Removal guides

Remove RIGH Ransomware Virus (2022 Guide)

RIGH ransomware attacks to encrypt data on victim’s PC

RIGH ransomware is the 190th version of DJVU malware that employs asymmetric encryption to lock all victim’s files on the computer. The virus targets Windows computers and aims to prevent data access to force the victim pay a ransom. Each affected file gets marked with .righ file extension, and the virus also drops _readme.txt ransom note in every affected data folder. The ransom note commands the victim to contact criminals via datarestorehelp@firemail.cc or datahelp@iran.ir and pay a ransom of $490-$980 in Bitcoin.

The ransomware typically hides in malicious online downloads. Once opened, the malicious file runs the RIGH ransomware executive which then disables security programs, firewalls, and deletes Volume Shadow Copies. The virus begins the encryption process by scanning all file system. It has a target list of file extensions to corrupt, and bypasses folders that hold system files. Its primary goal is to restrict access to personal files (years of work, precious memories such as photos, videos, and similar).

RIGH ransomware deletes any system restore points to prevent victims from restoring their files easily. Therefore, only people who have backups will succeed in recovering files quickly.

The ransomware developers are the only ones who have private keys required for data decryption. Therefore, they suggest contacting them via provided emails and pay a ransom of $490 if paid within 72 hours from the infection. Otherwise, the price goes up to $980.

RIGH ransomware leaves money-demanding note in _readme.txt file.

This STOP/DJVU ransomware variant is extremely dangerous as it also infects the host computer with Azorult Trojan. This Trojan is capable of stealing private information like login credentials and even more.

As you may have guessed, the first thing you need to do is wipe your computer from malware. Therefore, we suggest you to remove RIGH ransomware virus using free instructions provided at the end of this article.

Identify if your files were encrypted by offline or online key

RIGH file virus encrypts files using online or offline keys depending on its success to establish connection with its Command & Control server. In case the attempts to connect are unsuccessful, the virus encrypts files using offline key, which is the same for all victims of one extension ransomware attack.

To clarify, RIGH malware has only one offline key. This is why it is easier for security experts to extract it and use it to help victims of offline key encryption. However, if you were affected by the online key (each victim gets a different key), it is nearly impossible to recover your files.

Victims might decrypt .righ extension files in the future using STOP decrypter.

Please keep in mind that this is only possible if an offline key was used for your data encryption.

Threat summary

NameRIGH ransomware virus
TypeRansomware; File-encrypting virus (STOP/DJVU variant)
EncryptionRSA
SymptomsCan’t open files with .righ file extension
Ransom note_readme.txt
Ransom demand$490 or $980
Contact emailsdatarestorehelp@firemail.cc or datahelp@iran.ir
DistributionMalicious downloads, including software cracks, keygens, illegal activation tools
DecryptionNot possible. Decryption will be possible for offline key victims (see more info below)
Additional detailsInstalls AZORULT Trojan
RemovalRemove using antivirus with a help of a guide provided below

The virus reaches victims via illegal downloads

RIGH ransomware virus victims typically install the malware by opening malicious downloads such as software cracks. Please keep in mind that such files are very dangerous and are used for illegal activation of paid software.

STOP/DJVU ransomware variants are distributed via illegal downloads, so stay away from such files.

Malware creators love packing such downloads with various viruses, so you should keep distance from them at all times. The same distribution method has been used to spread MSOP, HETS, ZOBM and ROTE variants.

Ransomware is also frequently transmitted via phishing emails and infected websites. As a matter of fact, ransomware distribution continuously evolves and new ways to spread it emerge every now and then. Therefore, we present these ransomware prevention methods for you.

The best way to remove RIGH ransomware

You can remove RIGH ransomware virus for free using the instructions provided below this post. We also advise using antivirus software of your choice to escort the malware from the computer safely.

Only after a successful RIGH ransomware removal you can do further steps to secure yourself and try to recover some files. First of all, we suggest changing all of your login data as the Azorult Trojan could have stolen it already. Next, we recommend you to learn more about DJVU decryption by reading this article.

