Mado Virus (. Mado Files Ransomware) – Decrypt & Removal Tool
36″Mado” Viruswhat Is “Mado”? Ransomware Is a Kind of Virus That Crypted Your Documents and Then Forces You to Pay for Them. Djvu (Aka Stop) Ransomware Family...
36″Mado” Virus
What is “Mado”?
Ransomware is a kind of virus that crypted your documents and then forces you to pay for them. DJVU (aka STOP) ransomware family was first revealed and analyzed by virus analyst Michael Gillespie">2.
Mado is similar to other ransomware like: Jope,Opqz, Npsk, Remk. It crypted all popular file types. Hence, users can’t open files. Mado adds its particular “.mado” extension into all files after encryption. For instance, the file “video.avi”, will be amended into “video.avi.mado”. As soon as the encryption is accomplished, Mado drops a special text file “_readme.txt” and adds it into all folders that contain the modified files.
| Ransomware family3 | DJVU/STOP4 ransomware |
| Extension | .mado |
| Ransomware note | _readme.txt |
| Ransom | From $490 to $980 (in Bitcoins) |
| Contact | , |
| Detection5 | BScope.TrojanSpy.Zbot, Trojan-Dropper.Win32.Dropback.ln, Trojan:Win32/Glupteba.RDL!MTB |
| Symptoms | Your files (photos, videos, documents) have a .mado extension and you can’t open it |
| Fix Tool | See If Your System Has Been Affected by .mado file virus |
This text asking payment is for restore files via decryption key:
The scary alert demanding from users to pay the ransom to decrypt the encoded data contains these frustrating warnings: _readme_txt
The cryptography algorithm used by Mado is AES-256. So, if your files got encrypted with a specific decryption key, which is totally unique and there are no other copies. The sad reality is that it is impossible to recover the information without the unique key available.
In case if Mado worked in online mode, it is impossible for you to gain access to the AES-256 key. It is stored on a remote server owned by the criminals who promote the Mado ransomware.
There are also some reports that saying about Mado ransomware add it’s readme.txt file in autoload registry bush, so every time user logging in his system, he will get annoying reminder. This causes are not widespread, but, as we can see, Mado has a lot of subversions that have a lot of distinction in it’s performance.
But adding his entities to Run key is not the only Mado ransomware action with registry. The common practice is that it adds it’s .exe file in the RunOnce key. So, every time user starts Windows – ransomware will start, too, so you can’t stop ransomware with simple system restart. But, it could be prevented with system launch in special mode – safe mode or mode with command line support.
In spite of registry, Mado ransomware can also change hosts file to disable Windows updates. Thus, Windows can’t perform “self-cleaning”, changing all it’s internal settings, registry keys and directories on the C:/ to default. So, if you used to have Windows updates regulary, and notice that your PC haven’t got them for a long time – it can be a sign of slow Mado ransomware activity on your PC.
One of the most knavish trick of Mado ransomware is hosts file editing. It can add all popular sites of anti-malware softare, forums, where ransomwares are disscussed, to hosts file. So, you wouldn’t able to open this pages. It’s quite easy to fix, but not being in panic and having the only wish to get your files back.
Jope ransomware distributors understand, that a huge part of their victims can be get cured using advices given on such sites. So, they are usually blocking all sites you can see below:
This list is updating.
For receiving decryption key the payment should be $980. To obtain the payment details the victims are encouraged by the message to contact the frauds by email ().
N.B. Some users, generally from Western Europe, reporting about modified readme.txt files, that contains much bigger sum asked for decryption key. In majority of cases it vary from 1300$ up to 1500$ for key, but their pricing in 72 hrs term is unchanged – 490$. It looks like crooks forcing their victims to pay now, or pay much more.
UPD 17.04.2020. One more group of Mado ransomware victims reported that their readme.txt contained another information about the sum they need to pay. Ransomware distributors are asking them to send 0.3 BTC (about 2100$) to decrypt their files. They have even changed a sum for 72-hrs payment. Now, that is 0.1 BTC. It can also be an instrument to force users to pay faster. Bitcoin price is unstable, so scared victims will probably hurry up to pay less.