RADIYU Ransomware ๐Ÿ” (.RADIYU File) โ€” Removal Guide

The Radiyu virus belongs under the ransomware type of infection. A harmful program of this type encrypts all the data on your PC (images, documents, excel tables, audio files, videos, etc) and appends its extra extension to every file, creating the Radian_Radiware_Radiyu.exe files in each folder containing encrypted files.

There is a free decryptor available for this ransomware. In the ransom note window โ€“ Radian_Radiware_Radiyu.exe โ€“ type the number โ€œ43โ€ in the field below. This will get your files back, though this may change in future.

What is known about the Radiyu virus?

Radiyu will append its specific .Radiyu extension to the title of each encoded file. For example, an image named โ€œphoto.jpgโ€ will be changed to โ€œphoto.jpg.Radiyuโ€. In the same manner, the Excel table with the name โ€œtable.xlsxโ€ will be renamed to โ€œtable.xlsx.Radiyuโ€, and so on.

In each directory with the encoded files, a Radian_Radiware_Radiyu.exe file will appear. It is a ransom money note. Therein you can find information about the ways of contacting the racketeers and some other remarks. The ransom note usually contains instructions on how to buy the decryption tool from the tamperers. That is how they do it.

Radiyu Overview:

Name Radiyu Virus
Extension .Radiyu
Ransomware note Radian_Radiware_Radiyu.exe
Ransom 120210 KRW
Detection Gator.Adware.Advertising.DDS Virus Removal, Adware:Win32/Trickler Virus Removal, Trojan:MSIL/AgentTesla.AQF!MTB Virus Removal
Symptoms Your files (photos, videos, documents) have a .Radiyu extension and you canโ€™t open them.
Fix Tool See If Your System Has Been Affected by Radiyu virus

The Radian_Radiware_Radiyu.exe document accompanying the Radiyu ransomware provides the following frustrating information:

๋‚ด ์ปดํ“จํ„ฐ๋Š” ์–ด๋–ป๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๊นŒ?
๋‹น์‹ ์˜ ์ค‘์š”ํ•œ ํŒŒ์ผ์€ ๋ผ๋””์œ ๊ฐ€ ๋จน์–ด๋ฒ„๋ ธ์Šต๋‹ˆ๋‹ค.
๋ฌธ์„œ, ์‚ฌ์ง„, ๋น„๋””์˜ค, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋ฐ ๊ธฐํƒ€ ํŒŒ์ผ์€
๋ฐฐ๊ณ ํ”ˆ ๋ผ๋””์œ ๊ฐ€ ๋จน์–ด๋ฒ„๋ ค์„œ ๋” ์ด์ƒ ์‹คํ–‰ ์‹œํ‚ฌ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
์–ด์ฉŒ๋ฉด ํŒŒ์ผ์„ ๋ณต๊ตฌ ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์ฐพ๋А๋ผ ๋ฐ”์˜์ง€๋งŒ, ์‹œ๊ฐ„์„ ๋‚ญ๋น„ํ•˜์ง€ ์•Š์•„๋„ ๋ฉ๋‹ˆ๋‹ค.
๋ˆ„๊ตฌ๋„ ๋ผ๋””์œ ๊ฐ€ ๋จน์€ ํŒŒ์ผ์€ ๋ณต๊ตฌ ํ•  ์ˆ˜ ์—†์—ˆ์Šต๋‹ˆ๋‹ค. *์œ ๋ฏธ๋ผ๊ฐ€ ์•„๋‹ˆ๋ผ๋ฉด์š”*
 
