• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Geek's Advice

IT News, Software Reviews, How To's & Computer Help

  • News
  • Reviews
  • Removal guides
  • Fix
  • Tutorials
  • Forum
  • ASK A GEEK

Remove RIGH Ransomware Virus (2023 Guide)

January 31, 2020 By Norbert Webb 2 Comments

RIGH ransomware attacks to encrypt data on victim’s PC

Contents

  • RIGH ransomware attacks to encrypt data on victim’s PC
    • Identify if your files were encrypted by offline or online key
    • Threat summary
  • The virus reaches victims via illegal downloads
  • The best way to remove RIGH ransomware
  • FAQ

RIGH ransomware is the 190th version of DJVU malware that employs asymmetric encryption to lock all victim’s files on the computer. The virus targets Windows computers and aims to prevent data access to force the victim pay a ransom. Each affected file gets marked with .righ file extension, and the virus also drops _readme.txt ransom note in every affected data folder. The ransom note commands the victim to contact criminals via datarestorehelp@firemail.cc or datahelp@iran.ir and pay a ransom of $490-$980 in Bitcoin.

The ransomware typically hides in malicious online downloads. Once opened, the malicious file runs the RIGH ransomware executive which then disables security programs, firewalls, and deletes Volume Shadow Copies. The virus begins the encryption process by scanning all file system. It has a target list of file extensions to corrupt, and bypasses folders that hold system files. Its primary goal is to restrict access to personal files (years of work, precious memories such as photos, videos, and similar).

RIGH ransomware deletes any system restore points to prevent victims from restoring their files easily. Therefore, only people who have backups will succeed in recovering files quickly.

The ransomware developers are the only ones who have private keys required for data decryption. Therefore, they suggest contacting them via provided emails and pay a ransom of $490 if paid within 72 hours from the infection. Otherwise, the price goes up to $980.

remove righ ransomware virus
RIGH ransomware leaves money-demanding note in _readme.txt file.

This STOP/DJVU ransomware variant is extremely dangerous as it also infects the host computer with Azorult Trojan. This Trojan is capable of stealing private information like login credentials and even more.

As you may have guessed, the first thing you need to do is wipe your computer from malware. Therefore, we suggest you to remove RIGH ransomware virus using free instructions provided at the end of this article.

Identify if your files were encrypted by offline or online key

RIGH file virus encrypts files using online or offline keys depending on its success to establish connection with its Command & Control server. In case the attempts to connect are unsuccessful, the virus encrypts files using offline key, which is the same for all victims of one extension ransomware attack.

To clarify, RIGH malware has only one offline key. This is why it is easier for security experts to extract it and use it to help victims of offline key encryption. However, if you were affected by the online key (each victim gets a different key), it is nearly impossible to recover your files.

Victims might decrypt .righ extension files in the future using STOP decrypter.

Please keep in mind that this is only possible if an offline key was used for your data encryption.

Threat summary

NameRIGH ransomware virus
TypeRansomware; File-encrypting virus (STOP/DJVU variant)
EncryptionRSA
SymptomsCan’t open files with .righ file extension
Ransom note_readme.txt
Ransom demand$490 or $980
Contact emailsdatarestorehelp@firemail.cc or datahelp@iran.ir
DistributionMalicious downloads, including software cracks, keygens, illegal activation tools
DecryptionNot possible. Decryption will be possible for offline key victims (see more info below)
Additional detailsInstalls AZORULT Trojan
RemovalRemove using antivirus with a help of a guide provided below

The virus reaches victims via illegal downloads

RIGH ransomware virus victims typically install the malware by opening malicious downloads such as software cracks. Please keep in mind that such files are very dangerous and are used for illegal activation of paid software.

righ file virus hides in malicious downloads
STOP/DJVU ransomware variants are distributed via illegal downloads, so stay away from such files.

Malware creators love packing such downloads with various viruses, so you should keep distance from them at all times. The same distribution method has been used to spread MSOP, HETS, ZOBM and ROTE variants.

