The Radiyu virus belongs under the ransomware type of infection. A harmful program of this type encrypts all the data on your PC (images, documents, excel tables, audio files, videos, etc) and appends its extra extension to every file, creating the Radian_Radiware_Radiyu.exe files in each folder containing encrypted files.
There is a free decryptor available for this ransomware. In the ransom note window โ Radian_Radiware_Radiyu.exe โ type the number โ43โ in the field below. This will get your files back, though this may change in future.
What is known about the Radiyu virus?
Radiyu will append its specific .Radiyu extension to the title of each encoded file. For example, an image named โphoto.jpgโ will be changed to โphoto.jpg.Radiyuโ. In the same manner, the Excel table with the name โtable.xlsxโ will be renamed to โtable.xlsx.Radiyuโ, and so on.
In each directory with the encoded files, a Radian_Radiware_Radiyu.exe file will appear. It is a ransom money note. Therein you can find information about the ways of contacting the racketeers and some other remarks. The ransom note usually contains instructions on how to buy the decryption tool from the tamperers. That is how they do it.
Radiyu Overview:
| Name | Radiyu Virus |
| Extension | .Radiyu |
| Ransomware note | Radian_Radiware_Radiyu.exe |
| Ransom | 120210 KRW |
| Detection | Gator.Adware.Advertising.DDS Virus Removal, Adware:Win32/Trickler Virus Removal, Trojan:MSIL/AgentTesla.AQF!MTB Virus Removal |
