Omerta Virus 🔐 (. Omerta Files) — How to Remove?

Omerta virus: what is known so far?

The pattern of renaming is this: %random_string%.omerta. In the process of encryption, a file entitled, for instance, “report.docx” will be turned into “vFwOmmDtGtkWkKp8.omerta”.

In every folder containing the encoded files, a Инструкция.TXT file will appear. It is a ransom money note. Therein you can find information about the ways of contacting the racketeers and some other information. The ransom note usually contains a description of how to buy the decryption tool from the racketeers. You can obtain this tool after contacting through email. That is how they do it.

NameOmerta Virus
Extension.omerta
Ransomware noteИнструкция.TXT
Contact
Detection1Win32/Packed.BlackMoon.A suspicious, BScope.TrojanDownloader.Deyma, Mal/Kryptik-BX
SymptomsYour files (photos, videos, documents) have a .omerta extension and are renamed to a random string. You can’t open them.
Fix ToolSee If Your System Has Been Affected by Omerta virus

The Инструкция.TXT file accompanying the Omerta malware states the following:

Ваши документы, базы данных и другие файлы были зашифрованы. Но не стоит переживать!
Мы все расшифруем и вернем на свои места.

Для расшифровки данных:

Напишите на почту - 
 
 *В письме указать Ваш личный идентификатор (Key Identifier)
 *Прикрепите 2 файла до 2 мб для тестовой расшифровки.
  мы их расшифруем, в качестве доказательства, что ТОЛЬКО МЫ можем расшифровать файлы.

ВАЖНО! Не пишите с mail.ru (к нам не доходят пиьсма) Используйте - yandex.ru gmail.com и т.д.
Все кроме mail.ru

 -Чем быстрее вы сообщите нам свой идентификатор, тем быстрее мы выключим произвольное удаление файлов.
 -Написав нам на почту вы получите дальнейшие инструкции по оплате.

В ответном письме Вы получите программу для расшифровки.
После запуска программы-дешифровщика все Ваши файлы будут восстановлены.

Мы гарантируем:
100% успешное восстановление всех ваших файлов
100% гарантию соответствия
100% безопасный и надежный сервис
Внимание!
 * Не пытайтесь удалить программу или запускать антивирусные средства
 * Попытки самостоятельной расшифровки файлов приведут к потере Ваших данных
 * Дешифраторы других пользователей несовместимы с Вашими данными, так как у каждого пользователя
уникальный ключ шифрования


Каждые 24 часа удаляются 24 файла, необходимо прислать свой идентификатор чтоб мы отключили эту функцию.
Каждые 24 часа стоимость расшифровки данных увеличивается на 30% (через 72 часа сумма фиксируется)


P.S
Если Вам не ответили в течении 48 часов. Вам нужно будет связаться с нами по дополнительным контактам.

Скачайте и установите Tor Browser - hxxps://
Откройте через Tor Browser сайт - hxxp://sonarmsniko2lvfu.onion   (сайт не будет работать через обычный браузер, только через ТОР)
Зарегистрируйтесь и напишите нам.

*Наш ник в Sonar\'e - savefile365


=========================================

Ваш идентификатор (ID)

-

In the screenshot below, you can see what a directory with files encrypted by the Omerta looks like. Each filename has the “.omerta” extension added to it.

Files ciphered by Omerta ransomware

How did Omerta ransomware end up on my PC?

There are currently three most popular methods for hackers to have ransomware settled in your system. These are email spam, Trojan infiltration and peer file transfer.

If you access your mailbox and see emails that look like familiar notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, beware of opening those letters. They are most likely to have a harmful item attached to them. Thus it is even more dangerous to download any attachments that come with emails like these.

Another option for ransom hunters is a Trojan virus scheme2. A Trojan is a program that gets into your machine pretending to be something else. Imagine, you download an installer of some program you need or an update for some program. However, what is unpacked reveals itself a harmful program that compromises your data. Since the update file can have any title and any icon, you have to make sure that you can trust the resource of the things you’re downloading. The optimal thing is to use the software developers’ official websites.

As for the peer networks like torrents or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never know what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded objects with the anti-malware utility as soon as the downloading is complete.

Sarah Jenkins

Sarah Jenkins

Senior Technology Editor & AI Specialist

Sarah Jenkins is a veteran tech journalist with over 12 years of experience covering artificial intelligence, mobile innovations, and digital ethics. Her insights have appeared in leading technology publications worldwide.

Share this article
Twitter Facebook Pinterest