MegaCortex Ransomware
Ransomware | 11/21/2019

How to Remove MegaCortex Ransomware | Virus Removal Guidelines

About: MegaCortex Ransomware is an enterprise-focused system infection that has retooled to become a weapon of wide scale attacks. It is deployed to target large corporate networks & workstations.It encrypts system files, changes user credentials, ...  Read More  

| Ransomware | How to Remove MegaCortex Ransomware | Virus Removal Guidelines

MegaCortex Ransomware, a nasty, enterprise-focused system infection has resurfaced in the United States, Canada and parts of Europe. Research reveals that this malevolent crypto viral extortion is reportedly deployed against large corporate networks & workstations.It has been retooled to become a weapon of wide scale attacks.

For those who are not aware of MegaCortex, let us sneak a peek into the original version of MegaCortex Ransomware.

Original Version of MegaCortex Ransomware

MegaCortex Ransomware was first spotted earlier this year targeting enterprise networks. The malicious program was distributed by gaining access to the system networks. It encrypted all the files in the system & renamed it with .megacortex extension.

Encrypted Files- MegaCortex Old Version

Originally, this ransomware contained a payload that was protected by a password. Though this feature made reverse engineering of its payload a cumbersome task, it also made its widespread distribution a challenge.

To install this ransomware, the threat actors had to follow a sequence of manual steps on each targeted network. Moreover, they had to monitor the infection and manually finish up the menace once the damage was dome.In short the operation of this infection involved a lot of manual labour.

Threat Summary of .MegaCortex Ransomware Infection

Threat Summary
Name MegaCortex
Type Ransomware
Category Malware
Targeted OS Windows
Symptoms It infiltrates your system with the motive to encrypt stored files. After successful encryption, the virus demands Ransom money to decrypt them.
Damage You cannot open a locked file without paying the asked ransom. Additionally, it may increase the malicious payload in your system.
Removal Download Removal Tool

New Version of MegaCortex Ransomware: Threat Behavior

MegaCortex Ransomware version-2 has been redesigned to self-execute the malicious code. This means, the password requirement for its installation has been quashed. The password is now hard coded in the binary.

Apart from this, the new version is deployed with the range of other changes. These include:

1). Manual execution of batch file has been hard coded to automatically kill antivirus solutions&wide range of other system processes& security products. It does so by comparing the list of running processes to a kill list.

2). When MegaCortex launcher is executed, it extracts 3 CMD scripts & 2 DLL files. When these CMD scripts are executed,Shadow volume copies are deleted to avoid recovery of files through backup folders.

3). When DLL files are executed, all the system files are encrypted & renamed with the new extension i.e. .m3g4c0rtx.Encrypted files - Mega Cortex New Version

4). In addition, this malevolent ransomware drops in a legal notice on the encrypted machine displaying a message Locked By MegaCortex & some email id is mentioned below it. This message is displayedeven before the user logs in their respective accounts.

5). Once the user logs in, a ransom note is displayed on the desktop titled!-!_README_!-!.rtf.

Mega Cortex Ransom Note 1

Mega Cortex Ransom Note 2

The ransom note reads that all the user credentials have been changed & the files have been encrypted.

1). Once the system is rebooted, user is unable to login to their accounts. This implies that the user credentials are indeed modified.

2). Apart from changing the user credentials, the notestates that the victim’s data is copied to a secure location. Users are threatened that their data would be revealed in public if the ransom is not paid. However there is no confirmation of the fact that the user data is really copied.

3). It is also noted that with the up gradation of ransomware version the ransom demand subsequently increased from 2 Bitcoins to 600 Bitcoins or roughly $20,000 to $5.8 million.

The guarantee of file recovery from this ransomware attack is negligible. Victims are therefore recommended not to fall for it as their concerns are usually neglected once the ransom is paid. Instead they are advised to adopt a mix of cyber security safeguards and follow best practices like backup and recovery of data to mitigate the risks associated with such malware.

Distribution Techniques of .MegaCortex file virus

The cyber-criminals behind .MegaCortex virus ransomware use various strategies for malware distribution which include –

  1. Software Bundling: Software bundling is the process in which a malicious program is distributed with other free software, to get an unnoticed entry into your computer system. When a user installs a free application, the malicious programs gains a front door entry with the free application, the user has downloaded. Thus, it is a good idea to keep an eye on the installation screens while installing these free applications.
  2. Infected Storage Devices: Your system can also get infected by using removable media such as USB hard drives and jump drives without scanning them with an anti-virus.
  3. Spam Emails – Spamming is the most economic and common method used for the distribution of such malware. The targeted users get genuine looking emails which contain .doc, .txt, and other similar attachments. These attachments can be named as anything which can grab the user’s attention and triggers him/her to open the attachment. As soon as the user opens this attachment, the malware infects the user’s computer system.
  4. Malicious Websites or Malevolent Advertisements: The malicious websites are the ones which are created just for promoting the malware infections. Such websites include but are not limited to porn sites, torrent sites and other free downloading platforms. By visiting such websites, the adware infects the user’s computer without permission. Fake advertisements and updates like Flash player and windows updates which ask the user to update to the latest version are a few examples. When the users click on such links, their computer system gets infected. That is why, it is highly recommended to resist clicking on such links. Also avoid clicking on advertisements offering free stuff such as Win an iPhones, cars or free overseas trips etc.