| Symptoms | Your files (photos, videos, documents) have a .Radiyu extension and you canโt open them. |
| Fix Tool | See If Your System Has Been Affected by Radiyu virus |
The Radian_Radiware_Radiyu.exe document accompanying the Radiyu ransomware provides the following frustrating information:
๋ด ์ปดํจํฐ๋ ์ด๋ป๊ฒ ๋์์ต๋๊น? ๋น์ ์ ์ค์ํ ํ์ผ์ ๋ผ๋์ ๊ฐ ๋จน์ด๋ฒ๋ ธ์ต๋๋ค. ๋ฌธ์, ์ฌ์ง, ๋น๋์ค, ๋ฐ์ดํฐ๋ฒ ์ด์ค ๋ฐ ๊ธฐํ ํ์ผ์ ๋ฐฐ๊ณ ํ ๋ผ๋์ ๊ฐ ๋จน์ด๋ฒ๋ ค์ ๋ ์ด์ ์คํ ์ํฌ ์ ์์ต๋๋ค. ์ด์ฉ๋ฉด ํ์ผ์ ๋ณต๊ตฌ ํ ์ ์๋ ๋ฐฉ๋ฒ์ ์ฐพ๋๋ผ ๋ฐ์์ง๋ง, ์๊ฐ์ ๋ญ๋นํ์ง ์์๋ ๋ฉ๋๋ค. ๋๊ตฌ๋ ๋ผ๋์ ๊ฐ ๋จน์ ํ์ผ์ ๋ณต๊ตฌ ํ ์ ์์์ต๋๋ค. *์ ๋ฏธ๋ผ๊ฐ ์๋๋ผ๋ฉด์* ๋ด ํ์ผ์ ๋ณต๊ตฌ ํ ์ ์์ต๋๊น? ๋ผ๋์ ๊ฐ ๋จน์ ํ์ผ๋ค์ ์์ ํ๊ณ ์ฝ๊ฒ ๋ณต๊ตฌ ํ ์ ์์ต๋๋ค. ๊ทธ๋ฌ๋ ๋ผ๋ถ์ด์๊ฒ ๊ทธ๋ ๊ฒ ์ถฉ๋ถํ ์๊ฐ์ด ์์ต๋๋ค. ์๋ํ๋ฉด ํ์ผ์ ๋จน์ด๋ ๋ผ๋์ ๋ ๋ฐฐ๊ฐ ์์ฐจ๊ธฐ์, ๋น์ ์ ์ก์ ๋จน๊ณ ๋ฐฐ๋ฅผ ์ฑ์ฐ๊ธฐ ์ํด์ ์ค๋นํ๊ณ ์๊ธฐ ๋๋ฌธ์ ๋๋ค. ์ ํด๋ฆญํ์ฌ ์ ๋ฏธ๋ผ๋ฅผ ๋ฏธ๋ผ๋ก ์ฌ์ฉํด์ ํ์ผ์ ๋ณต๊ตฌํ์ญ์์ค. ๊ทธ๋ฌ๋ ์ ๋ฏธ๋ผ๋ฅผ ์ํ ํ๋ ค๋ฉด ๋ฌธ์ ๋ฅผ ํ์ด์ผ ํฉ๋๋ค. ๋ฌธ์ ๋ ๋ฑ~! ํ๋๋ง ๋ผ ๊ฒ์ ๋๋ค. *ํ๋ฆฐ ๋ต์ด ์๋์ง ์ ์๊ฐ ํด ๋ณด์๊ณ ๋ฌธ์ ๋ฅผ ํ์ด ๋ณด์ญ์์ค!* ๋ฌธ์ ์ ๋ต์ ์ด๋์์ ์์ฑํ๋์? ์๋์ ๋ณด์ด๋ ํฐ์ ๋ค๋ชจ๋ฐ์ค(TextBox)์ ๋น์ ์ด ๋ง๋ค๊ณ ์๊ฐ๋๋ ๋ต์ ์ ์ด ์ฃผ์๋ฉด ๋ฉ๋๋ค. *๋ต์ ๋ง์ถ๊ธฐ ์ซ๋ค๋ ์ด์ ๋ก ์ปดํจํฐ๋ฅผ ๊ป๋ค ํค๊ฑฐ๋ ์ด ์ฐฝ์ ์ข ๋ฃ ์ํค๋ฉด* *๋ค์๋ ํ์ผ์ ๋ณต๊ตฌ ํ์ค ์ ์์ต๋๋ค.* ๋ฌธ์ ๋ฅผ ํ์ง ๋ชปํ๋ฉด ์ด๋ป๊ฒ ๋๋์? ๋ฌธ์ ๋ฅผ ํ์ง ๋ชปํ๋ฉด ๋ผ๋์ ๊ฐ ๋จน์(์ํธํ) ํ์ผ๋ค์ ๋ณต๊ตฌ ํ ์ ์์ต๋๋ค! ๋ฌธ์ ๋ฅผ ํ๋ฆฌ๋ฉด ์ด๋ป๊ฒ ๋๋์? ๋ฌธ์ ๋ฅผ ํ๋ฆฌ๋ฉด explorer.exe๊ฐ ์๋์ผ๋ก ์ข ๋ฃ๋ฉ๋๋ค. ํ์ง๋ง ๊ฑฑ์ ๋ง์ญ์์ค! ๋ฌธ์ ๋ฅผ ๋ง์ถ๊ฒ ๋๋ฉด explorer.exe๊ฐ ์๋์ผ๋ก ๋ณต๊ตฌ๋ฉ๋๋ค. *ํน์๋ ํด์ ๋งํ๋ ๊ฒ๋๋ค! explorer.exe๊ฐ ๊ฐ์๊ธฐ ๊บผ์ ธ์ ๋นํฉํด๊ฐ์ง๊ณ * *์ด ์ฐฝ์ ๋์๋ฉด ์๋ผ์!!!