PSCrypt – ransomware-type virus which requires 2500 Ukrainian hryvnia for decrypting encrypted files

PSCrypt is ransomware virus which was noticed for the first time in 2017. Since then, it has been infiltrating systems, encrypting their files and adding .docs file extension next to each name. Additionally, PSCrypt ransomware leaves a ransom note called Paxynok.html in every folder of the encrypted data and asks paying 2500 Ukrainian hryvnia for the decryption of these files. Naturally, it is more than obvious that the ransomware is targeting computer users in Ukraine[1] and Russia.
Previously, PSCrypt had been appending .pscrypt or .paxynok file extensions. To make the encrypted data readable again, the virus suggests buying Bitcoins[2] at LocalBitcoins, Coinbase or XChange and then transferring a required amount of money to a provided Bitcoin wallet.
To cyber criminals, the victim is asked contacting them via systems64x@tutanota.com email address which is also provided in the ransom note. Crooks claim that their “operator will give the further instructions.” According to the ransom note, victims have to pay 2500 hryvnia (approximately 96 US dollars) in order to decrypt corrupted files. The cyber criminals provide an unusual ransom payment method – paying the ransom via IBOX terminal.
Cyber security experts advise victims not to pay the ransom. The virus simply seeks to swindle money from the victim. Although currently there are no tools that could help to recover files corrupted by this ransomware, we suggest staying patient and focusing on PSCrypt removal.
Malware not only encrypts files but also makes the system vulnerable. It might make various modifications in the system, create new or delete existing registry entries, and even open the backdoor to other cyber threats. Thus, having this malicious program installed on a device might lead to even more serious problems.
It goes without saying that you should stop thinking about data recovery until you remove PSCrypt ransomware from the computer. We recommend using FortectIntego or another anti-malware software. If you are a Russian-speaking computer user, you might want to visit Bedynet.ru site[3] which provides information about computer viruses in your language.

Distribution strategies of the file-encrypting virus
Ransomware is really different from other viruses and cybercriminals distribute it using strict techniques. Some of these methods, however, are also used to spread typical malware like Trojans, keyloggers and other critical programs. The main ransomware attack vectors are:
- Malicious spam;
- Exploit kits;[4]
- Compromised websites;
- Malware-laden ads;
- Trojans;
- Illegal downloads such as software cracks.
All of these attack vectors help this ransomware infect thousands of computers per year. As you can see, we mentioned malicious spam first. It is the most basic and yet the most efficient technique to compromise the target computer. The victim receives an email that looks quite convincing.[5] Typically, scammers pretend to be:
- Someone looking for a job (email attachment can be called “Resume,” “MyResume” or similarly);
- A legal authority sending a subpoena or tax-return documents;
- A well-known company sending an invoice or another document.
After opening such email, the victim can find a JavaScript, Word, ZIP or executive file. As soon as the victim opens such file, the system gets infected. Therefore, you should stay clear of emails sent by unknown people or someone who seems to be a scammer.
Other techniques we listed are hard to fight against; usually, the only combination that helps to protect your PC or survive a PSCrypt virus attack is an anti-malware program and a data backup. If you do not have these, take care of this matter immediately.
Removal instructions for the PSCrypt ransomware and data recovery options
If you wish to continue using your computer, you have to remove PSCrypt virus immediately. Do not delay its removal because keeping such ransomware on the system is not a good idea. Besides, you can never know whether the virus compromised your PC alone or together with some other pieces of malware.
Therefore, for an ultimate PSCrypt removal, you should run the anti-malware program to check your system automatically. We highly recommend choosing one of these tools: FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Of course, you can choose your preferred software too. However, make sure that it’s up-to-date.
However, malware may be resistant. Thus, below, we provide instructions on how to launch your chosen security software. Finally, use instructions we provided to restore your files.
Was this guide helpful?
Be the first to comment