Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2018

How to remove MC ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

MC ransomware is a virus that tries to make users play Minecraft

MC ransomware

MC virus is fake ransomware that was first spotted in April 2018 and is meant to encrypt all users’ files and make them unusable. However, in reality, it does not encode any data. Security experts discovered 11 different variants[1] of the virus, but they did not differ much from each other. Developers of the virus claim to be NATroutter.

 SUMMARY
 Name MC
 Type Ransomware
 First detected by MalwareHunterTeam
 Date detected April 2018
 Status Does not encrypt files
 Demands Playing Minecraft game
 Elimination Download and install FortectIntego or MalwarebytesMalwarebytes

It merely displays a pop-up window (it contains Minecraft screenshot and the text “Waiting for minecraft”) that waits for Minecraft game to be launched. The virus is meant to decrypt of files as soon as the demanded game time is complete.

We recently observed PUBG ransomware that encourages users to play PlayerUnknown’s Battlegrounds game. This virus also does not encrypt any files. Due to its controversial nature, PUBG ransomware got a lot of media attention. Therefore, there is no wonder that there are many copycats who want to do the same.

Regardless, ransomware is a severe infection which should be dealt with immediately. Thus, if you found a weird screen on your desktop asking you to play Minecraft, download and install reputable security software (FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes) which will help you to remove MC ransomware in just a few minutes.

MC virus is extremely poorly coded as it cannot determine whether the victim is actually playing the Minecraft game. It simply checks for the tasks ran in the Task Manager and, if it detects the “Minecraft” string, it executes a specific script.

It instantaneously launches another program called Minecraft123.exe which runs in the background and the “Waiting for minecraft” status changes to “Playing minecraft.” Thus, it is quite easy to trick these viruses by merely changing the name of an executable file to Minecraft.exe.

Nevertheless, it is never recommended to fulfill hackers’ demands. Other crypto-viruses, such as Locky or the infamous WannaCry, encrypt users’ files and make them unusable. To return all files, hackers demand a ransom to be paid in cryptocurrencies, such as Bitcoin or Monero.

Because these viruses encrypt a variety of files, including most popular formats like .doc, .pdf, .gif, .jpg, .mp3, .mpg, users are tempted to pay the ransom and get all the personal photos, videos and other important documents back.

As we already mentioned, it is never a good idea to interact with cybercrooks or fulfill their demands. Regardless if MC ransomware was created as a joke, it should be deleted straight away as newer and improved versions may appear at any time. For that purpose, we will provide file decryption steps that might help.

It is understandable that some users might not even understand what has happened. As virus does not encrypt files, they don’t have to. All they have to do is proceed with MC ransomware removal.

MC ransomware virus

Ransomware viruses can spread not only via spam emails

According to virusai.lt[2] the most prominent ransomware distribution method is spam emails. Hackers employ spambots that distribute malicious emails to thousands of people. If some are careless enough, they might easily get infected with the virus. Therefore, please restrain yourself from clicking on suspicious attachments in emails of unknown origin, especially if the file asks you to enable macro function.

Cybercrooks can also exploit vulnerabilities within the certain software, for example, Adobe Flash.[3] Thus, software developers continually patch their products to ensure its security. Therefore, it is essential to keep your system and software up to date at all times.

Also, avoiding file-sharing and torrent sites is a good idea. Repacked software or fake updates might contain a malicious payload of the ransomware virus.

Remove MC ransomware automatically

MC virus is poorly coded. However, it might be difficult to eliminate it manually. Therefore, we recommend automatic MC ransomware removal. For that, download and install anti-malware software.

In some cases, the virus might block security software from booting. Therefore, you should restart your PC in Safe Mode with Networking and perform a full system scan.

As mentioned above, the virus might be not yet fully developed. But newer variants might contain a code that can actually encrypt files. In that case, check our file recovery procedure below. Remember, you have to remove MC ransomware before proceeding.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.