๋‚ด ํŒŒ์ผ์„ ๋ณต๊ตฌ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?
๋ผ๋””์œ ๊ฐ€ ๋จน์€ ํŒŒ์ผ๋“ค์€ ์•ˆ์ „ํ•˜๊ณ  ์‰ฝ๊ฒŒ ๋ณต๊ตฌ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๊ทธ๋Ÿฌ๋‚˜ ๋ผ๋ถ•์ด์—๊ฒ ๊ทธ๋ ‡๊ฒŒ ์ถฉ๋ถ„ํ•œ ์‹œ๊ฐ„์ด ์—†์Šต๋‹ˆ๋‹ค.
์™œ๋ƒํ•˜๋ฉด ํŒŒ์ผ์„ ๋จน์–ด๋„ ๋ผ๋””์œ ๋Š” ๋ฐฐ๊ฐ€ ์•ˆ์ฐจ๊ธฐ์—,
๋‹น์‹ ์„ ์žก์•„ ๋จน๊ณ  ๋ฐฐ๋ฅผ ์ฑ„์šฐ๊ธฐ ์œ„ํ•ด์„œ ์ค€๋น„ํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.
์„ ํด๋ฆญํ•˜์—ฌ ์œ ๋ฏธ๋ผ๋ฅผ ๋ฏธ๋ผ๋กœ ์‚ฌ์šฉํ•ด์„œ ํŒŒ์ผ์„ ๋ณต๊ตฌํ•˜์‹ญ์‹œ์˜ค.
๊ทธ๋Ÿฌ๋‚˜ ์œ ๋ฏธ๋ผ๋ฅผ ์†Œํ™˜ ํ•˜๋ ค๋ฉด ๋ฌธ์ œ๋ฅผ ํ’€์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
๋ฌธ์ œ๋Š” ๋”ฑ~! ํ•˜๋‚˜๋งŒ ๋‚ผ ๊ฒƒ์ž…๋‹ˆ๋‹ค.
*ํ‹€๋ฆฐ ๋‹ต์ด ์—†๋Š”์ง€ ์ž˜ ์ƒ๊ฐ ํ•ด ๋ณด์‹œ๊ณ  ๋ฌธ์ œ๋ฅผ ํ’€์–ด ๋ณด์‹ญ์‹œ์˜ค!*

 

๋ฌธ์ œ์˜ ๋‹ต์€ ์–ด๋””์—์„œ ์ž‘์„ฑํ•˜๋‚˜์š”?
์•„๋ž˜์— ๋ณด์ด๋Š” ํฐ์ƒ‰ ๋„ค๋ชจ๋ฐ•์Šค(TextBox)์— ๋‹น์‹ ์ด ๋งž๋‹ค๊ณ  ์ƒ๊ฐ๋˜๋Š” ๋‹ต์„ ์ ์–ด ์ฃผ์‹œ๋ฉด ๋ฉ๋‹ˆ๋‹ค.
*๋‹ต์„ ๋งž์ถ”๊ธฐ ์‹ซ๋‹ค๋Š” ์ด์œ ๋กœ ์ปดํ“จํ„ฐ๋ฅผ ๊ป๋‹ค ํ‚ค๊ฑฐ๋‚˜ ์ด ์ฐฝ์„ ์ข…๋ฃŒ ์‹œํ‚ค๋ฉด*
*๋‹ค์‹œ๋Š” ํŒŒ์ผ์„ ๋ณต๊ตฌ ํ•˜์‹ค ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.*
 
๋ฌธ์ œ๋ฅผ ํ’€์ง€ ๋ชปํ•˜๋ฉด ์–ด๋–ป๊ฒŒ ๋˜๋‚˜์š”?
๋ฌธ์ œ๋ฅผ ํ’€์ง€ ๋ชปํ•˜๋ฉด ๋ผ๋””์œ ๊ฐ€ ๋จน์€(์•”ํ˜ธํ™”) ํŒŒ์ผ๋“ค์€ ๋ณต๊ตฌ ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค!
 