* ๋ฌธ์ ์ ํํธ๋ ์ด๋์ ๋ณด๋์? ๋ฌธ์ ์ ํํธ๋ ๋ผ๋์ ์ํฐ์ ์๋ \'\'๋.๋จธ.๋ฆฌ\'\'๋ผ๋ ๊ฒ์์ ํ๋ ์ด ํด ๋ณด์๋ฉด ์์๊ฒ ๋ ๊ฒ์ ๋๋ค! ์๋์ ์๋ ์ฌ์ดํธ์์ \'\'๋.๋จธ.๋ฆฌ\'\'๋ฅผ ๋ค์ด ๋ฐ์ ํ๋ ์ด ํ์ญ์์ค! \'\'๋.๋จธ.๋ฆฌ\'\'๋ค์ด๋ก๋ : hxxps://shelter.id/radiyu5/community/board/all(modal:_/radiyu5/10461) ํํธ๋ฅผ ๋ณด์๋๋ฐ๋ ๋ฌธ์ ์ ์ ๋ต์ ๋ชจ๋ฅด๊ฒ ์ด์!! ๋์์ฃผ์ธ์!!! ๋ฌธ์ ์ ํํธ๋ฅผ ๋ณด์๋๋ฐ๋ ๋ฌธ์ ์ ์ ๋ต์ ๋ชจ๋ฅด์๊ฒ ๋ค๋ฉด ์๋์ ์ฃผ์๋ก ๋น์ฉ์ ์ง๋ถํ์ญ์์ค! ๋น์ฉ์ ํธ์, ํฌ๋ค์ด์ ์ผ๋ก๋ง ํ์ฉ๋ฉ๋๋ค. ํธ์(twip)์ผ๋ก ์ง๋ถํ๊ธฐ hxxps://twip.kr/radiyu ํฌ๋ค์ด์ ์ผ๋ก ์ง๋ถํ๊ธฐ hxxps://toon.at/donate/637246377212080144 ์ง๋ถ ๊ธ์ก์ 120210์ ์ ๋๋ค. ์ง๋ถ์ด ํ์ธ๋๋ฉด ๊ทธ ์ฆ์ ๋ฌธ์ ์ ๋ต์ ๋๋ฆฌ๊ฒ ์ต๋๋ค. ==(**!!๊ฒฝ๊ณ !!**)== ์ด ์ฐฝ์ ๋๊ฑฐ๋ Game.exe(Radian_Radiware_Radiyu.exe)๋ฅผ ์ ๊ฑฐํ์ง ๋ง์๊ณ ๋ฌธ์ ๋ฅผ ํ๊ณ ๋ฌธ์ ์ ์ ๋ต์ด ํ์ธ ๋ ๋ ๊น์ง ์ ์ ๋์ ์ํฐ ๋ฐ์ด๋ฌ์ค(๋ฐฑ์ : ์์ฝ, V3, AppCheck๋ฑ ์)๋ฅผ ๋นํ์ฑํ ํ์ญ์์ค! *๋นํ์ฑํ๋ ์ ์ ๋์ ๋ฐฑ์ ์ ๊บผ๋ฌ๋ผ๋ ๊ฒ๋๋ค...* ์? ๋ฐฑ์ ์ ๊บผ์ผ ๋๋๊ฑฐ์ผ? *์๋ํ๋ฉด ๋ฐฑ์ ์ด ์ด ์ฐฝ์ ๋ฐ์ด๋ฌ์ค๋ก ๊ฐ์งํด์ ์๋์ผ๋ก ์ญ์ ๋๋ฉด* *๋ณต๊ตฌ๊ฐ ๋ถ๊ฐ๋ฅ ํด์ง๊ธฐ ๋๋ฌธ์ ๋๋ค!!!* ์ด ์ฐฝ์ ๋๊ฑฐ๋ ์ํฐ ๋ฐ์ด๋ฌ์ค๊ฐ ์ ๋ฐ์ดํธ ๋์ด์ ์ด ์ํํธ์จ์ด๊ฐ ์๋์ผ๋ก ์ ๊ฑฐ๋๋ฉด ๋ฌธ์ ๋ฅผ ๋ง์ถ๋๋ผ๋ ๋ผ๋์ ๊ฐ ๋จน์ ํ์ผ๋ค์ ๋ณต๊ตฌ ํ ์ ์๋ค๊ณ ๋๋ฒ ๊ฒฝ๊ณ ํ์ต๋๋ค! *๋ด ๋งํ๊ธฐ ์๊ธ* ^^ ํด๋น ๋์ฌ์จ์ด๋ RSA-AES์ํธํ๋ฅผ ์ฌ์ฉํด์ ๋ง๋ค์๊ธฐ ๋๋ฌธ์ ๋ผ๋์ ๋์ฌ์จ์ด ์ฐฝ์ ๋๊ฒ ๋๋ค๋ฉด ์ํธํ๋ ํค๋ ์๋์ผ๋ก ์์ด์ ธ ๋ฒ๋ ค ๋ณตํธํ๊ฐ ๋ถ๊ฐ๋ฅ ํฉ๋๋ค!!! **์ฅ๋์ผ๋ก ํ๋ ๋ง์ด ์๋์ ๋ฐํ๋๋ค!**
In the picture below, you can see what a folder with files encrypted by the Radiyu looks like. Each filename has the โ.Radiyuโ extension appended to it.