How to Delete MegaCortex Ransomware?

Note: The removal guidelines for .MegaCortex extension are not known at this time, however mentioned below are few common measures that victims can implement in order to restore the system to the older version.

Step A: Reboot Your System to Safe Mode

To restart the system to Safe Mode with Networking,  if already switched ON then follow the below steps:

Windows 7/ Vista/ XP

  1. Click on Windows icon present in the lower left corner of the computer screen.
  2. Select and click  Restart.
  3. When the screen goes blank, Keep tapping  F8  Key until you see the Advanced Boot Options window.
  4. With the help of arrow keys on keyboard, Select Safe Mode with Networking  option from the list and press the Enter Key. The system will then restart to Safe Mode with Networking.

5 Once the system restarts, click on the username and enter the password (if any) to log in.

Windows 10 / Windows 8

  1. Press and hold the Shift Key and simultaneously click on the windows icon present in the lower left corner of your computer screen.
  2. While the Shift key is still pressed click on the Power button and then click on Restart.
  3. Now select Troubleshoot → Advanced options → Startup Settings.
  4. When the Startup Settings screen appears which is the first screen to appear after restart, select and click on Enable Safe Mode with Networking. The system will then restart to Safe Mode with Networking.
  5. Once the system restarts in Safe Mode, click on the username and enter the password, if any to log in.

STEP B: Delete the Suspicious File from the Registry Key

  1. Press Windows Button and R key simultaneously to initiate the “Run Box”.
  2. Type “Regedit” in Run Box, select it and press Enter.
  3. An authorization dialog box will appear, then you just have to click “Yes”. (The dialog box appearance may vary depending on OS used. For Windows 10 the the dialog box looks like the first screenshot and for windows 7 it appears like the second screenshot)
  4. In the registry editor, take the backup of the current registry settings before making any changes in case you want to revert to old settings later. For this, Click on File option in the menu and select Export. Save the entry at a known location.
  5. From the Menu, Click Edit and Select Find.
  6. Enter MegaCortex Ransomware and click Ok in the search box.
  7. Select and delete suspicious  enteries.

STEP C: Restore the Encrypted Data Via Windows Previous Version

If the system restore was enabled for both, system and user files, then you can recover your personal data through Windows Previous Version, provided the ransomware has not damaged the backup files. To restore your data follow the instructions given below –

  1. Open My Computer and search for the folder you want to restore.
  2. As soon as you find it, right click on it and choose the restore previous version option from the new window.restore windows previous version
  3. This option will display all the previous copies of the folder.restore windows previous version
  4. Now select restore data and through the options i.e. Open – Copy – Restore. 

How to Protect System from .MegaCortex Ransomware Infection?

  1. Keeping the Operating System Updated- In order to remain protected and avoid such infections, it is recommended to keep your Operating System updated by enabling the automatic update on your system. The systems with outdated or older versions of Operating System become an easy target for the attackers.
  2. Resist clicking on spam emails – One of the major techniques used for malware distribution is forwarding spam emails to the user. The system gets infected as soon as the user clicks on the attachment. These mails appear to be genuine, so be aware and resist falling for these tricks.
  3. Keep an eye on third party installations- It is quite important that you take due care while installing any third party applications for they are major source of such infections. Such malware programs come bundled with the free applications thereby requiring the user to remain cautious.
  4. Regular periodical backup- In order to keep your data and files safe, it is recommended to take regular back up of all your data and files either on an external drive or cloud.
  5. Use Anti-Virus Protection- We strongly recommend the use of antivirus protection/internet security in your PC like Vipre and BULL GUARD so that it remains safe.
  6. Enable the Ad Blocker/Popup Blocker in your browser- Enabling the popup blocker/ ad blocker in your chosen browser will help you to stay protected from annoying adware.

Hits: 151

Leave a Reply

Your email address will not be published. Required fields are marked *

Did you find the article informative? Yes NO

Get Regular Updates Related to All the Threats

Want to stay informed about the latest threats & malware? Sign up for our newsletter & learn how to get rid of all types of threats from your computer.

Virus Removal Guidelines
Plot No 319, Nandpuri- B Pratap Nagar
Jaipur
Rajasthan 302033
Phone: +91 9799661866