ZaLtOn – another member of the Xorist ransomware family

ZaLtOn virus is new ransomware belonging to the Xorist ransomware family. Once installed on a Windows machine, it encrypts users' data by adding an extension “.ZaLtOn” to all non-system files, such as your photos, documents, audio, video, and other personal files. What is relatively unique for this strain is that it uses the TEA algorithm[1] for data locking, and, besides delivering a regular text file “HOW TO DECRYPT FILES.txt,” it also changes the desktop of the infected computer. Pop-up windows might also emerge with the ransom demands.
The note consists of an explanation that users' files are encrypted and that the only way to get them back is to pay the required amount. The Xorist family ransomware usually demands from 0.3 to 2 Bitcoins for the promised decryption software/key. ZaLtOn isn't an exception – cybercriminals are asking for 0.11 Bitcoins to be transferred to their digital wallet (17cvUD9uzYk3fsCZzGyKNZ3aSgnoSKU3X7).
| NAME | ZaLtOn |
| FAMILY | Xorist ransomware |
| ADDED EXTENSION | .ZaLtOn |
| RANSOM NOTE | Seen on changed desktop wallpaper, pop-up error messages, HOW TO DECRYPT FILES.txt files |
| DEMANDED RANSOM | 0.11 Bitcoins |
| SYMPTOMS | Non-system files appear with a new extension – .ZaLtOn and are inaccessible. Desktop wallpaper changed to a ransom text, ransom note files appear in affected folders, irritating error pop-up windows appear |
| DANGER | Data loss, money loss if agreeing with the demands, system registry modification threat |
| DISTRIBUTION | Spam emails with infected attachments, Torrent sites with bogus software |
| CYBERCRIMINALS EMAIL | zalton@tuta.io |
| ELIMINATION | To eliminate ZaLtOn, you should acquire a reliable anti-malware software, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes and run a full system check. |
| SYSTEM FIX | This malware could have also altered your system registry and some system files, what might cause your system to work improperly. To fix and restore the damage done to your computer use FortectIntego tool. |
Victims found the aforementioned ransom demanding .txt files in all affected folders. The ransom message is the same in all its forms (wallpaper, .txt files, pop-up windows) on the infected computer system. This is what it says:
In your attention!!!
Hello, your server is very vulnerable, that's why you became a victim of ransomware
All your files are currently encrypted
However, there is also good news, the files can be decrypted if you pay 0.11 bitcoin.
All you have to do is follow the steps below.Buy 0.11 bitcoin, you can easily buy bitcoin from this sites:
www.localbitcoins.com
www.paxful.comSend the amount to this wallet: 17cvUD9uzYk3fsCZzGyKNZ3aSgnoSKU3X7
After sending, contact us at this email address: zalton@tuta.io
With this subject: –ATTENTION!! we do not receive emails sent from gmail accounts
Immediately after this you will receive an email with the keys and a small tutorial for decrypting the files.
Here's another list of where to buy bitcoin:
hxxps://bitcoin.org/en/exchanges
As always, we strongly recommend not to comply with the demands. There is no guarantee that after completing the payment in cryptocurrency, the user will regain access to their data. Furthermore, instead of a decryption tool, the criminals could send the victim some additional malware, such as trojans.[2] Trojans might gather sensitive information like the users' passwords, logins, etc., thus getting the victim into even more trouble.

To dodge these kinds of dealings in the future or remove ZaLtOn ransomware from your computer, we advise using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. If you are struggling with the process or malware is tampering with your security software, you can access Safe Mode with Networking and perform the scan from there.
Unfortunately, ZaLtOn ransomware removal won't decrypt your files. Prior to eliminating the ransomware, try and export as much of encrypted data as you can to an external backup. Regrettably, there is no third-party tool to unlock the encrypted data, but it might come up one day. In this day and age, it's very important to keep backups of your sensitive data in different kinds of locations, both online and offline.
As stated in VirusTotal.com, 55 out of 63 anti-virus (AVs) programs have recognized the ransomware. This shows how important is owning a dependable AV tool. Here are a few detection names by various vendors:[3]
- Ransom:Win32/Sorikrypt.A
- Trojan-Ransom.Win32.Xorist.lk
- Ransom-FASY!D8722DC3A9ED
- Trojan.Ransom.AIG
- Win32:Filecoder-M [Trj]
- Trojan-Ransom.Win32.Xorist.lk, etc.
ZaLtOn not only encrypts users' files it also might modify the system registry. That might lead to users' computers slowing down, crashing and showing other signs of malfunctions. To fix these issues, cyber victims should use a system optimization tool FortectIntego. This software can indicate and restore corrupted files/software, Windows Registry entries, etc.
Stay alert about malicious file attachments
Malware spreads in many ways, but the most usual means to get it is when downloading anything from an untrustworthy source or opening sketchy emails. Users might infect their systems while downloading some gaming cheat codes, illegal activation tools (aka “cracks”), opening email attachments from unknown, mischievous senders, downloading and installing pirated (illegally activated) software.
After a malicious file gets into your computer system, it might immediately initiate users' data encryption, additional malware downloads, start collecting users' sensitive information (e.g., passwords, logins, etc.), and so on. It depends on the type of the malware. The infectious files can come in many ways – .pdf, .txt. .jpeg, .exe files, etc. The best way to keep the cybercriminals' attempt at getting rich unsuccessful is to have a proper anti-malware software and keeping it up to date.

Remove ZaLtOn ransomware and all associated files
Manual ZaLtOn ransomware removal is very complicated, lengthy, and risky process. It's not recommended even for tech-savvy individuals. The virus might leave its traces all over the system, making the task practically impossible.
The best way to assure that the ransomware and all its associated files are completely removed from your computer is by using an anti-malware, security app with an excellent antivirus detection engine. SpyHunterCombo Cleaner and MalwarebytesMalwarebytes does the trick perfectly. These apps prevent your system from infection. If you were unlucky enough to obtain the virus, these apps will completely remove ZaLtOn ransomware fully.
Although the virus doesn't encrypt system files, it could still have altered them. That might cause your computer to work poorly, crash. Use FortectIntego to restore whatever damage to system files the malware might have done and enjoy your computer anew. Stay safe!
Was this guide helpful?
Be the first to comment