๋ฌธ์ œ๋ฅผ ํ‹€๋ฆฌ๋ฉด ์–ด๋–ป๊ฒŒ ๋˜๋‚˜์š”?
๋ฌธ์ œ๋ฅผ ํ‹€๋ฆฌ๋ฉด explorer.exe๊ฐ€ ์ž๋™์œผ๋กœ ์ข…๋ฃŒ๋ฉ๋‹ˆ๋‹ค.
ํ•˜์ง€๋งŒ ๊ฑฑ์ •๋งˆ์‹ญ์‹œ์˜ค! ๋ฌธ์ œ๋ฅผ ๋งž์ถ”๊ฒŒ ๋˜๋ฉด explorer.exe๊ฐ€ ์ž๋™์œผ๋กœ ๋ณต๊ตฌ๋ฉ๋‹ˆ๋‹ค.
*ํ˜น์‹œ๋‚˜ ํ•ด์„œ ๋งํ•˜๋Š” ๊ฒ๋‹ˆ๋‹ค! explorer.exe๊ฐ€ ๊ฐ‘์ž๊ธฐ ๊บผ์ ธ์„œ ๋‹นํ™ฉํ•ด๊ฐ€์ง€๊ณ *
*์ด ์ฐฝ์„ ๋„์‹œ๋ฉด ์•ˆ๋ผ์š”!!!*
 
๋ฌธ์ œ์˜ ํžŒํŠธ๋Š” ์–ด๋””์„œ ๋ณด๋‚˜์š”?
๋ฌธ์ œ์˜ ํžŒํŠธ๋Š” ๋ผ๋””์œ  ์‰˜ํ„ฐ์— ์žˆ๋Š” \'\'๋Œ€.๋จธ.๋ฆฌ\'\'๋ผ๋Š” ๊ฒŒ์ž„์„ ํ”Œ๋ ˆ์ด ํ•ด ๋ณด์‹œ๋ฉด ์•„์‹œ๊ฒŒ ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค!
์•„๋ž˜์— ์žˆ๋Š” ์‚ฌ์ดํŠธ์—์„œ \'\'๋Œ€.๋จธ.๋ฆฌ\'\'๋ฅผ ๋‹ค์šด ๋ฐ›์•„ ํ”Œ๋ ˆ์ด ํ•˜์‹ญ์‹œ์˜ค!

 

\'\'๋Œ€.๋จธ.๋ฆฌ\'\'๋‹ค์šด๋กœ๋“œ : hxxps://shelter.id/radiyu5/community/board/all(modal:_/radiyu5/10461)
 
ํžŒํŠธ๋ฅผ ๋ณด์•˜๋Š”๋ฐ๋„ ๋ฌธ์ œ์˜ ์ •๋‹ต์„ ๋ชจ๋ฅด๊ฒ ์–ด์š”!! ๋„์™€์ฃผ์„ธ์š”!!!
๋ฌธ์ œ์˜ ํžŒํŠธ๋ฅผ ๋ณด์•˜๋Š”๋ฐ๋„ ๋ฌธ์ œ์˜ ์ •๋‹ต์„ ๋ชจ๋ฅด์‹œ๊ฒ ๋‹ค๋ฉด ์•„๋ž˜์˜ ์ฃผ์†Œ๋กœ ๋น„์šฉ์„ ์ง€๋ถˆํ•˜์‹ญ์‹œ์˜ค!
๋น„์šฉ์€ ํŠธ์œ•, ํˆฌ๋„ค์ด์…˜์œผ๋กœ๋งŒ ํ—ˆ์šฉ๋ฉ๋‹ˆ๋‹ค.
 
ํŠธ์œ•(twip)์œผ๋กœ ์ง€๋ถˆํ•˜๊ธฐ
hxxps://twip.kr/radiyu
 
ํˆฌ๋„ค์ด์…˜์œผ๋กœ ์ง€๋ถˆํ•˜๊ธฐ
hxxps://toon.at/donate/637246377212080144
 
์ง€๋ถˆ ๊ธˆ์•ก์€ 120210์› ์ž…๋‹ˆ๋‹ค. ์ง€๋ถˆ์ด ํ™•์ธ๋˜๋ฉด ๊ทธ ์ฆ‰์‹œ ๋ฌธ์ œ์˜ ๋‹ต์„ ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.
 
