Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Aug 2018

How to remove Zoldon Crypter ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Zoldon Crypter ransomware – a sophisticated file encrypting virus that also mines cyryptocurrency

Zoldon Crypter ransomware

Zoldon ransomware is an advanced piece of malware that is capable of encrypting files and making them unusable, as well as injecting Bitcoin Miner Pro V3.1.exe that would secretly mine cryptocurrency on the infected machine. As soon as the payload is distributed, the malware encrypts all files using AES-256[1] cipher and displays ZOLDON Crypter V3.0 program that shows the ransom note. It urges users to contact cybercriminals via the zoldon-staff@mail.ru email after a payment of $150 in Bitcoin is transferred. Hackers also warn that the ransom size will be upped to $400 in 24 hours. Zoldon Crypter virus does not use any additional file extensions to encipher files.

SUMMARY
Name Zoldon Crypter
Type Ransomware/Trojan – cryptominer
Related files Bitcoin Miner Pro V3.1.exe, 
Ransom note ZOLDON Crypter V3.0
Cipher used AES-256
Extension None
Ransom size $150 in BTC ($400 in 24 hours)
Contact email zoldon-staff@mail.ru
Elimination Download and install FortectIntego or MalwarebytesMalwarebytes

Zoldon Crypter ransomware can get into users' PCs via contaminated spam email attachments, from malicious JavaScripts[2] on compromised websites, as well as breakthrough via insecure RDP configuration. Therefore, certain precaution measures would profoundly decrease the chance of Zoldon virus infection.

Unlike viruses like Animus, FileEncrypted, Magniber, Zoldon ransomware does not add any extensions to the encrypted files. The ransom note DesktopZoldon.txt is also present but does not execute correctly due to the mistake in the code. Nevertheless, victims get all the information from the ZOLDON Crypter V3.0 application that is launched right after data encryption:

Alert: Your computer and Files are encrypted By Zoldon Virus
$150 within 24 hours. $400 after 24 hours

———–Write this information down———-
Email: zoldon-staff@mail.ru
———————————————————-
How to remove the virus?
After the payment send to Bitcoin Address,
send email to [zoldon-staff@mail.ru] containing Your Machine ID
Once payment is received, you will get the decryption password
and simple instructions to restore all your files and computer to normal instantly
Without the decryption password, you will not get them back.
If we do not reach the amount within 72 hours
We will punish all the contents of your device on the Internet
———————————————————-
IF YOU LOOSE THIS INFO, YOU WILL NOT BE ABLE TO CONTACT US

Although Zoldon virus authors try to scare users by declaring that their files will be lost within 24 hours, victims should not contact hackers and remove Zoldon ransomware trojan using reputable security software. We advise picking FortectIntego or MalwarebytesMalwarebytes.

Those who do contact criminals risk not only losing their file but also money. Security researchers[3] warn that malware authors often ignore victims and merely keep the money without giving the decryptor. Additionally, those who will successfully retrieve the decoder might be targeted by Zoldon Crypter developers again.

Although Zoldon ransomware is not decryptable yet, users should retrieve their files from a backup (such as external storage drives or remote server). Those who failed to prepare a backup before the virus struck can try using third-party applications to get their data. However, chances of such outcome are low, as Zoldon Crypter removes Shadow Volume copies.

While users may be devastated because of the encrypted personal files (malware targets databases, image files, pictures, videos, documents and similar), the virus also utilizes compromised machine's hardware to mine cryptocurrency for hackers. Such activity might result in high electricity bills, as well as lowered PC performance. For that reason, Zoldon Crypter ransomware removal should be performed as soon as possible.

Zoldon Crypter virus

Ransomware can affect anybody who is not careful enough online

While many people consider ransomware attacks something that they saw on the news, it is by far more accessible than one might think. Even users who avoid dodgy websites can be at risk. That is because malware has various distribution methods, and not everybody is aware of them. While there is no way to protect yourself 100%, but there are several precautions that can significantly reduce the chance of infection:

  • Do not open attachments of suspicious emails. Spam emails are one of the most prominent ransomware distribution techniques, merely because it is so effective and requires minimum effort from cybercriminals' side. Thus, beware that some phishing emails might look authentic, but hide malware payload inside.
  • Employ reputable security software. Those who neglect security measures and refuse to install anti-malware software are at the highest risk. Developers often update databases so that the newest viruses would be caught before infiltration.
  • Update your software promptly. Software vulnerabilities is another way for hackers to inject malware relatively easily. Security patches of popular software like Adobe or Flash are especially critical.
  • Stay aware from dubious sites. Visiting a compromised or a malicious website can result in malware infection (especially if PUP, such as adware is hiding inside the machine). Therefore, users should never click on suspicious ads and close down their browsers if they get redirected.
  • Use strong passwords. Never use the same password for multiple accounts, and make sure you change them often. Brute-force attacks are quite common when it comes to malware infiltration.

Delete Zoldon Crypter ransomware instead of contacting cybercrooks

If you were unlucky enough and contaminated your PC with Zoldon virus, you should not panic, as contacting cybercriminals is the worst idea. As we already mentioned, they can simply ignore you even after the payment is processed, making your lose not only your files but also money.

Therefore, you should hurry and remove Zoldon ransomware from your computer instead. However, do not try to perform the elimination manually, as the complex virus should only be removed by using professional security software. Of course, you can try to perform manual Zoldon Crypter removal if you are a trained IT professional.

Only after the Zoldon virus is removed, you can try to get your files back. You should use your backups if you had any. If not, your last hope is third-party software. You will find all the instructions below this article.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.