the 1GZCw453MzQr8V2VAgJpRmKBYRDUJ8kzco wallet.

The victim is urged to pay the ransom to remove the UselessDisk ransomware and boot the system again. However, experts from NoVirus.uk[2] recommend not to pay the smallest fraction of Bitcoin for the crooks who developed this infection. It seems that this lock-screen virus causes permanent data loss and needs serious maintenance.

Based on the DiskWriter ransomware analysis, the thieves do not indicate their contacts (except the address of Bitcoin wallet), which does not refer to any specificities of the owner. Besides, the criminals won't be able to recognize who paid the ransom, so they won't know which PC has to be unlocked.

UselessDisk  lock screen

Therefore, DO NOT pay the ransom because it does not seem to have a valid decryptor or UselessDisk removal tool. You should remove the infection instead and then try to recover locked or deleted data with the help of third-party recovery tools.

It's not possible to remove UselessDisk ransomware from the system by fixing the MBR. After that, the system fails to boot normally and displays an error of a Master File Table (MTF). To initiate a full UselessDisk removal, you should boot your PC into Safe Mode with Networking and run a full system scan with FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. We would highly recommend using Reimage as it functions as a powerful Windows optimizer and anti-virus simultaneously.

The ransomware can be disguised under fake software updates

The dissemination strategies of this lock-screen ransomware do not differ from the ones used by crypto-ransomware viruses. The following are the techniques that its developers can use to trick less experienced PC users into a trap:

  • Malspam campaigns;[3] 
  • Corrupted RDP configuration;
  • Drive-by-download attacks;
  • Exploit kits;
  • Fake software updates;
  • Phishing websites;
  • Malicious downloads on peer-to-peer networks, etc.

Anyway, this particular ransomware will be disguised under DiskWriter.exe or UselessDisk.exe files. In case of spam email, the file attachment may be disclosed as a DOC, PNG, DOCX, JPG, or other popular file formats to trick users into opening it. Nevertheless, the fake document will eventually load a DiskWriter.exe or UselessDisk.exe payload.

To protect yourself from attack, make sure to install a powerful anti-virus with a real-time protection feature and don't forget to update definitions regularly. Besides, avoid visiting illegal websites or clicking on phishy looking ads, links, and other content.

Uninstall UselessDisk ransomware virus

UselessDisk removal is a complicated task to perform. The virus affects both the MBR and MTF records. The changes not only prevents Windows from boot but can also corrupt personal files and render them inaccessible permanently.

Thus, we would not recommend you to remove UselessDisk virus with the help of a professional anti-malware. Since you cannot boot into Windows, try to boot it into Safe Mode with networking and run a scan. If you cannot do so, you may need help from a professional IT technician.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.