Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jul 2020

How to remove Try2Cry ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

Try2Cry – dangerous open-source ransomware with the USB worm traits

try2cry ransomware

Try2Cry ransomware is a dangerous ransomware-type malware that uses the Rijndael symmetric key encryption algorithm[1] by calculating SHA512 hash for locking personal files on the host machine. Discovered by Karsten Hahn from the G DATA[2] team of cybersecurity experts, the ransomware has been attributed to the Stupid ransomware family. 

The Try2Cry virus is an open-source malware, meaning that its code is accessible for hackers online and, most probably, less experienced criminals can customize it and use it for their needs in exchange for a commission fee. The virus is not capable of infecting all file types on the machine, though it is capable of locking the most popular data, such as pictures, PDF documents, Excel sheets, and other documents. Each of the locked entries gets the .try2cry file marker. 

The main distinguishing feature of the Try2Cry ransomware virus is the way it spreads. In fact, it can be attributed to the USB worm[3] category as well, since it's secondary task is to inject the malicious Update.exe file into all USB devices connected to the host machine. This file is a ransomware copy, so as soon as the infected USB flash drive is connected to another device, the payload gets activated. 

Name Try2Cry
Classification Ransomware
Geneology Stupid ransomware
Encryption model Rijndael algorithm
SHA512 hash
File extension .try2cry file extension
Files targeted .doc, .ppt, .jpg, .xls, .pdf, .docx, .pptx, .xls, and .xlsx files
Contacts Try2Cry@Indea.info
Other traits It's open-source ransomware. Its source code is accessible for hackers on various background forums. 
Distribution  This cryptovirus is being disseminated by various means, i.e. spam email attachments, cracks, keygens, fake software updates, etc. However, people can also get infected via USB Flash Drives as this virus can copy its Update.exe file to the external drive connected to the host machine
Decryption The ransomware is decryptable. Users can use the Stupid decrypter for unlocking .try2cry files
 Removal Before launching the decryption software, it's a must to remove the ransomware from the system using a professional anti-virus program. In addition to that, it's advisable to scan all USB flash drives for infection if they have been connected to the infected machine
Fix ransomware damage This particular virus can alter Temp folder and initiate various alterations within the Registry. To fix suchlike damage, run a scan with FortectIntego upon virus elimination

Try2Cry virus has been found by a researcher from the G DATA team when the detection signature software designed for the detection of active USB worm components has been triggered by a malicious Update.exe file. After the sample analysis, the ransomware has been approved. It's genealogy straining from the open-source ransomware family known as Stupid. According to its behavioral traits, the virus is similar to Spora, Thanos ransomware, and Andromeda trojan.

This misleading ransomware has been found spreading via infected USB Flash Drives and misusing LNK shortcuts to alter data stored on the infected drive. The files marked by LNK shortcuts serve as a ransomware payload, so once clicked, they open the original file and download the virus onto the machine. Consequently, Update.exe file runs the cipher and locks the .doc, .ppt, .jpg, .xls, .pdf, .docx, .pptx, .xls, and .xlsx files.

According to the researcher, the virus uses the Rijndael symmetric key encryption algorithm and SHA512 hash of the password to lock the data. Upon the encryption, the victim sees the data with the .try2cry file appendix. Besides, the victim may notice the \explorer.exe file, which once launched opens a ransom note saying: 

You Are Fully Encrypted,
Don't Try to Change Name Or Format PC>> All Data Will Lose
Call Me Try2Cry@Indea.info
Your Pass Key Is: 

The note does not specify criminals' expectations about the size of the ransom or the time span the victim should react. The Try2Cry file virus note only contains the email address Try2Cry@Indea.info and the unique key, which consists of lower and upper case letters, numbers, and symbols. 

Windows machines that are already infected with any type of cyber infection are not likely to be infected by Try2Cry ransomware. The ransomware code has been designed to skip infected machines with the DESKTOP-PQ6NSM4 or IK-PC2 machine names. The researchers suppose that such behavior is based on the criminals' will to test the ransomware with being interfered.

Try2cry virus

Anyway, if your machine got infected by this malicious virus, you should immediately scan the system with a professional anti-virus program to remove Try2Cry virus. There are plenty of reasons why you should do that. First of all, the longer the virus remains on the system, the more malicious system changes it can cause. Second of all, the Update.exe file copy can be disseminated to many USB devices, thus allowing the virus to reach other machines easily.

Last, but not least, before you decrypt try2cry files, it's a must to perform a full Try2Cry removal. Otherwise, the virus may re-encrypt unlocked files or wipe them out completely. In order to perform a full virus elimination, you should restart the system into Safe Mode with Networking and launch the security software. 

Right after the Try2Cry virus removal, run a scan with FortectIntego repair tool to recover the Windows machine. This application can help to restore deleted or altered registry keys, enable crucial processes that might have been disabled, and recover the Temp folder in a state it was before the ransomware attack. 

Do not open suspicious files on the USB flash drives

The most interesting feature of this particular ransomware strain is its ability to infect USB drives connected to the infected machine. The malicious copy of the Update.exe is automatically transferred to the external drive, which shows up in the form of a new folder. In addition, the virus creates several folders that are named using Arabic names. 

These folders are infected by malicious ransomware files. Therefore, if the user gets caught by the curiosity and others the Arabic-named files, the ransom file is opened and the ransomware payload is launched. However, NoVirus.uk[4] experts warn that the virus can also be disseminated by other means, including but not limited to spam email attachments, software cracks, and fake updates. 

Try2cry infects USB flash drives

Therefore, a piece of advice would be to stop using torrenting sites for getting pirated software. Besides, we would strongly recommend staying away from cracks and keygens because instead of saving the money for some license key you may get infected with ransomware or another virus. Such experience may leave your pockets empty or cause complete loss of personal files. 

Advanced guide on Try2Cry ransomware removal

When it comes to ransomware, it's a must to act fast once you find at least a single file locked. There's no reason to postpone the elimination process as delayed removal can lead to a higher number of encrypted files, more system modifications, and infiltration of other cyber infections. 

Try2Cry removal is a process that can be handled by a professional anti-virus program only. There's no way to eliminate the malicious bundle of ransomware files manually. Thus, we recommend using SpyHunterCombo Cleaner or MalwarebytesMalwarebytes tools for cleaning your machine. Note that some of the malicious files may be blocking security tools, so you may need to restart the system into Safe Mode with Networking. 

Once you remove Try2Cry ransomware, we strongly recommend you to scan the USB flash drive with security software or format it to prevent a relapsed attack. Besides, it's advisable to ensure a full Windows optimization, which can be done by running a scan with FortectIntego utility.

Try2cry runs malicious files

After a full Try2Cry removal, try to decrypt your files using the Stupid decryption software or alternative data recovery methods that we have listed below.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.