What is Nqedrmt ransomware
Nqedrmt ransomware is an illegal program that is a part of the Magniber ransomware family. It is known to spread through malicious websites that mimic the look of Windows Update, as well as by exploiting the flaws in the Internet Explorer browser. It is, of course, possible for it to infect computers in other ways as well – these are just the most common ones. It mainly targets people in Asian countries like China, South Korea, and Singapore.
Ransomware in general, in case you’re not familiar, is a class of viruses that generate money for the hacker through extortion. The ransomware virus, once on the victim’s computer, will encrypt all the data, and then demand ransom to decrypt it via a ransom note. The image above contains Nqedrmt’s ransom note if you’re interested in reading it. Otherwise, here’s a summary.
The ransom note is called “README.html”. It contains no important information – instead, the victim is asked to download Tor Browser and navigate to their personalized page.
Here is an example of such a page. As you can see, the hackers appear to be asking for 0.18 BTC, or 0.09 BTC if paid within first five days. Note that that these prices may change from victim to victim.
The ransom web page correctly says that 0.18 BTC is $5466 – and that’s quite a lot of money. With this guide, however, you will be able to remove Nqedrmt ransomware without paying a dime. It will be a little bit harder to decrypt .nqedrmt files, and you may not be able to recover everything – but it might be possible, too.