==(**!!๊ฒฝ๊ณ !!**)==
 
์ด ์ฐฝ์„ ๋„๊ฑฐ๋‚˜ Game.exe(Radian_Radiware_Radiyu.exe)๋ฅผ
์ œ๊ฑฐํ•˜์ง€ ๋งˆ์‹œ๊ณ  ๋ฌธ์ œ๋ฅผ ํ’€๊ณ  ๋ฌธ์ œ์˜ ์ •๋‹ต์ด
ํ™•์ธ ๋  ๋•Œ ๊นŒ์ง€ ์ž ์‹œ ๋™์•ˆ ์•ˆํ‹ฐ ๋ฐ”์ด๋Ÿฌ์Šค(๋ฐฑ์‹ : ์•Œ์•ฝ, V3, AppCheck๋“ฑ ์„)๋ฅผ
๋น„ํ™œ์„ฑํ™” ํ•˜์‹ญ์‹œ์˜ค!
*๋น„ํ™œ์„ฑํ™”๋Š” ์ž ์‹œ ๋™์•ˆ ๋ฐฑ์‹ ์„ ๊บผ๋‹ฌ๋ผ๋Š” ๊ฒ๋‹ˆ๋‹ค...*

 

์™œ? ๋ฐฑ์‹ ์„ ๊บผ์•ผ ๋˜๋Š”๊ฑฐ์•ผ?
*์™œ๋ƒํ•˜๋ฉด ๋ฐฑ์‹ ์ด ์ด ์ฐฝ์„ ๋ฐ”์ด๋Ÿฌ์Šค๋กœ ๊ฐ์ง€ํ•ด์„œ ์ž๋™์œผ๋กœ ์‚ญ์ œ๋˜๋ฉด*
*๋ณต๊ตฌ๊ฐ€ ๋ถˆ๊ฐ€๋Šฅ ํ•ด์ง€๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค!!!*
 
์ด ์ฐฝ์„ ๋„๊ฑฐ๋‚˜ ์•ˆํ‹ฐ ๋ฐ”์ด๋Ÿฌ์Šค๊ฐ€ ์—…๋ฐ์ดํŠธ ๋˜์–ด์„œ
์ด ์†Œํ”„ํŠธ์›จ์–ด๊ฐ€ ์ž๋™์œผ๋กœ ์ œ๊ฑฐ๋˜๋ฉด ๋ฌธ์ œ๋ฅผ ๋งž์ถ”๋”๋ผ๋„
๋ผ๋””์œ ๊ฐ€ ๋จน์€ ํŒŒ์ผ๋“ค์„ ๋ณต๊ตฌ ํ•  ์ˆ˜ ์—†๋‹ค๊ณ  ๋‘๋ฒˆ ๊ฒฝ๊ณ  ํ–ˆ์Šต๋‹ˆ๋‹ค!
*๋”ด ๋งํ•˜๊ธฐ ์—†๊ธ”* ^^
 
ํ•ด๋‹น ๋žœ์„ฌ์›จ์–ด๋Š” RSA-AES์•”ํ˜ธํ™”๋ฅผ ์‚ฌ์šฉํ•ด์„œ ๋งŒ๋“ค์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ๋ผ๋””์œ  ๋žœ์„ฌ์›จ์–ด ์ฐฝ์„ ๋„๊ฒŒ ๋œ๋‹ค๋ฉด
์•”ํ˜ธํ™”๋œ ํ‚ค๋Š” ์ž๋™์œผ๋กœ ์—†์–ด์ ธ ๋ฒ„๋ ค ๋ณตํ˜ธํ™”๊ฐ€ ๋ถˆ๊ฐ€๋Šฅ ํ•ฉ๋‹ˆ๋‹ค!!!
 
**์žฅ๋‚œ์œผ๋กœ ํ•˜๋Š” ๋ง์ด ์•„๋‹˜์„ ๋ฐํž™๋‹ˆ๋‹ค!**

In the picture below, you can see what a folder with files encrypted by the Radiyu looks like. Each filename has the โ€œ.Radiyuโ€ extension appended to it.

Radiyu Virus - encrypted .Radiyu files

An example of encrypted .Radiyu files.

