Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2017

How to remove Crypt32@mail.ru ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Crypt32@mail.ru ransomware is looking for victims right now

Computer users should beware of Crypt32@mail.ru virus, which is a new ransomware variant that hails from Apocalypse ransomware family[1]. This ransomware strain is also known under Al-Namrood ransomware name, and it has been torturing victims for almost a year now. Crypt32@mail.ru ransomware virus is a program that can infect your system and damage[2] your personal files, and most likely you won’t even have time to react to the attack because the virus encrypts the data in minutes[3]. The indicated virus hasn’t changed much if compared to its previous version – it only provides a different email address to the victims. Respectively, it drops a ransom note called md5.txt and changes names of the files it encrypts this way: [original filename].ID-[8 characters+victim’s country code][Crypt32@mail.ru].[14 characters]. The ransomware uses AES encryption[4] to lock victim’s files securely, and it throws the decryption key to criminals’ servers right after completing the encryption procedure.

Crypt32@mail.ru virus

Speaking of data decryption, we can say that there are some Al-Namrood and Apocalypse decryption tools available, but they were created for previous versions of these viruses. However, you might need to wait for a while until malware analysts find a way to crack the new ransomware. Some malware researchers say that the virus’ code most likely was improved and that basically explains why previous decryption tools do not help to decrypt files with .ID-[8 characters+victim’s country code][Crypt32@mail.ru].[14 characters] extensions. However, you should not lose hope because malware analysts proved that Al-Namrood versions could be decrypted without paying the ransom. Therefore, we strongly recommend you to scan your PC with anti-malware software like FortectIntego and remove Crypt32@mail.ru virus completely. This way, you will toss out all dangerous files created by the virus, as well as all other shady programs. After eliminating the virus, you can try to restore your files using methods described below the article. As we said, there is hope that malware analysts will discover an antidote for files encrypted by Crypt32@mail.ru virus, so do not rush to collect money for the criminals.

How does this virus infect the computer?

According to the latest reports, Al-Namrood ransomware versions are mostly pushed to servers that have remote desktop services enabled. Attackers attempt to log into target computers via RDP[5] using brute-force attacks. To prevent such attacks, security experts advise users to set up two-factor authentication, create a PRO and change default RDP port from 3389 to another free port. However, you might also become a victim of Crypt32@mail.ru ransomware attack if you tend to explore strange-looking emails in your Inbox folder. Remember – the easiest way to “invite” a ransomware virus into your computer is to willingly open links or attachments that come with messages from unknown senders. Cyber frauds often pretend to be someone they’re not, so if you received a letter from someone who claims to be from Amazon or Paypal, do not rush to open the files attached to the message. It is highly advisable to check sender’s email address online and see if it is actually associated with the company one claims to work for. If you opened a suspicious attachment and it infected your PC with ransomware, follow instructions provided below.

How to remove Crypt32@mail.ru ransomware?

The first thing that malware analysts recommend doing is removing the ransomware from the system; however, we must point out that ransomware is no regular software and it won’t suggest using its uninstaller. You will have to identify, locate and remove Crypt32@mail.ru virus step by step because it tends to spread its files all over the computer system. The best way to clean your PC system after ransomware attack is to perform Crypt32@mail.ru removal using professional malware removal tools. Do not forget to reboot your PC using instructions provided below.

Did this guide help?

4 comments

  1. junior

    Crypt32@mail.ru ransomware attacked my PC this morning, so far I cannot find any ways to restore my files

  2. Sofya

    I lost all my files due to ransomware attack. I was attacked by this ransomware that is described in the article - I found Crypt32@mail.ru email address in corrupted data names. I hope someone finds a way to restore those files, because I REALLY need them!

  3. Kayla

    2-spyware team is very helpful! However, I could not restore my files, either. Maybe its a new variant of the virus or something. I feel so, so bad. I simple refuse to accept the idea that my files are corrupted for good..

  4. poppin

    Removed the virus, but still stuck with piles of encrypted data.

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.