OUR GEEKS RECOMMEND

Our team recommends a two-step rescue plan to remove ransomware and other remaining malware from your computer, plus repair caused virus damage to the system:

STEP 1. REMOVE AUTOMATICALLY WITH ROBUST ANTIVIRUS

Get INTEGO ANTIVIRUS for Windows to remove ransomware, Trojans, adware and other spyware and malware variants and protect your PC and network drives 24/7.. This VB100-certified security software uses state-of-art technology to provide protection against ransomware, Zero-Day attacks and advanced threats, Intego Web Shield blocks dangerous websites, phishing attacks, malicious downloads and installation of potentially unwanted programs.

Use INTEGO Antivirus to remove detected threats from your computer.

Read full review here.

STEP 2. REPAIR VIRUS DAMAGE TO YOUR COMPUTER

RESTORO provides a free scan that helps to identify hardware, security and stability issues and presents a comprehensive report which can help you to locate and fix detected issues manually. It is a great PC repair software to use after you remove malware with professional antivirus. The full version of software will fix detected issues and repair virus damage caused to your Windows OS files automatically.

RESTORO uses AVIRA scanning engine to detect existing spyware and malware. If any are found, the software will eliminate them.

Read full review here.

GeeksAdvice.com editors select recommended products based on their effectiveness. We may earn a commission from affiliate links, at no additional cost to you. Learn more.

RIGH Ransomware Removal Guidelines

Method 1. Enter Safe Mode with Networking

Step 1. Start Windows in Safe Mode with Networking

Before you try to remove the virus, you must start your computer in Safe Mode with Networking. Below, we provide the easiest ways to boot PC in the said mode, but you can find additional ones in this in-depth tutorial on our website – How to Start Windows in Safe Mode. Also, see a video tutorial on how to do it:

Instructions for Windows XP/Vista/7 users

  1. First of all, turn off your PC. Then press the Power button to start it again and instantly start pressing F8 button on your keyboard repeatedly in 1-second intervals. This launches the Advanced Boot Options menu.
  2. Use arrow keys on the keyboard to navigate down to Safe Mode with Networking option and press Enter.

Instructions for Windows 8/8.1/10 users

  1. Open Windows Start menu, then press down the Power button. On your keyboard, press down and hold the Shift key, and then select Restart option.
  2. This will take you to Windows Troubleshoot screen. Choose Troubleshoot > Advanced Options > Startup Settings > Restart. Tip: If you can't find Startup Settings, click See more recovery options.
  3. In Startup Settings, press the right key between F1-F9 to enter Safe Mode with Networking. In this case, it is the F5 key.
Step 2. Remove files associated with the virus

Now, you can search for and remove RIGH Ransomware files. It is very hard to identify files and registry keys that belong to the ransomware virus, Besides, malware creators tend to rename and change them repeatedly. Therefore, the easiest way to uninstall such type of a computer virus is to use a reliable malware removal program. In addition, we suggest trying a combination of INTEGO antivirus (removes malware and protects your PC in real-time) and RESTORO (repairs virus damage to Windows OS files).

REMOVE MALWARE & REPAIR VIRUS DAMAGE

1 Step. Get robust antivirus to remove existing threats and enable real-time protection

INTEGO Antivirus for Windows provides robust real-time protection, Web Shield against phishing and deceptive websites, blocks malicious downloads and blocks Zero-Day threats. Use it to remove ransomware and other viruses from your computer professionally.

2 Step. Repair Virus Damage on Windows Operating System Files

Download RESTORO to scan your system for FREE and detect security, hardware and stability issues. You can use the scan results and try to remove threats manually, or you can choose to get the full version of software to fix detected issues and repair virus damage to Windows OS system files automatically.

Method 2. Use System Restore

In order to use System Restore, you must have a system restore point, created either manually or automatically.

Step 1. Boot Windows in Safe Mode with Command Prompt

Instructions for Windows XP/Vista/7 users

  1. Shut down your PC. Start it again by pressing the Power button and instantly start pressing F8 button on your keyboard repeatedly in 1-second intervals. You will see Advanced Boot Options menu.
  2. Using arrow keys on the keyboard, navigate down to Safe Mode with Command Prompt option and press Enter.