How did my machine catch Radiyu ransomware?

There are many possible ways of ransomware injection.

There are currently three most exploited ways for evil-doers to have the Radiyu virus working in your system. These are email spam, Trojan introduction and peer file transfer.

  • If you open your inbox and see emails that look just like notifications from utility services companies, delivery agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, be wary of opening those letters. They are very likely to have a malicious item enclosed in them. Thus it is even riskier to open any attachments that come with emails like these.
  • Another option for ransom hunters is a Trojan horse scheme. A Trojan is a program that gets into your computer disguised as something different. Imagine, you download an installer of some program you need or an update for some software. But what is unpacked turns out to be a harmful agent that corrupts your data. Since the installation wizard can have any title and any icon, you have to make sure that you can trust the resource of the things youโ€™re downloading. The optimal thing is to trust the software developersโ€™ official websites.
  • As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the folder containing the downloaded files with the antivirus as soon as the downloading is complete.

How to remove ransomware?

It is crucial to note that besides encrypting your data, the Radiyu virus will probably deploy Vidar Stealer on your computer to get access to credentials to different accounts (including cryptocurrency wallets). That spyware can extract your credentials from your browserโ€™s auto-filling cardfile.

How do I avert ransomware infiltration?

Radiyu ransomware doesnโ€™t have a endless power, so as any similar malware.

You can defend your system from ransomware attack in several easy steps:

  • Never open any emails from unknown mailboxes with strange addresses, or with content that has nothing to do with something you are expecting (how can you win in a lottery without participating in it?). In case the email subject is likely something you are expecting, check all elements of the dubious letter carefully. A fake letter will surely contain mistakes.
  • Avoid using cracked or untrusted programs. Trojans are often spreaded as an element of cracked software, possibly as a โ€œpatchโ€ preventing the license check. Understandably, untrusted programs are difficult to distinguish from trustworthy ones, as trojans may also have the functionality you seek. Try searching for information about this software product on the anti-malware forums, but the optimal way is not to use such programs at all.

Frequently Asked Questions

๐Ÿค” How can I open โ€œ.Radiyuโ€ files?Is it possible to openโ€œ.Radiyuโ€ files?

Negative. That is why ransomware is so frustrating. Until you decode the โ€œ.Radiyuโ€ files you will not be able to access them.

๐Ÿค” I really need to decrypt those โ€œ.Radiyuโ€ files ASAP. How can I do that?

Itโ€™s good if you have fะฐr-sightedly saved copies of these important files elsewhere. Otherwise, you might try to employ System Restore. The only question is whether you have saved any Restore Points that would be helpful now. The rest of the methods require patience.

๐Ÿค” What actions should I take if the Radiyu ransomware has blocked my computer and I canโ€™t get the activation key.

๐Ÿค” And what should I do now?

Many of the blocked files might still be within your reach

  • If you exchanged your critical files through email, you could still download them from your online mail server.
  • You may have shared images or videos with your friends or family members. Simply ask them to send those pictures back to you.
  • If you have initially got any of your files from the Web, you can try doing it again.
  • Your messengers, social networks pages, and cloud disks might have all those files too.
  • Maybe you still have the needed files on your old computer, a portable device, phone, external storage, etc.

USEFUL TIP: You can use data recovery utilities1 to get your lost data back since ransomware encodes the copies of your files, deleting the authentic ones. In the tutorial below, you can learn how to use PhotoRec for such a restoration, but remember: you wonโ€™t be able to do it before you eradicate the ransomware itself with an antivirus program.

I need your help to share this article.

It is your turn to help other people. I have written this guide to help people like you. You can use the buttons below to share this on your favorite social media Facebook, Twitter, or Reddit.
Brendan Smith

References

  1. Hereโ€™s the list of Top 10 Data Recovery Software Of 2023.

About the author

Brendan Smith

Cybersecurity analyst covering malware families, suspicious files, and detection alerts. Brendan focuses on clear explanations of what a warning means, when it may be a false positive, and which cleanup steps are appropriate.

Leave a Comment