Readinstructions Ransomware (. Readinstructions File) — Removal Guide
Readinstructions Virus: What Is Known So Far? Readinstructions Adds Its Extra. Readinstructions Extension to Every File’s Name. for Example, a File Entitled...
Readinstructions virus: what is known so far?
Readinstructions adds its extra .ReadInstructions extension to every file’s name. For example, a file entitled “photo.jpg” will be turned into “photo.jpg.ReadInstructions”. Likewise, the Excel file named “table.xlsx” will end up as “table.xlsx.ReadInstructions”, and so forth.
In every folder with the encoded files, a INSTRUCTIONS.html text file will be created. It is a ransom money memo. Therein you can find information on the ways of paying the ransom and some other remarks. The ransom note most probably contains a description of how to purchase the decryption tool from the racketeers. You can obtain this tool after contacting through email. That is basically the scheme of the malefaction.
| Name | Readinstructions Virus |
| Extension | .ReadInstructions |
| Ransomware note | INSTRUCTIONS.html |
| Contact | |
| Detection1 | Ransom:HTML/Cryptowall, Win32/Filecoder.DCryptor.A, Win32/Filecoder.Ishtar.B |
| Symptoms | Your files (photos, videos, documents) have a .ReadInstructions extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Readinstructions virus |
The INSTRUCTIONS.html document accompanying the Readinstructions ransomware states the following:
Your files are encrypted! What happened? Your files are encrypted, and currently unavailable. You can check it: all files on you computer has new expansion. By the way, everything is possible to recover (restore), but you need to buy a unique decryptor. Otherwise, you never cant return your data. For purchasing a decryptor contact us by email: If you will get no answer within 24 hours contact us by our alternate emails: What guarantees? Its just a business. If we do not do our work and liabilities - nobody will not cooperate with us. To verify the possibility of the recovery of your files we can decrypted 1 file for free. Attach 1 file to the letter (no more than 10Mb). Indicate your personal ID on the letter: - Attention! ? Attempts of change files by yourself will result in a loose of data. ? Our e-mail can be blocked over time. Write now, loss of contact with us will result in a loose of data. ? Use any third party software for restoring your data or antivirus solutions will result in a loose of data. ? Decryptors of other users are unique and will not fit your files and use of those will result in a loose of data. ? If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause just we have the private key.
In the image below, you can see what a directory with files encrypted by the Readinstructions looks like. Each filename has the “.ReadInstructions” extension added to it.
How did my computer get infected with Readinstructions ransomware?
There are currently three most exploited ways for hackers to have ransomware planted in your digital environment. These are email spam, Trojan injection and peer networks.
If you access your mailbox and see letters that look just like notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose “from” field is strange to you, beware of opening those emails. They are very likely to have a harmful item enclosed in them. Thus it is even riskier to download any attachments that come with emails like these.
Another thing the hackers might try is a Trojan file model2. A Trojan is a program that gets into your PC disguised as something different. Imagine, you download an installer for some program you want or an update for some service. But what is unpacked turns out to be a harmful program that encodes your data. As the installation file can have any title and any icon, you have to make sure that you can trust the resource of the things you’re downloading. The optimal way is to trust the software companies’ official websites.
As for the peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is reasonable to scan the directory containing the downloaded files with the antivirus as soon as the downloading is complete.