Oonn File Extension Malware - How to remove

Oonn is a file extension used by file-corrupting extortion malware. Files being renamed to have Oonn as their extension is a sign that ransomware infected the computer. Most of the files that got the Oonn extension are corrupted and probably gone for good. But that doesn’t mean that the situation is hopeless. In addition, it’s important to protect yourself from the spyware that likely came together with Oonn.

About Oonn:

Classification Ransomware,

spyware,

trojan.

How malware infects PCs Downloaded from torrenting sites, unofficial download sites, comes with cracked programs, mods, and cheats.
How to fix the Oonn files Use the free decryptor,

restore the files from a backup,

repair the files manually.

How to remove Oonn Unblock websites by fixing the hosts file,

use antivirus programs (Spyhunter, Malwarebytes, others) to detect and remove malware,

restore OS settings.

How Oonn works

Infection

Oonn ransomware infects Windows computers. It usually comes from pirating sites, but people have also reported getting infected after visiting unofficial software download sites and modding sites. They download some program, maybe a cracked application, a cheat, or a mod, extract and run it.

Oonn ransomware (and likely some spyware) gets downloaded by the infected file. Once it starts working, it very quickly goes through all the files on the computer (except for system files – Oonn wants to keep Windows working) and encrypts them.

Sometimes, people are aware that they’re downloading files that their antivirus program won’t like and they disable real-time protection intentionally. This only makes things easier for Oonn ransomware.

Generally, the files that download Oonn are detected by antivirus programs as Malware, Trojan, Downloader, Backdoor, Stealer. Oonn gets the same detection names plus Cryptor, Ransom, Chapak, etc. I recommend treating every pirated file as potentially infected and preparing by making a backup image of your computer to an external drive or cloud. It’s tedious but it could save you a lot of problems.

File encryption

So, what does Oonn do once on the computer?

First, it encrypts files. Encryption is basically corruption of data, only reversible when you have the specific decryption key. This decryption key is unique to each and every computer that Oonn attacks. This key is also practically impossible to guess or to calculate. The only way to get it is to pay the ransom to the criminals behind Oonn which amounts to hundreds of dollars.

This is found in the ransom note left by Oonn, called _readme.txt:

ATTENTION!
Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-NjQb8RxCzz
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.
To get this software you need write on our e-mail:
[email protected]
Reserve e-mail address to contact us:
[email protected]

Oonn's ransom note asks for money.

How to get your files back

Methods for restoring lost files

Encrypted files cannot be read by programs and data in them is lost. If you open some text files that Oonn encrypted, you should see gibberish. If you open the encrypted photos, they look all wrong.

However, not all is lost:

  • If you had a file backup, then you can restore those files once you remove Oonn. Even if you didn’t intentionally make backups, you probably had uploaded some of your files somewhere online and can download them.
  • To save time, Oonn only encrypts the beginning of the bigger files. This means that you can learn about removing corruption and restore the remaining uncorrupted portions of your files. For archives like Zip, this means that the files after the first one can be extracted. For photos and audio recording, they need to be cropped. This is all hard work that you can do later, after getting rid of Oonn.
  • In rare cases, the decryption key that Oonn uses is shared among a few victims. I don’t want to give false hope but do check out the Emsisoft decryptor.

Just remember that if you want to mess with your Oonn files, such as by repairing them, always, always keep a backup. Put all the files that Oonn encrypted on your PC and that you want to restore on some drive or a folder in the cloud where they won’t be touched. Make copies of those files before messing with them.

Don’t fall for scammers

And remember that there is no miracle cure for Oonn. There are scammers who promise to fix your files, then take your money and disappear. Don’t fall for them.

Oonn isn’t new, it’s part of the existing Djvu ransomware family, along with Nile, Erif, Vawe, and over a hundred of other variants. If there was a way to fix the files, it would have been discovered by now. There used to be, actually. But the developers of Djvu and Oonn have plugged the holes and squashed the bugs and now their ransomware works, unfortunately.

How to remove Oonn ransomware

To make itself as difficult as possible to remove, Oonn disables the Task Manager, disables the antivirus program (or tries to), messes with the hosts file (adds erroneous entries to block some websites), and deletes backup files.

Below are instructions for repairing your hosts file and this link goes to a post on how to enable the Task Manager after an attack.

Make sure that your antivirus program has all the latest updates downloaded and installed (as Oonn might have deleted them). Or download a new antivirus application, such as Spyhunter, Malwarebytes, or others. Scan your computer and remove all the malicious files, including those from your downloads.

In the worst case, you can also reinstall Windows. Just make sure that any and all malicious files are gone from your computer.

Finally, once your computer is free of infections, go through your online accounts and set new passwords. This way, if the spyware that came with Oonn successfully stole any of your passwords, they won’t be usable anymore and your accounts won’t be stolen.

Important -- edit the hosts file to unblock security websites

TL DR : The hosts file is edited to block security sites Before the virus can be removed, it's necessary to fix the hosts file (the file which controls which addresses connect to which IPs). That is the reason the majority of security websites is inaccessible when infected with this particular parasite. This infection edits this file to stop certain websites, including anti-malware download sites, from being accessed from the infected computer, making browsers return the "This site can't be reached" error. Luckily, it's trivial to fix the file and remove the edits that were made to it.

Find and edit the hosts file

The hosts file can be found on C:/Windows/System32/Drivers/etc/hosts. If you don't see it, change the settings to see hidden files.
  1. In the Start Menu, search for Control Panel.
  2. In the Control Panel, find Appearance and Personalization.
  3. Select Folder Options.
  4. Open the View tab.
  5. Open Advanced settings.
  6. Select "Show hidden files...".
  7. Select OK.
Open this file with administrator privileges. notepad run as administrator
  1. Open the Start Menu and enter "notepad".
  2. When Notepad shows up in the result, right-click on it.
  3. In the menu, choose "Run as administrator"
  4. File->Open and browse for the hosts file.
The hosts file should look like this: hosts file default contents Delete additional lines that they connect various domain names to the wrong IP address. Save the file.

Download and run the antivirus program

After that, download antivirus programs and use them to remove the ransomware, the trojan, and other malware. Spyhunter (https://www.2-viruses.com/reviews/spyhunter/dwnld/).

Automatic Malware removal tools

Download Spyhunter for Malware detection
(Win)

Note: Spyhunter trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions,

Download Combo Cleaner for Malware detection
(Mac)

Note: Combo Cleaner trial provides detection of parasites and assists in their removal for free. limited trial available, Terms of use, Privacy Policy, Uninstall Instructions, Refund Policy ,


How to recover Oonn File Extension Malware encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:


for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode
 

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again.CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before Oonn File Extension Malware has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3
 

Step 2. Complete removal of Oonn File Extension Malware

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Spyhunter and remove all malicious files related to Oonn File Extension Malware. You can check other tools here.  

Step 3. Restore Oonn File Extension Malware affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually Oonn File Extension Malware tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so. Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer. a) Native Windows Previous Versions Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.
Previous version
b) Shadow Explorer It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover Oonn File Extension Malware encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:
  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download a data recovery program.
  • Install and scan for recently deleted files. Data Recovery Pro
Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.
Leave a Reply

Your email address will not be published. Required fields are marked *