RensenWare Virus – Remove It and Restore .RENSENWARE Files

RensenWare Virus – Remove It and Restore .RENSENWARE Files

This article will aid you in removing the RensenWare ransomware absolutely. Follow the ransomware removal instructions given at the bottom of the article.

The RensenWare virus is an encrypting ransomware type. The ransomware will lock your files and place a secondary extension to them, which is .RENSENWARE. After your computer gets infected, the RensenWare cryptovirus will display a window with a ransom message. That message shows right after the file-encryption process is completed and instead of money, requires you to reach an insanely huge score in the game “Touhou Seirensen 12 ~ Undefined Fantastic Object”. Read on to see how you could decrypt your files.

Threat Summary

TypeRansomware, Cryptovirus
Short DescriptionThe ransomware virus will encrypt your files and also put a lock screen window up.
SymptomsThe ransomware will display a window containing a ransom note and will encrypt files while placing the .RENSENWARE extension to them.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by RensenWare


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss RensenWare.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

RensenWare Virus – Delivery

The RensenWare virus might deliver its infection through different ways. The payload file which executes the malicious script for this ransomware, that in turn infects your computer system, is circling around the Internet. Malware researchers have found an executable file that delivers the payload. You can see the detections of various security vendors for that recently found executable by checking the screenshot from the VirusTotal service right here:

The RensenWare virus could also deliver its payload file on social media sites and file-sharing networks. Freeware applications which are found on the Web could be presented as helpful but at the same time could be hiding the malicious script for this cryptovirus. Don’t be opening files right when you have downloaded them, especially if they come from sources such as suspicious links or emails. Instead, you should scan them beforehand with a security tool, while also checking the sizes and signatures of those files for anything that seems unusual. You should give the tips for ransomware prevention a read, found on our forums.

RensenWare Virus – Further Details

RensenWare is a cryptovirus of the ransomware variety. Once your files get encrypted by this latest variant, they will receive the .RENSENWARE extension. The ransom isn’t money, but instead, you as a victim are required to reach an insanely huge score in the game “Touhou Seirensen 12 ~ Undefined Fantastic Object”. In the screenshot down here you can see how that game looks like:

The ransom message will pop up inside a window screen after the encryption process is finished. That message contains instructions on how you might get your files back. The note of RensenWare opens in a lock screen. You can see the note in the snapshot provided right here:

The ransom note inside that window reads the following:

Rensenware WARNING!


Your syste have been encrypted by RensenWare

What the HELL is it?

Minamitsu “The Captain” Murasa encrypted your precious data like documents, musics, pictures, and some kinda project files. it can’t be recovered without this application because they are encrypted with highly strong encryption algorithm, using random key.

How can I recover my files?

That’s easy. You just play TH12 ~ Undefined Fantastic Object and score over 0.2 billion in LUNATIC level. this application will detect TH12 process and score automatically. DO NOT TRY CHEATING OR TEMRMINATE THIS APPLICATION IF YOU DON’T WANT TO BLOW UP THE ENCRYPTION KEY!

As clearly seen from the ransom message above, the developer of the RensenWare cryptovirus wants the ransom to be paid out by playing a game and reaching an insane amount of points. This particular ransomware is set as a joke, but it got leaked to the Internet by mistake. Keep on reading and see what could be done about decrypting your files.

RensenWare Virus – Encryption Process

RensenWare ransomware is set to encrypt all files which have the following extensions:

→.jpg, .txt, .png, .pdf, .hwp, .psd, .cs, .c, .cpp, .vb, .bas, .frm, .mp3, .wav, .flac, .gif, .doc, .xls, .xlsx, .docx, .ppt, .pptx, .js, .avi, .mp4, .mkv, .zip, .rar, .alz, .egg, .7z, .raw

The encryption algorithm is discovered to be AES 256-bit by malware researchers. The extension which will be given to files that have been encrypted is .RENSENWARE and it will be appended as a secondary one, keeping the original extension of the files, including their file names.

Don’t worry about your computer system being infected or playing the game to unlock your files. Although the ransomware threatens that if you somehow cheat your data will be irrevocably lost, but no such system is actually implemented. All of your data files can be recovered with the help of a tool that lies about the game’s score, by placing the right amount, so the decryption process can begin. That tool is called rensenWare_forcer and it comes from the original developer with a note of apology as seen below:

If the tool didn’t decrypt some of the files, you would see an option to try and manually decrypt the rest:

Be warned, as the ransomware developer says to be extremely careful when tampering with the ransomware depending on what version it is, as quoted below:


The original version of the ransomware was intended as a joke, but other ones might be created as the source code of the virus was leaked.

Remove RensenWare Virus and Restore .RENSENWARE Files

If your computer got infected with the RensenWare virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.

Berta Bilbao

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

More Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share