Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2017

How to remove AnonCrack ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

AnonCrack ransomware targets Spanish users

The image of AnonCrack ransom note

AnonCrack virus is the name of a new file-encrypting virus which is oriented at Spanish[1] users as the ransom note is written in the respective language. It is another ransomware created on the basis of HiddenTear.

Luckily, multiple security tools already detect the malware as Gen:Heur.Ransom.HiddenTears.1, MSIL.Trojan-Ransom.Cryptear.A, and Ransom_RAMSIL.SM[2]. After it infects the system and encodes files, it appends .crack file extension. In case, victims run into technical difficulties, they can contact the perpetrators via anoncrack@protonmail.com.

It is still unknown whether anyone contacted the perpetrators. Another distinctive feature of this malware – it disguises under fake Paypal money sender app. Specifically, the ransomware hides under Paypal Money Sender V2.0.exe.

Interestingly, the malware targets older computers running 32-bit Intel 386 processors. Furthermore, the malware hides under counterfeited PayPal sender app and it demands quite a small ransom. However, the initial motive behind targeting older processors remains unknown. In any case, it is not recommended to pay the ransom but perform AnonCrack removal. FortectIntego or MalwarebytesMalwarebytes might speed up the process.

More “international” threats

Besides mentioned features, it also drops the mscoree.dll executable file. As common for ransomware, AnonCrack ransomware developers urge victims to remit the payment within 7 days. Otherwise, the amount raises from $30 up to $100.

Interestingly, Spanish hackers recently have made a move. More Spanish-oriented ransomware have appeared in the cyber space. Another sample is Bugware which is said to have originated from Brazil. Besides wasting time and money, you can check whether these free HiddenTear decrypters can be of use. Before you use them, remove AnonCrack virus completely.The picture illustrating AnonCrack ransom notes and its alternative names

Transmission tendencies

Bear in mind that this kind of malware pretends to be PayPal app. Perhaps the perpetrators picked up the idea from recent CCleaner v5.33 incident[3]. Note that there is no app which is called PayPal Money Sender. You can send the money from the official account or via PayPal app downloaded from Apple or Google Play store.

This malicious impersonator is likely to have been distributed in forums or insecure websites. Do not forget that a significant number of ransomware threats are still distributed via spam emails (beware of the new Locky version – Asasin). In order to escape AnonCrack hijack or the encounter with another ransomware, improve the overall security of your system and pay attention to the downloaded content and received email attachments.

Eliminate AnonCrack from the operating system

Before you proceed to data recovery, remove AnonCrack virus with the assistance with the elimination tool. In case you cannot launch it, check below guide. It explains how you can reboot the system in Safe Mode.

After you complete AnonCrack removal procedure, download free HiddenTear decrypters. Though they were created for the original version of the malware, there is still a higher probability to restore data rather than rely on hackers’ conscience.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.