RONALDIHNO ENCRYPTER Ransomware Makes Exaggerated Threats
RONALDIHNO ENCRYPTER is the strange name of a new strain of file-encrypting malware. The program behaves largely as a ransomware variant.
RONALDIHNO ENCRYPTER will, fittingly, encrypt almost all files on a system. The ransomware will append the ".r7" extension after the original file name and extension. This will turn a file called "image.png" into "image.png.r7".
The ransomware will encrypt most archive files, media files, documents and executables.
Once encryption finishes, the ransom demands are displayed inside a file called "READ_THIS.txt" and the system wallpaper is also changed to show the email used by the ransomware operator for contacting victims. The ransom note makes threats that the ransomware can damage the system hardware if tampered with, which is simply an empty, false threat. The full ransom note goes as follows:
Welcome to
RONALDIHNO ENCRYPTER
READ INSTRUCTION
READ ALL 😀
______________________________________________
Okay you got my virus, so if you want decrypt your all files you must follow my instruction
1. Dont kill proccess in task manager, if you kill my virus your computer can get bluescreen and hardware lock
2. If you change file exstesion ( myfile.lock - myfile.png ) you files can get DELETED only if you change files extesion!
3. You dont like my ransomware but you want decrypt all files? you must pay for DECRYPT-KEY, it's only 20$
Recommended payments - Bitcoin , Litecoin , Etherum
If you are from polish you can pay via BLIK or Paysafecard
I F O R M A T I O N
YOU HAVE 24H TO PAY ME OR YOUR FILES GET DELETED ,- YOUR SYSTEM TOO! and hardware !
______________________________________________








