What is ViaCrypt Ransomware?
ViaCrypt Ransomware is a threat first detected at the end of June, 2017 by malware analysts. It enters computers to encrypt files and then tells users to enter a decryption key to restore them. Unfortunately, it is not so easy to get this key, but it seems that ViaCrypt Ransomware does not act like other ransomware-type infections do. That is, it does not demand money in exchange for the decryption key. Well, at least the version analyzed by specialists at anti-spyware-101.com does not even mention a ransom. To be frank, we cannot guarantee that all the users who encounter ViaCrypt Ransomware will need to go to unlock their files. It seems that there is a version that does not encrypt a single file after the entrance, so you should first check files stored on your PC first before taking action. If you encounter the version that does not lock personal data, all you need to do is to remove the ransomware infection from the system. That is, you do not even need to go to acquire the decryption key. You will find more about the removal of this ransomware infection at the end of this article.
What does ViaCrypt Ransomware do?
If a fully working version of ViaCrypt Ransomware ever slithers onto your computer, you will find all your files locked and having a new filename extension .via. What else indicates about the entrance of this infection is a new file your system has been encrypted! please read further instruction!.txt on Desktop. This file tells users that they cannot access their files because they have all been locked, and the only way to recover them is by “purchasing unlocking key.” Even though users are told that they have to purchase the unlock key, it seems that they could get it by uploading the public encryption key on http://sigmalab.lv/other/crypt/payment_request.php. You should definitely follow the step-by-step decryption instructions inside this file and try out this file restoration method. If it happens that you are told to send cyber criminals money for the decryption tool, do not pay a cent to them. In this case, you should try to recover your files from a backup. If you find this impossible, i.e. you do not have a backup of your data since you have never backed up your files, you should wait until specialists in the cyber security field develop a free decryptor. Unfortunately, we cannot promise that it will be developed soon.
Where does ViaCrypt Ransomware come from?
Research has revealed that ViaCrypt Ransomware might be distributed in spam emails and enter computers when users open their attachments. Also, users might also download it from dubious file-sharing websites. Needless to say, they find out about that only when they notice that their files have been encrypted or discover a ransom note left by this infection on Desktop. These are not all the symptoms showing that ViaCrypt Ransomware is active on the system. If you can discover crawl.exe in %APPDATA%\Microsoft\Windows\Start Menu\\Programs\Startup and %USERPROFILE%\Desktop too, there is no doubt that ViaCrypt Ransomware is the one you should blame for encrypting your files. Ransomware infections are sneaky threats which do not need to get permission to slither onto computers, so you must be more cautious in the future. Unfortunately, not all the users, even those experienced ones, manage to protect their PCs from ransomware infections, so, in the opinion of experienced security specialists, a user must have an enabled security application on his/her PC.
How to delete ViaCrypt Ransomware
There are two methods to delete ViaCrypt Ransomware. If you are ready to erase all its components from your PC manually one by one, you should adopt the manual method. In this case, you will have to remove crawl.exe from two directories. Also, you will have to take care of .txt and .rkf files which have been created on Desktop. The good news is that our manual removal guide will help you. If you do not find it very helpful, you can erase this infection from your PC using an automated scanner as well. Make sure the scanner you are going to use is fully trustworthy before actually launching it.
ViaCrypt Ransomware removal guide
- Open the Windows Explorer (tap Win+E).
- Delete crawl.exe from %USERPROFILE%\Desktop and %APPDATA%\Microsoft\Windows\Start Menu\\Programs\Startup.
- Find two files your system has been encrypted! please read further instruction!.txt and your_encryption_public_key.rkf from Desktop and remove them one by one.
- Delete all suspicious recently downloaded files.
- Empty the Recycle bin.
tested removal of ViaCrypt Ransomware* 100% FREE spyware scan and
0 Comments.