Instructions for Windows 8/8.1/10 users

  1. Launch Windows Start menu, then click the Power button. On your keyboard, press down and hold the Shift key, and then choose Restart option with the mouse cursor.
  2. This will take you to Windows Troubleshoot screen. Choose Troubleshoot > Advanced Options > Startup Settings > Restart. Tip: If you can't find Startup Settings, click See more recovery options.
  3. In Startup Settings, press the right key between F1-F9 to enter Safe Mode with Command Prompt. In this case, press F6 key.
Step 2. Start System Restore process
  1. Wait until system loads and command prompt shows up.
  2. Type cd restore and press Enter, then type rstrui.exe and press Enter. Or you can just type %systemroot%system32restorerstrui.exe in command prompt and hit Enter.
  3. This launches System Restore window. Click Next and then choose a System Restore point created in the past. Choose one that was created before ransomware infection.
  4. Click Yes to begin the system restoration process.

After restoring the system, we recommend scanning the system with antivirus or anti-malware software. In most cases, there won't be any malware remains, but it never hurts to double-check. In addition, we highly recommend checking ransomware prevention guidelines provided by our experts in order to protect your PC against similar viruses in the future.

Alternative software recommendations

Malwarebytes Anti-Malware

Removing spyware and malware is one step towards cybersecurity. To protect yourself against ever-evolving threats, we strongly recommend purchasing a Premium version of Malwarebytes Anti-Malware, which provides security based on artificial intelligence and machine learning. Includes ransomware protection. See pricing options and protect yourself now.

System Mechanic Ultimate Defense

If you're looking for an all-in-one system maintenance suite that has 7 core components providing powerful real-time protection, on-demand malware removal, system optimization, data recovery, password manager, online privacy protection and secure driver wiping technology. Therefore, due to its wide-range of capabilities, System Mechanic Ultimate Defense deserves Geek's Advice approval. Get it now for 50% off. You may also be interested in its full review.

Disclaimer. This site includes affiliate links. We may earn a small commission by recommending certain products, at no additional cost for you. We only choose quality software and services to recommend.

FAQ

All my files have .righ file extensions and I cannot open these files. What does it mean?

RIGH is a file-encrypting virus which is named after extensions it adds to encrypted files. In short, it is the 190th variant of STOP/DJVU ransomware. This virus restricts access to personal files by encrypting them with RSA cryptography.

How can I decrypt .righ extension files?

RIGH ransomware encrypts files using online or offline keys. You can hope to restore files if you’re subject to offline key encryption. However, you need to wait for STOP decryptor update. The solution doesn’t come easy or quick.

How do I determine what key was used?

To find out whether your files were encrypted by online or offline key, go to C:\SystemID\PersonalID.txt and look at IDs listed here. If any of them end with t1, it indicates usage of an offline key. It also means that part or all of your files can be recovered as soon as the aforementioned decryption tool gets an update.

How long do I have to wait for solution?

RIGH extension virus is a very new version of STOP/DJVU, so we’d say give a few weeks or a month for the decryption means to appear. Remember, this applies only if your files were affected by the offline key. There is no solution for online key victims.

View Comments

Recent Posts

Remove WDLO Ransomware Virus (DECRYPT .wdlo FILES)

WDLO ransomware uses encryption to lock your personal files WDLO ransomware is a malicious computer…

11 hours ago

Why You Need a VPN and How Does It Protect You?

What is a VPN and how does it work? The term VPN stands for Virtual…

1 day ago

Remove PPHG Ransomware Virus (DECRYPT .pphg FILES)

PPHG ransomware encrypts your computer files, threatens to keep them locked until a ransom is…

2 days ago

Remove SSOI Ransomware Virus (DECRYPT .ssoi FILES)

SSOI ransomware aims to lock all of your data on a computer and then extort…

3 days ago

Remove KKIA Ransomware Virus (DECRYPT .kkia FILES)

KKIA ransomware sneakily encrypts your files KKIA ransomware is a newly emerged computer virus that…

3 days ago

Remove HFGD Ransomware Virus (DECRYPT .hfgd FILES)

HFGD ransomware aims to take your computer files hostage HFGD ransomware is a malicious malware…

4 days ago