Zekwacrypt ransomware is a file locking virus that attempts to delete your backups

Zekwacrypt virus (also known as Win32/Zekwacrypt.A) is a dangerous ransomware-type cyber infection[1] that damages a wide range of files stored on the targeted computer. It is capable of encrypting more than 600 different file types, so there’s no doubt that ransomware attacks will cause huge damage to the users.
All images, databases, documents, audio, video, and other files will be encrypted with a strong encryption algorithm. During data encryption, the ransomware appends a unique 7-character file extension to the targeted files. Therefore, after data encryption, example.jpg will be renamed to example.jpg.zxcvbnm.
| Name | Zekwacrypt |
| Type | Ransomware |
| File extension | .zxcvbnm |
| Ransom notes | encrypted_readme.txt and encrypted_list.txt |
| Distribution | Malicious spam email attachments and infectious social media links |
| Removal | Perform a full system scan with anti-malware software |
| System fix | You can remediate Windows system files and fix virus damage with PC repair tool FortectIntego |
What is more, the malware searches for deletes all files that include the name “backup” and “backups,” so recovering files from Shadow Volume Copies[2] is impossible. The only files that are left untouched by the Zekwacrypt virus are:
- System
- Temp
- Framework
- Torrent
- Borland
- Content.IE5
- I386
- and Mozilla.
What makes this malware even more dangerous is that it does need an Internet connection for data encryption. Therefore, disconnecting from the Internet won’t help to stop malware. However, disconnecting may only help to protect other devices that may be connected to the same network.
After infiltration, ransomware also modifies Windows Registry and drops two files in each directory and folder that includes encrypted files – encrypted_readme.txt and encrypted_list.txt. These documents include information about encrypted files and the possibility to decrypt them. Similar to other ransomware, the virus also demands to pay the ransom[3].
We want to remind you that transferring a particular amount of money for cybercriminals does not guarantee that your files will be restored. Cybercriminals may have hidden goals to demand more money, install new malware, or simply took your money and disappear[4].
It’s better to remove Zekwacrypt from the computer and lose your files than sponsor illegal hackers’ projects. For virus elimination, you will need strong and reputable malware removal tools such as SpyHunterCombo Cleaner. When malware removal is over, try additional data recovery methods or use data backups to restore encrypted files. Also, FortectIntego could take care of Windows system file remediation.
Ransomware distribution methods and prevention tips
Developers of the ransomware mainly distribute malware executable via malicious spam email attachments. Therefore, you can easily get infected with ransomware or any other virus after opening a suspicious attachment. Bear in mind that it’s not safe to open spam emails and links or files added to them.
If you do not know the sender or the message itself seems suspicious (for example, lack of credentials, grammar or spelling mistakes, empty message, strange email address, etc.[5]), do not rush opening provided files or documents. This click may end up with a ransomware attack and data loss. Furthermore, malvertising may be another malware distribution way.
Therefore, you should be aware of the fact that malicious ads may be placed on legitimate websites and look safe. Before clicking interesting ads, think about the possible consequences. The virus may also be using exploit kits to check and use computer vulnerabilities. So, strengthen your computer’s protection by installing antivirus software and keep all the programs installed on your PC up-to-date.
Instructions for Zekwacrypt removal
Trying to remove the virus manually may end up with an even bigger loss. Ransomware is capable of changing the Windows registry as well as renaming its malicious files with the names of safe and necessary Windows OS files.
Therefore, you may accidentally delete crucial files instead of dangerous ones (system damage can be corrected with repair tools such as FortectIntego). Bear in mind that only experienced IT specialists can complete this task successfully. For regular computer users, automatic Zekwacrypt removal is the only option to clean their devices.
Automatic elimination requires installing a professional malware removal tool (e.g. SpyHunterCombo Cleaner or MalwarebytesMalwarebytes) and running a full system scan with an updated program. We want to warn that sometimes malware prevents victims from installing or accessing security tools. If this happens to you, follow the instructions below to reboot your PC to the Safe Mode and activate malware removal programs.
Did this guide help?
3 comments
Vinod
nasty virus!!!
Kumar
When will they stop creating ransomware viruses?
encrypted
lucky me, I had data backups!