Crypren is a highly dangerous cyber infection listed as ransomware

Crypren is a ransomware virus[1] that attacks random system's via infected email attachments and locks personal files with .encrypted file extension. An example of a file encrypted by Crypren ransomware would be: photo199.jpg.encrypted. The ransomware payload spreads in a form of Crypren.exe. It uses RSA-2048 algorithm[2] to lock personal files out and runs multiple scripts to root deeply into OS. Upon successful installation and file encryption, the virus leaves a READ_THIS_TO_DECRYPT.txt file on the desktop and drops a HTML file with payment instructions.
| Name | Crypren |
|---|---|
| Type | Ransomware |
| Danger level | High. Can cause permanent data loss |
| Related files | Crypren.exe |
| File extension | .encrypted |
| Ransom note | READ_THIS_TO_DECRYPT.txt |
| Currency accepted | Bitcoin only |
| Decryptable | No |
| A scan with FortectIntego will eliminate Crypren ransoware permanently | |
Crypren virus has been first spotted in 2016 by a group of ransomware researchers. It does not differ from the rest of ransomware family members. Its payload (Crypren.exe) is being distributed via malspam, rogue software updates, drive-by-download, and other social engineering strategies.
As soon as it is downloaded, it launches a scanner, enables RSA cipher, and appends .encrypted file extension to the following file formats:
sql, .mp4, .7z, .rar, .m4a, .wma, .avi, .wmv, .csv, .d3dbsp, .zip, .sie, .sum, .ibank, .t13, .t12, .qdf, .gdb, .tax, .pkpass, .bc6, .bc7, .bkp, .qic, .bkf, .sidn, .sidd, .mddata, .itl, .itdb, .icxs, .hvpl, .hplg, .hkdb, .mdbackup, .syncdb, .gho, .cas, .svg, .map, .wmo, .itm, .sb, .fos, .mov, .vdf, .ztmp, .sis, .sid, .ncf, .menu, .layout, .dmp, .blob, .esm, .vcf, .vtf, .dazip, .fpk, .mlx, .kf, .iwd, .vpk, .tor, .psk, .rim, .w3x, .fsh, .ntl, .arch00, .lvl, .snx, .cfr, .ff, .vpp_pc, .lrf, .m2, .mcmeta, .vfs0, .mpqge, .kdb, .db0, .dba, .rofl, .hkx, .bar, .upk, .das, .iwi, .litemod, .asset, .forge, .ltx, .bsa, .apk, .re4, .sav, .lbf, .slm, .bik, .epk, .rgss3a, .pak, .big, wallet, .wotreplay, .xxx, .desc, .py, .m3u, .flv, .js, .css, .rb, .png, .jpeg, .txt, .p7c, .p7b, .p12, .pfx, .pem, .crt, .cer, .der, .x3f, .srw, .pef, .ptx, .r3d, .rw2, .rwl, .raw, .raf, .orf, .nrw, .mrwref, .mef, .erf, .kdc, .dcr, .cr2, .crw, .bay, .sr2, .srf, .arw, .3fr, .dng, .jpe, .jpg, .cdr, .indd, .ai, .eps, .pdf, .pdd, .psd, .dbf, .mdf, .wb2, .rtf, .wpd, .dxg, .xf, .dwg, .pst, .accdb, .mdb, .pptm, .pptx, .ppt, .xlk, .xlsb, .xlsm, .xlsx, .xls, .wps, .docm, .docx, .doc, .odb, .odc, .odm, .odp, .ods, .odt.
Then the victim is presented with the payment instructions – a text file READ_THIS_TO_DECRYPT.txt on the desktop and READ_THIS_TO_DECRYPT HTML. Earlier Crypren ransom was considered to be relatively small – 0.1 BTC. However, while in 2016 0.1 BTC was approximately 37 USD, currently the ransom reaches approximately 700 USD.
Virukset.fi[3] cyber security experts warn that this ransomware did not discontinue. Although it hasn't been active in 2017, researchers found it revived in the beginning of April 2018. Although 45 out 65 AV engines are capable of detecting (Trojan.Ransom.Crypren, Trojan-Ransom.Win32.Crypren.acmd,Ransom.Win32.Crypren.a, Ransom_Crypren.R002C0DD318, etc.), ransomware viruses keep mutating and find out how to evade detection.

If this ransomware has already attacked your PC, we would strongly recommend you to perform a full Crypren removal using FortectIntego, SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or another reputable anti-virus. Manual ransomware elimination is not recommended and is hardly possible. That's because it corrupts Windows Registry entries, compromises boot order, injects related components into core system's folders, and initiates other complex modifications that can be reverted with a professional utility only.
You'll be able to recover encrypted data after a complete Crypren removal. Please do not trust criminals and rėestrain from paying the ransom despite the fact how small it might seem to you. Instead of a paid Crypren decryptor, crooks can foist spyware or worm.
You can find a list of alternative ways on how to decrypt files encrypted by Crypren ransomware at the end of this article.
The transmission of crypto malware
This threat is seen traveling along with spam. In other words, cyber criminals have created persuasive spam emails which contain infected attachments. As a result of users’ curiosity, a relatively high number of users worldwide reported their computers to be infected with crypto-malware. Thus, when the attachment is open, the virus gets activated, and it takes off to encrypt the files.

Additionally, the virus may infiltrate your computer via exploit kits or so-called trojans. They are regarded as especially dangerous for their ability to pass themselves as legitimate files. Thus, at this point, it is of vital importance to have an anti-spyware program, for example, FortectIntego, on your system for it detect such threats as exploit kits.
In addition, the virus may also disperse via peer-to-peer sharing and gaming websites. These websites are often filled with various hyperlinks and distracting advertisements offering to visit certain websites or purchase specific applications. All in all, you should not get carried away and avoid click on suspicious links and images. Finally, let us proceed to the section where will tell you how to remove ransomware effectively.
Crypren removal steps
The only effective way to remove Crypren virus and root out its helper objects, files, and processes is to install a powerful security tool and run a full system scan with it. Indeed, you can use a program that is currently running on your PC, but don't forget to update its definitions before a scan.
As we have already pointed out, manual Crypren removal is not possible. By deleting random files you can damage the system and cause fatal crash. Therefore, we would recommend choosing a risk-free removal option.
Was this guide helpful?
3 comments