Anoncrack Ransomware Virus - How To Remove?

 

Anoncrack ransomware virus – yet another ransomware infection based on Hidden Tear open source ransomware base, such as Balbaz ransomware or Defray ransomware. It is a typical ransomware infection and if your computer is infected with it, you are about to face some pretty severe consequences.

There are some good new – all ransomware infections developed on the basis of Hidden Tear open source project are pretty similar, thus it won’t be very difficult to puzzle it out. However, some consequences caused by this virus are still detrimental – you should take it very seriously.

One way or another, sooner or later, Anoncrack virus will get your attention (if it is inside of your computer). It will block your files by adding a specific extension to every one of them so you won’t be able to open them and then demand a ransom in order to unlock them.

Anoncrack ransomware virus

Infection methods of Anoncrack ransomware virus

Infecting computers with ransomware usually is the same – malicious files come as an attachment to spam emails. Cyber criminals just spread a bunch of spam email letters and hope that someone will open them and open the attachment. Usually those infected attachments are named as an important .jpg or .doc files – users are tempted to open them and once that’s done it’s game over. Malicious processes of the virus will run automatically and if you don’t have any real-time anti-malware protection of your system, Anoncrack virus will successfully take over your computer.

It’s worth to mention that spam emails is not the only way this ransomware can enter your computer. It can also come as a fake update of software (such as Flash player updates or updates to your Windows OS). Again, it is very important to keep the system protected with anti-malware software because only this way you will be able to avoid mistakes that can be very costly.

As reported by MalwareHunterTeam on Twitter, Anonkrack comes as a Paypal generator, so look our for that.

Processes of Anoncrack ransomware

Installed on your computer Anoncrack will scan it for files that can possibly be encrypted. Once that is done, it will added an extension “.crack” to the end of all those files and this way encrypt them. That means you won’t be able to open them or use in any other way.

Immediately after that you will notice a new .txt file on your desktop called “pago.txt”. It is a so-called ransom note with the instructions how to pay the ransom. The virus will also change your desktop picture with some text on there too.

All texts are written in Spanish, thus we can presume that this ransomware infection either came from Spain or is targeted to the Spanish market. Original text of the ransom note:

Tu computador ha sido hackeado y encriptado by ANONCRACK …!

¿COMO RECUPERAR TUS ARCHIVOS?

1. Realiza el pago de 30 USD ha esta direccion bitcoin : 1CvWhugm6QbHisVvhyRuKn81kQgVVs4ov8
2. Envia una captura del pago y nombre de tu PC ha este correo: anoncrack@protonmail.com
3. Una vez verificado tu pago, te enviaremos la KEY de DESENCRIPTACION
4. Disfruta de tus archivos personales

Tus amigos ANONCRACK 😉

What surprises us the most is the amount of the ransom – it’s only $30. Usually viruses like this are demanding something around $300 and up, thus such a low price can be very alluring for most of the victims. They are told that all files can be decrypted by using a special and unique key (which is true), and the key is stored on a remote server owned by the hackers behind Anoncrack. In order to receive that key, you are asked to pay the ransom. Even though the price is fairly low, we suggest not to do that. You can never trust cyber criminals, thus you can’t be sure that you will receive the key after paying the ransom.

How to deal with ANONCRACK virus?

Firstly, you should make sure that malicious files are eliminated from your system. It can be done with some help of anti-malware tools, such as Reimage or SpyHunter. Scan your computer with either one of them and the virus will be gone in minutes. It will also protect your computer from similar infections in the future so it’s worth to keep it installed. You can use other anti-malware tools of your choice as well, however, make sure that they are legitimate before downloading or purchasing anything. It is also recommended to get familiar with security options fighting against ransomware.

Sadly, anti-malware software won’t be able to decrypt your files and at this moment, there are no free decryptor on the market that you can use, but we will update this post as soon as one is out. For now, you can restore your files from a backup or set your system to the date previous to the infection, if you have a valid copy of your hard drive.

