What is Nomikon Ransomware
Discovered in February 2020, Nomikon is a malicious piece classified as ransomware. Ransomware is a type of virus that encrypts users’ data after penetration and demands paying a ransom. After installation, Nomikon will block all of the files stored on your system by changing their extensions to a random 5-letter set, for example, .cnmhr or .jrmcu. For instance, 1.mp4 will be replaced with 1.mp4.cnmhr or other randomly generated extension. Once the virus encrypted your data, it will then create an HTML file called DECRYPT.html with the following information:
Your computer has been infected
All your documents, photos, databases and other important files are encrypted
To decrypt your files you need to buy our special software - UmtxCnMh4r-Decryptor
You can do it right now. Follow the instruction below. But remember that you do not have much time
You have EXPIRED TIME
*If you do not pay on time the price will be doubled
*Time ends on February 19, 01:37:43
0.04114785 BTC $400 USD
After time ends 0.08229571 BTC $800 USD
This well-organized note says that your computer is infected and requires buying special software provided by frauds. The software itself costs roughly 400$ and has to be paid in BTC. They also intimidate that if you do not pay a ransom within the allocated period of time, the price will be doubled. In addition, victims are also offered to use trial decryption by sending one file (less than 5MB) to the attached e-mail. Extortionists warn you to not use third-party decryptors, otherwise, this may result in a permanent data loss. Unfortunately, most of the time, the locked files are unrecoverable, however, it does not mean that you should pay a ransom unless you have a lot of money. Instead, we recommend deleting Nomikon Ransomware from your computer and restoring the lost files from backup devices.
- Download Nomikon Ransomware Removal Tool
- Get decryption tool for your files
- Recover encrypted files with Stellar Data Recovery Professional
- Restore encrypted files with Windows Previous Versions
- Restore files with Shadow Explorer
- How to protect from threats like STOP Ransomware
How Nomikon Ransomware infected your computer
Ransomware developers tend to exploit multiple distribution channels such as e-mail spam, fake updaters, botnets, malicious ads, and hacking unprotected RDP configuration. Swindlers are keen on flooding users with fake messages marked as legitimate or vital. However, such messages can contain malicious attachments that, once opened, infect unprotected systems. Therefore, the best way to evade inadvertent infiltrations is not clocking or downloading unfamiliar files/software just because of curiosity. Another deceptive method is via fake updaters that claim that your software is outdated and needs to be updated. Unexperienced users fall into this trick and hence get infected with ransomware. Visiting shady websites that are bunched with unwanted ads can also become a major threat since they can redirect you to pages that stealthily infect your PC by running executable scripts. Rarely, but botnets can also be used to perform DDoS attack that allows frauds temporarily control your PC and steal credentials, personal data and infect it with malware as well. To remove Nomikon Ransomware, follow the underneath instructions that we have prepared for you.
Download Removal Tool
To remove Nomikon Ransomware completely, we recommend you to use Combo Cleaner from RCS LT. It detects and removes all files, folders and registry keys of Nomikon Ransomware and prevents future infections by similar viruses.
Alternative Removal Tool
To remove Nomikon Ransomware completely, we recommend you to use SpyHunter 5 from EnigmaSoft Limited. It detects and removes all files, folders and registry keys of Nomikon Ransomware. The trial version of SpyHunter 5 offers virus scan and 1-time removal for FREE.
Nomikon Ransomware files:
Nomikon Ransomware registry keys:
How to decrypt and restore your files
Use automated decryptors
Download Kaspersky RakhniDecryptor
Use following tool from Kaspersky called Rakhni Decryptor, that can decrypt your files. Download it here:
There is no purpose to pay the ransom because there is no guarantee you will receive the key, but you will put your bank credentials at risk.
Dr.Web Rescue Pack
Famous antivirus vendor Dr. Web provides free decryption service for the owners of its products: Dr.Web Security Space or Dr.Web Enterprise Security Suite. Other users can ask for help in the decryption of your files by uploading samples to Dr. Web Ransomware Decryption Service. Analyzing of files will be performed free of charge and if files are decryptable, all you need to do is purchase a 2-year license of Dr.Web Security Space worth $120 or less. Otherwise, you don’t have to pay.
If you are infected with Nomikon Ransomware and removed it from your computer you can try to decrypt your files. Antivirus vendors and individuals create free decryptors for some crypto-lockers. To attempt to decrypt them manually you can do the following:
Use Stellar Data Recovery Professional to restore your files
- Download Stellar Data Recovery Professional.
- Click Recover Data button.
- Select type of files you want to restore and click Next button.
- Choose location where you would like to restore files from and click Scan button.
- Preview found files, choose ones you will restore and click Recover.
Using Windows Previous Versions option:
- Right-click on infected file and choose Properties.
- Select Previous Versions tab.
- Choose particular version of the file and click Copy.
- To restore the selected file and replace the existing one, click on the Restore button.
- In case there is no items in the list choose alternative method.
Using Shadow Explorer:
- Download Shadow Explorer program.
- Run it and you will see screen listing of all the drives and the dates that shadow copy was created.
- Select the drive and date that you want to restore from.
- Right-click on a folder name and select Export.
- In case there are no other dates in the list, choose alternative method.
If you are using Dropbox:
- Login to the DropBox website and go to the folder that contains encrypted files.
- Right-click on the encrypted file and select Previous Versions.
- Select the version of the file you wish to restore and click on the Restore button.
How to protect computer from viruses, like Nomikon Ransomware, in future
1. Get special anti-ransomware software
Use ZoneAlarm Anti-Ransomware
Famous antivirus vendor BitDefender released free tool, that will help you with active anti-ransomware protection, as additional shield to your current protection. It will not conflict with bigger security applications. If you are searching complete internet security solution consider upgrading to full version of BitDefender Internet Security 2018.
2. Back up your files
As an additional way to save your files, we recommend online backup. Local storages, such as hard drives, SSDs, flash drives or remote network storages can be instantly infected by the virus once plugged in or connected to. STOP Ransomware uses some techniques to exploit this. One of the best services and programs for easy automatic online backup is iDrive. It has the most profitable terms and simple interface. You can read more about iDrive cloud backup and storage here.
3. Do not open spam e-mails and protect your mailbox
Malicious attachments to spam or phishing e-mails is most popular method of ransomware distribution. Using spam filters and creating anti-spam rules is good practice. One of the world leaders in anti-spam protection is MailWasher Pro. It works with various desktop applications, and provides very high level of anti-spam protection.