AVCrypt – ransomware that tries to uninstall security program on the affected Windows PC

AVCrypt is a malicious program that is designed to uninstall antivirus and security software on the targeted computer. Currently, it’s unknown if the virus is in-development ransomware or a wiper. However, the virus drops an empty +HOW_TO_UNLOCK.txt file which is supposed to be ransom note.
| Summary | |
| Name | AVCrypt |
| Type | Ransomware |
| Danger level | High. Makes system changes, deletes files and antivirus software |
| Symptoms | Encrypted files, deleted antivirus |
| Distribution methods | Malicious spam emails, bogus software downloads and updates, exploit kits, etc. |
| To uninstall AVCrypt install FortectIntego and run a full system scan. | |
However, the significant feature of the AVCrypt virus is the ability to remove security programs soon after the infiltration. The malicious program specifically targets Windows Defender and Malwarebytes and deletes Windows services in order to stop their proper operation.
Furthermore, AVCrypt queries to check what antivirus program is registered with Windows Security Center.[1] Then it uses WMIC[2] in order to delete it. However, the recent analysis tells that malware is not able to eliminate all security programs, meaning that some tool can be immune and used for virus elimination.
AVCrypt malware has features of both ransomware and a wiper. Therefore, it has features of both. It might delete specific Windows service to cause problems with proper work of the operating system. However, apart from that, this cyber threat is designed to encrypt files and drops a ransom note soon after that.
AVCrypt ransomware does not start encryption immediately after infiltration. It remains still for a while and then connects to Command and Control server via TOR. The server responds with:
- encryption key;
- timezone;
- a version of the targeted Windows system.
However, during this procedure, some errors occur, and this allows assuming that malware is still under construction. Before running system scan for data encryption, malware deletes antivirus programs. During the encryption, malware renames files using this path:
+[original_name]
Following the encryption AVCrypt ransomware creates a previously mentioned +HOW_TO_UNLOCK.txt file in each folder that contains the encrypted files. Undoubtedly, this file is supposed to be ransom note. However, it includes “lol n” message, and nothing else: no data recovery instructions, no Bitcoin demands, no contact email address. Though, it is expected that malware is still in-dev mode and might be updated to full ransomware anytime soon.
Currently, Microsoft detects this cyber threat as Ransom:Win32/Pactelung.A, so it can be deleted with a professional security software. We highly recommend urging AVCrypt removal because it already has destructive features and makes the system vulnerable. Though, it can be updated any minute.
The virus modifies and adds new Windows Registry values, deletes its files, event logs, ransomware processes and wipes out autorun entry. To clean the computer and fix the damage, we recommend you to remove AVCrypt with FortectIntego.

Possible ways to get infected with malware
The specific methods how this destructive malware spreads are unknown. Cybercriminals might be using one of the following popular strategies:
- malicious spam email attachments;
- malvertising;
- bogus software updates or downloads;
- exploit kits.
Therefore, paying attention to general security tips is needed to avoid cyber attacks. Additionally, specialists from NoVirus.uk[3] remind to install a reputable antivirus program and keep it update as well as other programs and operating system. Additionally, we urge to make data backups and update them regularly as well. After ransomware attack, they save you from the loss of important information.
Uninstall AVCrypt ransomware virus
For AVCrypt removal, you have to use professional security software. Indeed, the virus can delete a security software that is installed on your PC. Though, you may need to install a new tool. However, you should reboot the computer to Safe Mode with Networking first to disable the virus as shown below.
If you are not sure what program to choose for elimination, you can use FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. We can ensure that these tools can remove AVCrypt entirely. Moreover, if you do not have data backups and need file recovery solutions, try the methods suggested below.
Did this guide help?
Be the first to comment