Open MalwareTips in Safari and tap Share. You may need to open the Page Menu first.
Choose Add to Home Screen. If it is not listed, use Edit Actions to add it.
Keep Open as Web App enabled if shown, then tap Add.
Android
Open MalwareTips in Chrome or another browser that supports app installation.
Open the browser menu and look for Install app, Install and create shortcut, or Add to Home screen.
Choose Install and confirm. Wording varies by browser.
Desktop
Chrome: use the install icon in the address bar, or the menu under Cast, save and share.
Edge: open the menu, then More tools, Apps and Install this site as an app.
Safari on Mac: choose Share or File, then Add to Dock. Firefox on Windows: look for the web apps button in the address bar.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
Keep up with your conversations
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
The extension alone is usually not enough to identify the exact ransomware family with confidence, especially after so many years. I cannot safely tell you whether files with “.raldug” can be decrypted without more evidence.
What to do first
Do not delete the encrypted files.
Make copies of a few encrypted files and keep the originals untouched.
If you still have it, keep the ransom note, email, wallpaper change, or any file names created by the malware.
If the infected system is still powered on and connected, disconnect it from the network.
Best places to check for a decryptor
Use trusted ransomware identification and recovery resources:
That gives the best chance of identifying the ransomware family correctly.
Reality check
Because the attack happened 10 years ago, recovery depends on the specific ransomware strain:
Some old families now have free decryptors.
Some never received a public decryptor.
In some cases, backups, old cloud copies, or previous file versions are the only recovery path.
If you want help on MalwareTips
Post the following in the appropriate malware help section:
A sample ransom note
A screenshot of encrypted filenames
One harmless encrypted sample file, if allowed by forum rules
Whether you still have the original infected computer or only the encrypted files
That will let knowledgeable members analyze it more accurately.
Key takeaway
Do not assume the “.raldug” extension by itself is enough. The safest next step is to identify the ransomware through ID Ransomware or No More Ransom, then check whether a legitimate decryptor exists.
If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Double-click the FRST icon to run the tool. When the tool opens click Yes to disclaimer.
Press Scan button and wait for a while.
The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
Please attach the content of these two logs in your next reply.
Due to lack of activity, this topic is now closed. You requested help but did not respond to follow-up questions or instructions within three days and your topic has been moved here. If you still need help, open a new topic, and wait for a new helper.
Status
Not open for further replies.
Recently browsing
Members who viewed this thread in the last 5 minutes