How did my machine catch Radiyu ransomware?
There are many possible ways of ransomware injection.
There are currently three most exploited ways for evil-doers to have the Radiyu virus working in your system. These are email spam, Trojan introduction and peer file transfer.
- If you open your inbox and see emails that look just like notifications from utility services companies, delivery agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, be wary of opening those letters. They are very likely to have a malicious item enclosed in them. Thus it is even riskier to open any attachments that come with emails like these.
- Another option for ransom hunters is a Trojan horse scheme. A Trojan is a program that gets into your computer disguised as something different. Imagine, you download an installer of some program you need or an update for some software. But what is unpacked turns out to be a harmful agent that corrupts your data. Since the installation wizard can have any title and any icon, you have to make sure that you can trust the resource of the things youโre downloading. The optimal thing is to trust the software developersโ official websites.
- As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the folder containing the downloaded files with the antivirus as soon as the downloading is complete.
How to remove ransomware?
It is crucial to note that besides encrypting your data, the Radiyu virus will probably deploy Vidar Stealer on your computer to get access to credentials to different accounts (including cryptocurrency wallets). That spyware can extract your credentials from your browserโs auto-filling cardfile.
How do I avert ransomware infiltration?
Radiyu ransomware doesnโt have a endless power, so as any similar malware.
You can defend your system from ransomware attack in several easy steps:
- Never open any emails from unknown mailboxes with strange addresses, or with content that has nothing to do with something you are expecting (how can you win in a lottery without participating in it?). In case the email subject is likely something you are expecting, check all elements of the dubious letter carefully. A fake letter will surely contain mistakes.
- Avoid using cracked or untrusted programs. Trojans are often spreaded as an element of cracked software, possibly as a โpatchโ preventing the license check. Understandably, untrusted programs are difficult to distinguish from trustworthy ones, as trojans may also have the functionality you seek. Try searching for information about this software product on the anti-malware forums, but the optimal way is not to use such programs at all.
Frequently Asked Questions
๐ค How can I open โ.Radiyuโ files?Is it possible to openโ.Radiyuโ files?
Negative. That is why ransomware is so frustrating. Until you decode the โ.Radiyuโ files you will not be able to access them.
๐ค I really need to decrypt those โ.Radiyuโ files ASAP. How can I do that?
Itโs good if you have fะฐr-sightedly saved copies of these important files elsewhere. Otherwise, you might try to employ System Restore. The only question is whether you have saved any Restore Points that would be helpful now. The rest of the methods require patience.
๐ค What actions should I take if the Radiyu ransomware has blocked my computer and I canโt get the activation key.
๐ค And what should I do now?
Many of the blocked files might still be within your reach
- If you exchanged your critical files through email, you could still download them from your online mail server.
- You may have shared images or videos with your friends or family members. Simply ask them to send those pictures back to you.
- If you have initially got any of your files from the Web, you can try doing it again.
- Your messengers, social networks pages, and cloud disks might have all those files too.
- Maybe you still have the needed files on your old computer, a portable device, phone, external storage, etc.
USEFUL TIP: You can use data recovery utilities1 to get your lost data back since ransomware encodes the copies of your files, deleting the authentic ones. In the tutorial below, you can learn how to use PhotoRec for such a restoration, but remember: you wonโt be able to do it before you eradicate the ransomware itself with an antivirus program.
I need your help to share this article.
It is your turn to help other people. I have written this guide to help people like you. You can use the buttons below to share this on your favorite social media Facebook, Twitter, or Reddit.
Brendan SmithReferences
- Hereโs the list of Top 10 Data Recovery Software Of 2023.

Leave a Comment