The Ior virus belongs under the Dharma ransomware family. A harmful program of such sort encrypts all the data on your PC (photos, documents, excel tables, music, videos, etc) and appends its own extension to every file.
What is known about the Ior virus?
☝️ Ior is a Dharma family ransomware-type infection.
The scheme of renaming is this: .ior. During the encryption, a file named, for instance, “report.docx” will be altered to “report.docx.id-9ECFA84E.[[email protected]].ior”.
The ransom note usually contains instructions on how to buy the decryption tool from the ransomware developers. You can obtain this decoding tool after contacting [email protected] through email. That is how they do it.
Ior Summary:
| Name | Ior Virus |
| Ransomware family1 | Dharma ransomware |
| Extension | .ior |
| Contact | [email protected] |
| Detection | Trojan:Win32/Tnega!MSR Removal, Win32:Adware-DNA [Adw] Virus Removal, Win32:Secat [Trj] Virus Removal |
| Symptoms | Your files (photos, videos, documents) have a .ior extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Ior virus |
The note accompanying the Ior ransomware states the following:
All your files have been encrypted! All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail [email protected] Write this ID in the title of your message - In case of no answer in 24 hours write us to theese e-mails:[email protected] You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files. Free decryption as guarantee Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.) How to obtain Bitcoins The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click \'Buy bitcoins\', and select the seller by payment method and price. *** Also you can find other places to buy Bitcoins and beginners guide here: *** Attention! Do not rename encrypted files. Do not try to decrypt your data using third party software, it may cause permanent data loss. Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.
In the picture below, you can see what a folder with files encrypted by the Ior looks like. Each filename has the “.ior” extension added to it.
How did my machine catch Ior ransomware?
There are plenty of possible ways of ransomware infiltration.
There are currently three most popular methods for malefactors to have ransomware settled in your digital environment. These are email spam, Trojan infiltration and peer file transfer.
- If you open your inbox and see emails that look just like notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose addresser is strange to you, beware of opening those emails. They are very likely to have a viral item enclosed in them. Thus it is even more dangerous to download any attachments that come with emails like these.
- Another option for ransom hunters is a Trojan virus model. A Trojan is an object that infiltrates into your machine pretending to be something different. Imagine, you download an installer for some program you need or an update for some service. But what is unboxed reveals itself a harmful program that encodes your data. As the installation file can have any title and any icon, you’d better be sure that you can trust the source of the files you’re downloading. The optimal way is to use the software developers’ official websites.
- As for the peer networks like BitTorrent or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded objects with the antivirus as soon as the downloading is finished.
How do I get rid of ransomware?
It is crucial to note that besides encrypting your files, the Ior virus will most likely install Vidar Stealer on your machine to seize your credentials to various accounts (including cryptocurrency wallets). That program can derive your credentials from your browser’s auto-filling data.
How to avert ransomware attack?
Ior ransomware has no endless power, so as any similar malware.
You can armour your system from its attack within three easy steps:
- Never open any emails from unknown mailboxes with strange addresses, or with content that has nothing to do with something you are waiting for (can you win in a lottery without even taking part in it?). In case the email subject is more or less something you are waiting for, scrutinize all elements of the dubious email carefully. A fake letter will surely contain a mistake.
- Never use cracked or untrusted software. Trojan viruses are often distributed as an element of cracked software, possibly as a “patch” preventing the license check. Understandably, untrusted programs are very hard to distinguish from trustworthy software, because trojans may also have the functionality you need. You can try searching for information about this software product on the anti-malware forums, but the optimal way is not to use such programs at all.
Frequently Asked Questions
🤔 Is it possible to open “.ior” files?
There’s no way to do it, unless the files “.ior” files are decrypted.
🤔 What should I do to make my files accessible as fast as possible?
Hopefully, you have made a copy of those important files. If not, there is still a function of System Restore but it needs a Restore Point to be previously saved. All other solutions require time.
🤔 What actions should I take if the Ior malware has blocked my computer and I can’t get the activation key.
🤔 And what should I do now?
Many of the encoded files might still be within your reach
- If you exchanged your important files via email, you could still download them from your online mail server.
- You might have shared photographs or videos with your friends or relatives. Simply ask them to post those images back to you.
- If you have initially got any of your files from the Web, you can try doing it again.
- Your messengers, social networks pages, and cloud storage might have all those files too.
- It might be that you still have the needed files on your old PC, a portable device, mobile, external storage, etc.
USEFUL TIP: You can use data recovery programs2 to get your lost data back since ransomware blocks the copies of your files, deleting the original ones. In the tutorial below, you can learn how to use PhotoRec for such a recovery, but remember: you won’t be able to do it before you eradicate the ransomware itself with an anti-malware program.

Leave a Comment