Ransomware is also frequently transmitted via phishing emails and infected websites. As a matter of fact, ransomware distribution continuously evolves and new ways to spread it emerge every now and then. Therefore, we present these ransomware prevention methods for you.

The best way to remove RIGH ransomware

You can remove RIGH ransomware virus for free using the instructions provided below this post. We also advise using antivirus software of your choice to escort the malware from the computer safely.

Only after a successful RIGH ransomware removal you can do further steps to secure yourself and try to recover some files. First of all, we suggest changing all of your login data as the Azorult Trojan could have stolen it already. Next, we recommend you to learn more about DJVU decryption by reading this article.

OUR GEEKS RECOMMEND

Our team recommends a two-step rescue plan to remove ransomware and other remaining malware from your computer, plus repair caused virus damage to the system:

STEP 1. REMOVE AUTOMATICALLY WITH ROBUST ANTIVIRUS

REMOVE & PROTECT WITH INTEGO

Get INTEGO ANTIVIRUS for Windows to remove ransomware, Trojans, adware and other spyware and malware variants and protect your PC and network drives 24/7. This VB100-certified security software uses state-of-art technology to provide protection against ransomware, Zero-Day attacks and advanced threats, Intego Web Shield blocks dangerous websites, phishing attacks, malicious downloads and installation of potentially unwanted programs.

Use INTEGO Antivirus to remove detected threats from your computer.

Read full review here.

STEP 2. REPAIR VIRUS DAMAGE TO YOUR COMPUTER

DOWNLOAD RESTORO

RESTORO provides a free scan that helps to identify hardware, security and stability issues and presents a comprehensive report which can help you to locate and fix detected issues manually. It is a great PC repair software to use after you remove malware with professional antivirus. The full version of software will fix detected issues and repair virus damage caused to your Windows OS files automatically.

RESTORO uses AVIRA scanning engine to detect existing spyware and malware. If any are found, the software will eliminate them.

Read full review here.

GeeksAdvice.com editors select recommended products based on their effectiveness. We may earn a commission from affiliate links, at no additional cost to you. Learn more.

RIGH Ransomware Removal Guidelines

Method 1. Enter Safe Mode with Networking

Step 1. Start Windows in Safe Mode with Networking

Before you try to remove the virus, you must start your computer in Safe Mode with Networking. Below, we provide the easiest ways to boot PC in the said mode, but you can find additional ones in this in-depth tutorial on our website – How to Start Windows in Safe Mode. Also, see a video tutorial on how to do it:

Instructions for Windows XP/Vista/7 users

  1. First of all, turn off your PC. Then press the Power button to start it again and instantly start pressing F8 button on your keyboard repeatedly in 1-second intervals. This launches the Advanced Boot Options menu.
  2. Use arrow keys on the keyboard to navigate down to Safe Mode with Networking option and press Enter.
    Remove ransomware using Safe Mode with Networking

Instructions for Windows 8/8.1/10 users

  1. Open Windows Start menu, then press down the Power button. On your keyboard, press down and hold the Shift key, and then select Restart option.Hold Shift and click Restart to enter Windows Troubleshooting menu
  2. This will take you to Windows Troubleshoot screen. Choose Troubleshoot > Advanced Options > Startup Settings > Restart. Tip: If you can't find Startup Settings, click See more recovery options.Tutorial on how to enable Safe Mode in Windows 10,8,8.1
  3. In Startup Settings, press the right key between F1-F9 to enter Safe Mode with Networking. In this case, it is the F5 key.Choose Windows Safe Mode type by pressing the right function key
Step 2. Remove files associated with the virus

Now, you can search for and remove RIGH Ransomware files. It is very hard to identify files and registry keys that belong to the ransomware virus, Besides, malware creators tend to rename and change them repeatedly. Therefore, the easiest way to uninstall such type of a computer virus is to use a reliable malware removal program. In addition, we suggest trying a combination of INTEGO Antivirus (removes malware and protects your PC in real-time) and RESTORO (repairs virus damage to Windows OS files).

GET 75% OFF INTEGO ANTIVIRUS FOR WINDOWS

Method 2. Use System Restore

In order to use System Restore, you must have a system restore point, created either manually or automatically.

