Vurten is a ransomware virus that demands $ 10,000 for a decryptor

Vurten is a crypto-virus that has been revealed at the beginning of April 2018. The malware employs AES cryptography[1] to lock files on a targeted system. Encrypted files are distinguished from the others by .improved file extension. Upon successful encryption, Vurten ransomware creates a ransom note called UNCRYPT.README.txt, which demands the victim to pay $ 10,000 in Bitcoins for a unique decryptor.
| Name | Vurten |
|---|---|
| Type | Ransomware |
| Danger level | High. Corrupts core system's components and locks personal data |
| Distribution | Malicious spam email attachments, exploit kits, rogue software, drive-by-download |
| File extension | .improved |
| Ransom note | UNCRYPT.README.txt |
| Ransom demanded | $ 10,000 in Bitcoins |
| Boot the system into Safe Mode with Networking. Download FortectIntego and run a scan to delete Vurten ransomware | |
The ransomware hasn't yet been translated into languages. Its original version is written in English, so experts warn English-speaking users to mind the rules of safe web browsing. Experts from NoVirus.uk[2] stress the important to filter suspicious email messages out. Vurten ransomware is distributed via malicious spam email attachments (DOC and DOCX files) most actively. However, it can also be transmitted via exploit kits and fake software updates.
As soon as the payload is executed, Vurten virus starts scanning the system for targeted files. Using Administrative privileges, it runs scripts via Command Prompt to root into the OS and enable AES-256 cipher. Consequently, most of the personal files are appended with .improved file extension and cannot be read.
The information provided for the victim is not explicit, though it's sufficient for making the payment. The UNCRYPT.README.txt file says:
Your entire network is sensible data encrypted with our strong algorithm.
To recover your data send $ 10000 to the bitcoin address: 1Ln9RxSRuDqqFhCTuqBPBKRMeyhVhRaUG4
If you do not send money within 7 days, payment will be increased double.
After payment you will receive decryption software.
Contact email: vurten_knyert@protonmail.com
Developers of the Vurten ransomware virus are quite immodest. The decryptor they offer costs $ 10,000, which is by far the highest ransom demanded this year.[3] The deadline for payment is seven days, which is supposed to be sufficient to collect a required sum. Nevertheless, we do not recommend paying the ransom. Not only because it's abnormally high, but because there's a risk that hackers will send you a useless decryptor or a severe cyber infection (rootkit, spyware, worm, etc.).
If you fall victim to this crypto malware, run a scan with FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes and remove Vurten virus asap. The malware initiates multiple system's changes, including Windows Registry, boot options, and other system's parameters. Thus, Vurten removal is a must if you want to use your PC normally.

The ransomware hasn't yet spread widely, though experts specultate that it may be targetting large companies. That may be the reason why extortionists require for $ 10,000 . The ransomware targets the most popular file types, including but not limited to:
.Png, .psd, .pspimage, .tga, .thm, .tif, .tiff, .yuv, .ai, .eps, .ps, .svg, .indd, .pct, .pdf, .xlr, .xls, .xlsx, .accdb, .db, .dbf, .mdb, .pdb, .sql, .apk, .app, .bat, .cgi, .com, .exe, .gadget, .jar, .pif, .wsf, .dem, .gam, .nes, .rom, .sav, .dwg, .dxf, .gpx, .kml, .kmz, .asp, .aspx, .cer, .cfm, .csr, .css, .htm, .html, .js, .jsp, .php, .rss, .xhtml, .doc, .docx, .log, .msg, .odt, .pages, .rtf, .tex, .txt, .wpd, .wps, .csv, .dat, .ged, .key, .keychain, .pps, .ppt, .pptx, .ini, .prf, .hqx, .mim, .uue, .7z, .cbr, .deb, .gz, .pkg, .rar, .rpm, .sitx, .tar.gz, .zip, .zipx, .bin, .cue, .dmg, .iso, .mdf, .toast, .vcd, .sdf, .tar, .tax2014, .tax2015, .vcf, .xml, .aif, .iff, .m3u, .m4a, .mid, .mp3, .mpa, .wav, .wma, .3g2, .3gp, .asf, .avi, .flv, .m4v, .mov, .mp4, .mpg, .rm, .srt, .swf, .vob, .wmv, .3d, .3dm, .3ds, .max, .obj, .r.bmp, .dds, .gif, .jpg, .crx, .plugin, .fnt, .fon, .otf, .ttf, .cab, .cpl, .cur, .deskthemepack, .dll, .dmp, .drv, .icns, .ico, .lnk, .sys, .cfg.
Even though .improved file extension virus might lock most of the files on the system, do not rush to pay the ransom. Instead of that, remove Vurten virus and try to recover your files with the help of third-party software. You can find explicit recovery instructions at the end of this article.
Distribution campaigns do not change
In general, ransomware viruses are known for the employment of extr4emelly misleading distribution techniques, such as:
- Malspam. Hackers rely on spam bots to spread deceptive emails from well-known companies reporting parcel shipment problems, debts, and similar. The messages contain an attachment (dox, doc, pdf, png, and other formats that disguise a malicious .exe file).
- Fake software updates. Pop-up ads or new tab URL ads warning about updated software or critical vulnerabilities that can supposedly be patched by installing the update.
- Exploit kits. Hackers employ a specific toolkit to reveal system's vulnerabilities and attack them to inject ransomware payload.
- Illegal websites. Pornographic or gambling sites, as well as fake domains, can be infected with JavaScript code. They can contain malicious ads or download ransomware by default.
The listy is not definitive, but other methods are less commonly used. Anyway, it's important to keep OS updated and download software updates regularly to patch system's vulnerabilities. Besides, keep a reputable antivirus installed and update its definitions as frequently as possible.
Finally, do not fall for opening suspicious emails. If the sender is unknown, the message contains grammar or typo mistakes; it's better to report the email as spam and delete it.
Instructions on how to delete Vurten ransomware virus
Even though you have $ 10, 000 in your pocket, we do not recommend paying the ransom. Cybercriminals cannot be trusted since no one knows whether they have a working Vurten decryptor or not.
You should remove Vurten from the system entirely using FortectIntego, MalwarebytesMalwarebytes or SpyHunterCombo Cleaner, but many other tools can help you as well. Manual removal is not possible since the virus corrupts core system's components, such as Registry Entries.
Once the Vurten removal is finished, you can retrieve locked data from backups or rely on third-party software. There's a variety of methods that can help you to get the access to your data back.
Did this guide help?
Be the first to comment