Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2017

How to remove AutoEncryptor ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Auto Encryptor comes as the improved version of FileLocker ransomware

AutoEncryptor virus is a sequel to the improved version of FileLocker. Comparing it with its predecessor[1], it has not changed the design of GUI (graphical user interface), but it raised the amount of the ransom which is now 10 000 BTC approximately (12 410 663 USD). Besides this astounding amount of ransom, the malware also uses the image of Andrej Babiš, a Czeck politician, businessman, and the former Minister of Finances of the Czech Republic. Likewise, it presents the email address – babis@mfcr.cz – for public use. This malware also links to previous known several variations of Czech ransomware[2]. Needless to say, that few users could afford to pay such amount of ransom. Thus, it would be wiser to initiate AutoEncryptor removal. One of the solutions to do that is to install FortectIntego or MalwarebytesMalwarebytes.

The example of AutoEncryptor virus

While there are tons of malware which only focus on extorting money, some of the infections even convey a certain message or public discontent. The feature of this malware to refer to a politician reminds of Japanese counterpart Takahiro Locker which on its behalf made an allusion to a Japanese finance minister. The developers of AutoEncryptor ransomware did not bother themselves with devising a new design for the virus. It seems that FileCryptor failed to make a huge profit, as the crooks now demand the astonishing amount of money. Hardly anyone would agree to remit the payment. On the other hand, it suggests that the malware may be oriented at business companies[3]. AutoEncryptor malware is likely to attach .encr file extension to the affected data. The interface of the malware contains three-step payment site. It refers to a website instructing how to obtain bitcoins. Then, the following web page presents the email address and the box where the encrypted key. should be inserted. If the cyber villains obtain the required amount of ransom, they should send the decrypting password which you should enter on the third page of the program. Let us remind you that hackers rarely play fairly and transfer the decrypter. It would be more rational to remove Auto Encryptor right away.

The image illustrating AutoEncryptor virus

The distribution channels of the malware

Like its predecessor, AutoEncryptor hijack occurs when users recklessly open up corrupted emails. In order to lure users into their deception, the hackers often exert psychological terror. For example, they may counterfeit the alerts of the FBI and, likewise, force users into opening the infected attachment which contains AutoEncryptor.exe file. Tax-related topics continue to dominate among hackers. In addition, it is of crucial importance to update the system software. System vulnerabilities may serve as the backdoors for malware to sneak in and then inflict damage. For that purpose, an anti-spyware program may assist you eradicating the malware. In the cooperation with an anti-virus tool, it may lower the chances of encountering an exploit kit[4] as well. Usually, it dwells in a compromised website. Note that it comes in the form of a trojan as well:  Trojan.Ransom.FileCryptor, Trojan.Generic.D4911AF, and  Trojan.GenericKD.4788655. Naturally, you should avoid visiting gambling and torrent sharing domains, as often, they happen to be the havens of malware[5].

Steps you should take to terminate AutoEncryptor malware

Before you proceed to data recovery steps, it is crucial to fully remove AutoEncryptor virus. In order to do that malware elimination utility will benefit you. If you cannot run it, take a look at data recovery instructions. Only when AutoEncryptor removal is finished, file recovery will be of use. Otherwise, the remaining files might re-encrypt the files again. In addition, you might interfere with the virus processes by terminating the tasks in the Task Manager.

3 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.