How to recover Anoncrack ransomware virus encrypted files and remove the virus

Step 1. Restore system into last known good state using system restore

1. Reboot your computer to Safe Mode with Command Prompt:


for Windows 7 / Vista/ XP
  • Start Shutdown RestartOK.
  • Press F8 key repeatedly until Advanced Boot Options window appears.
  • Choose Safe Mode with Command Prompt. Windows 7 enter safe mode

for Windows 8 / 10
  • Press Power at Windows login screen. Then press and hold Shift key and click Restart. Windows 8-10 restart to safe mode
  • Choose TroubleshootAdvanced OptionsStartup Settings and click Restart.
  • When it loads, select Enable Safe Mode with Command Prompt from the list of Startup Settings. Windows 8-10 enter safe mode

2.Restore System files and settings.

  • When Command Prompt mode loads, enter cd restore and press Enter.
  • Then enter rstrui.exe and press Enter again. CMD commands
  • Click “Next” in the windows that appeared. Restore point img1
  • Select one of the Restore Points that are available before Anoncrack ransomware virus has infiltrated to your system and then click “Next”. Restore point img2
  • To start System restore click “Yes”. Restore point img3

Step 2. Complete removal of Anoncrack ransomware virus

After restoring your system, it is recommended to scan your computer with an anti-malware program, like Reimage and remove all malicious files related to Anoncrack ransomware virus. You can check other tools here.


Step 3. Restore Anoncrack ransomware virus affected files using Shadow Volume Copies

If you do not use System Restore option on your operating system, there is a chance to use shadow copy snapshots. They store copies of your files that point of time when the system restore snapshot was created. Usually Anoncrack ransomware virus tries to delete all possible Shadow Volume Copies, so this methods may not work on all computers. However, it may fail to do so.

Shadow Volume Copies are only available with Windows XP Service Pack 2, Windows Vista, Windows 7, and Windows 8. There are two ways to retrieve your files via Shadow Volume Copy. You can do it using native Windows Previous Versions or via Shadow Explorer.

a) Native Windows Previous Versions

Right-click on an encrypted file and select PropertiesPrevious versions tab. Now you will see all available copies of that particular file and the time when it was stored in a Shadow Volume Copy. Choose the version of the file you want to retrieve and click Copy if you want to save it to some directory of your own, or Restore if you want to replace existing, encrypted file. If you want to see the content of file first, just click Open.


Previous version
b) Shadow Explorer

It is a program that can be found online for free. You can download either a full or a portable version of Shadow Explorer. Open the program. On the left top corner select the drive where the file you are looking for is a stored. You will see all folders on that drive. To retrieve a whole folder, right-click on it and select “Export”. Then choose where you want it to be stored.
Shadow explorer

Step 4. Use Data Recovery programs to recover Anoncrack ransomware virus encrypted files

There are several data recovery programs that might recover encrypted files as well. This does not work in all cases but you can try this:

  • We suggest using another PC and connect the infected hard drive as slave. It is still possible to do this on infected PC though.
  • Download Data Recovery Pro (commercial)
  • Install and scan for recently deleted files. Data Recovery Pro

Note: In many cases it is impossible to restore data files affected by modern ransomware. Thus I recommend using decent cloud backup software as precaution. We recommend checking out Carbonite, BackBlaze, CrashPlan or Mozy Home.

Manual removal

 

Important Note: Although it is possible to manually remove Anoncrack ransomware virus, such activity can permanently damage your system if any mistakes are made in the process, as advanced spyware parasites are able to automatically repair themselves if not completely removed. Thus, manual spyware removal is recommended for experienced users only, such as IT specialists or highly qualified system administrators. For other users, we recommend using Reimage or other tools found on 2-viruses.com.

Processes:
Extensions:
External decryptor:
     
 

About the author

 - Malware researcher
Continuous ads and struggles to browser the Internet due to web-based malware is what really grinds my gears. That’s why my main goal is to fight against malware like adware or web hijackers and provide our readers with efficient solutions in this particular field. Keeping up to date with newest trends in cyber security world is a must nowadays and thus my interest goes way beyond malware infections - IoT security, international cyber wars and hacking outbreaks are under my radar as well.
 
October 12, 2017 08:19, October 12, 2017 08:19
 
   
 

Leave a Reply

Your email address will not be published. Required fields are marked *