Step 1. Boot Windows in Safe Mode with Command Prompt

Instructions for Windows XP/Vista/7 users

  1. Shut down your PC. Start it again by pressing the Power button and instantly start pressing F8 button on your keyboard repeatedly in 1-second intervals. You will see Advanced Boot Options menu.
  2. Using arrow keys on the keyboard, navigate down to Safe Mode with Command Prompt option and press Enter.
    Starting Windows in Safe Mode with Command Prompt

Instructions for Windows 8/8.1/10 users

  1. Launch Windows Start menu, then click the Power button. On your keyboard, press down and hold the Shift key, and then choose Restart option with the mouse cursor.Hold Shift and click Restart to enter Windows Troubleshooting menu
  2. This will take you to Windows Troubleshoot screen. Choose Troubleshoot > Advanced Options > Startup Settings > Restart. Tip: If you can't find Startup Settings, click See more recovery options.Tutorial on how to enable Safe Mode in Windows 10,8,7
  3. In Startup Settings, press the right key between F1-F9 to enter Safe Mode with Command Prompt. In this case, press F6 key.Choose Windows Safe Mode type by pressing the right function key
Step 2. Start System Restore process
  1. Wait until system loads and command prompt shows up.
  2. Type cd restore and press Enter, then type rstrui.exe and press Enter. Or you can just type %systemroot%system32restorerstrui.exe in command prompt and hit Enter.
    Start system restore from command prompt using these commands
  3. This launches System Restore window. Click Next and then choose a System Restore point created in the past. Choose one that was created before ransomware infection.Choose system restore point created before ransomware infection
  4. Click Yes to begin the system restoration process.

After restoring the system, we recommend scanning the system with antivirus or anti-malware software. In most cases, there won't be any malware remains, but it never hurts to double-check. In addition, we highly recommend checking ransomware prevention guidelines provided by our experts in order to protect your PC against similar viruses in the future.

Alternative software recommendations

Malwarebytes Anti-Malware

Removing spyware and malware is one step towards cybersecurity. To protect yourself against ever-evolving threats, we strongly recommend purchasing a Premium version of Malwarebytes Anti-Malware, which provides security based on artificial intelligence and machine learning. Includes ransomware protection. See pricing options and protect yourself now.

get malwarebytes premium

System Mechanic Ultimate Defense

If you're looking for an all-in-one system maintenance suite that has 7 core components providing powerful real-time protection, on-demand malware removal, system optimization, data recovery, password manager, online privacy protection and secure driver wiping technology. Therefore, due to its wide-range of capabilities, System Mechanic Ultimate Defense deserves Geek's Advice approval. Get it now for 50% off. You may also be interested in its full review.

Disclaimer. This site includes affiliate links. We may earn a small commission by recommending certain products, at no additional cost for you. We only choose quality software and services to recommend.

FAQ

All my files have .righ file extensions and I cannot open these files. What does it mean?

RIGH is a file-encrypting virus which is named after extensions it adds to encrypted files. In short, it is the 190th variant of STOP/DJVU ransomware. This virus restricts access to personal files by encrypting them with RSA cryptography.

How can I decrypt .righ extension files?

RIGH ransomware encrypts files using online or offline keys. You can hope to restore files if you’re subject to offline key encryption. However, you need to wait for STOP decryptor update. The solution doesn’t come easy or quick.

How do I determine what key was used?

To find out whether your files were encrypted by online or offline key, go to C:\SystemID\PersonalID.txt and look at IDs listed here. If any of them end with t1, it indicates usage of an offline key. It also means that part or all of your files can be recovered as soon as the aforementioned decryption tool gets an update.

How long do I have to wait for solution?

RIGH extension virus is a very new version of STOP/DJVU, so we’d say give a few weeks or a month for the decryption means to appear. Remember, this applies only if your files were affected by the offline key. There is no solution for online key victims.

norbert webb author at geeksadvice.com
Norbert Webb

Norbert Webb is the head of Geek’s Advice team. He is the chief editor of the website who controls the quality of content published. The man also loves reading cybersecurity news, testing new software and sharing his insights on them. Norbert says that following his passion for information technology was one of the best decisions he has ever made. “I don’t feel like working while I’m doing something I love.” However, the geek has other interests, such as snowboarding and traveling.

