Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2021

How to remove AngryKite ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

AngryKite ransomware alters the system and shows a scary message to victims

AngryKite virus seems to be yet another unoriginal ransomware[1], this time based on KRider ransomware virus. The main executable of this virus is angryKite_v3.exe.bin. Once in the computer system, the ransomware encrypts files found on the system (excluding some system files in order to keep the computer running). During the data encoding process, virus replaces the original filename with a random set of characters also adds .NumberDot extension at the end of it. As a result, the victim is left out with a bunch of encrypted files[2] that cannot be opened or manipulated in any way, besides, there is no way to understand which file is which, since the virus entirely corrupts their filenames.

Name AngryKite ransomware
Type Cryptovirus
Extension .NumberDot
Purpose Trick people into calling the number that reroutes to criminals asking for money
Distribution Malware spreads using malicious emails and attachments or direct dangerous sites
Elimination Remove the virus with the help of the guide below or an anti-malware application
Repair Make sure to repair damage with a proper tool like FortectIntego

What is interesting about the virus is that it is a tech-support-scam[3] type of virus. We have noticed that tech support scammers have employed ransomware-type viruses to attack victims and force them to communicate with scammers directly[4]. Actors behind AngryKite ransomware project might expect victims to buy some useless malware removal programs or pay for services “required to fix the computer.”

It is very likely to happen because the virus is programmed to launch a “Warning” window on the computer screen right after encrypting data stored on the computer. The suspicious warning says that “System may have found anonymous encryption on your computer. You would not be able to access the files on your computer.”

The warning also states that “Your system has encryption ransomware which may permanently encrypt your data.” Seeing such a message on the screen can make anyone freak out, however, there’s also some hope to improve the situation – the message suggests calling a provided number “to avoid further damage.” The number associated with this ransomware is 1-855-545-6800.

AngryKite ransomware virus

Our researcher called this number and was greeted with an auto-message “Your call is very important to us. Please stay on the line, and you will be transferred to the next available agent.” Surprisingly, the line was very busy, and we weren’t able to get more information on what scammers say to the victims.

However, if your computer was infected with ransomware, you should remove AngryKite virus right away. Do not listen to scammers who are trying to swindle money from you after illegally installing malware on your computer. For the removal, we strongly suggest using software like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. Before you start, reboot your PC according to the instructions provided below in the article.

Malware spreading ways

There are many ways how criminals distribute ransomware viruses, for example, they prepare a malicious code and inject it into a Word or JavaScript file[5], and then deliver this file to thousands of targets via email. In other words, scammers use the malspam technique. However, there are more ways to get infected with ransomware.

Some criminals employ more sophisticated ransomware distribution techniques that rely on exploit kits, malware-laden ads, and the like. In order to protect yourself from such attacks, one needs to set up a good anti-malware software system on the computer, update all programs to their latest versions (continuously!), and stay away from hazardous Internet websites while browsing the world wide web.

Get rid of this ransomware virus

Researchers say that this ransomware virus might be decryptable, so do not lose your hopes yet. If these expectations appear to be true, victims will successfully decrypt their files for free. That is very rare to have criminals release the decryptor even after payment. 

However, we need to have some patience and wait for more information from malware researchers. Until then, we strongly advise you to remove the virus. You can successfully get rid of the virus with the help of AngryKite removal instructions provided down below. Also, told like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes can help you do that.

4 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.