Related posts:

  1. Remove MKOS Ransomware Virus (2023 Guide) MKOS ransomware removes access to your own files by encrypting...
  2. Remove NAKW ransomware virus (2023 Guide) NAKW ransomware hits hundreds of victims, encrypts personal dataContentsNAKW ransomware...
  3. Remove XOZA Ransomware Virus (2023 Guide) XOZA ransomware version emerges: victims infected worldwideContentsXOZA ransomware version emerges:...

Filed Under: Ransomware, Removal guides Tagged With: DJVU

Reader Interactions

Comments

  1. Kübra Yıldız says

    December 7, 2019 at 7:28 pm

    My files have RIGH extension, is there any possibilities to recover files in the future?

    Reply
  2. Ellaine says

    December 7, 2019 at 8:04 am

    My files have RIGH extension, is there any possibilities to recover files in the future?

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

SEARCH OUR SITE

Trending

decrypt files locked by stop djvu ransomware virus

Decrypt Files Locked by STOP/DJVU Ransomware (Updated 2023 Guide)

Some STOP/DJVU ransomware victims can decrypt or … [Read More...] about Decrypt Files Locked by STOP/DJVU Ransomware (Updated 2023 Guide)

Remove STOP/DJVU Ransomware Virus (2023 Guide)

STOP/DJVU in 2023: more than 640 versions, latest … [Read More...] about Remove STOP/DJVU Ransomware Virus (2023 Guide)

Remove Segurazo Antivirus (SAntivirus Removal Guide 2023)

Segurazo review: is it a virus? Segurazo … [Read More...] about Remove Segurazo Antivirus (SAntivirus Removal Guide 2023)

easy ways to fix dns_probe_finished_nxdomain error on windows, mac, android, chromebook

Fix DNS_PROBE_FINISHED_NXDOMAIN Error (Windows, Mac, Android, Chromebook)

DNS_PROBE_FINISHED_NXDOMAIN error … [Read More...] about Fix DNS_PROBE_FINISHED_NXDOMAIN Error (Windows, Mac, Android, Chromebook)

POPULAR SOFTWARE REVIEWS

Private Internet Access Review

Private Internet Access Review 2023: Fast, Secure & Cheap VPN

Private Internet Access (PIA) VPN maintains its long-term role as a leader Private Internet … [Read More...] about Private Internet Access Review 2023: Fast, Secure & Cheap VPN

restoro review 2020

Restoro Review 2023

What is Restoro and how it works? Restoro is an ultimate malware removal and PC repair software … [Read More...] about Restoro Review 2023

INTEGO antivirus review for Mac 2021

Intego Antivirus Review: Best Mac Antivirus in 2023?

Intego Antivirus for Mac is probably the best security choice for OS X Intego Antivirus for Mac … [Read More...] about Intego Antivirus Review: Best Mac Antivirus in 2023?

OUR EXPERTS RECOMMEND

Comprehensive PC Repair Software

geek's advice recommends restoro pc repair as editors choice
DOWNLOAD NOW
  • Uses Avira engine to remove malware
  • Repairs Virus Damage
  • Fixes Windows Errors & BSOD
  • Replaces Damaged DLLs
  • Repairs Damaged Windows Settings
  • Identifies Hardware Problems

Compatible with Microsoft Windows.

Read Full Review

Robust Mac Antivirus

geek's advice recommends intego mac internet security x9 as editors choice
GET INTEGO
  • 24/7 real-time protection
  • Intelligent firewall
  • Scans emails for malware
  • Scans iOS devices & external drives
  • Excellent malware detection rate
  • Easy-to-use

Compatible with Mac OS X 10.9-12.

Read Full Review

Copyright © 2023 Geeksadvice.com. Any unauthorized copying, redistribution or reproduction of part or all of the site contents in any form is prohibited.

About Us · Terms of Use · Privacy Policy · Contact Us