Severity scale:  
  (99/100)

EnkripsiPC ransomware virus. How to remove? (Uninstall guide)

removal by Julie Splinters - - | Type: Ransomware
12

Crucial facts about EnkripsiPC ransomware

EnkripsiPC virus is a new file-encrypting malware which mainly targets Indonesian users since the ransom message is published in the respective language. It clearly follows the manner of CryptoLocker since the ransom note has a striking resemblance to the mentioned virus. Though the former ransomware is said to have ended its notorious activity [1], its termination has inspired countless hacker wannabees to maintain the activity of file-encrypting malware. Interestingly, that this time the virus originates from Indonesia. The source contains the information that the virus encodes all files named in the Indonesian language. Nonetheless, it does not mean that users living in other regions are safe from this virtual menace. After the malware gets into a computer, it marks all files with .fucked file extensions. If you notice that all your files are blocked and contain the previous extension, do not panic but instead concentrate on EnkripsiPC removal. For that purpose, it would be better to rely on Reimage. This application will effectively remove EnkripsiPC and all its components.

CryptoWall, CryptoLocker, and Locky gave rise for the boom of ransomware which encrypt the files using AES algorithm. The effectiveness of such virtual threats lies in several factors. Firstly, the hackers communicate via the network granting anonymity or single-use email addresses. Secondly, AES encryption is easy to use but provide elaborate and difficult decryption keys which cannot be guessed. What is more, vivid and huge informational resources covering this particular topic enlightened many interested users on how to simply encode the files [2].

Likewise, ransomware business is booming. Though the market is controlled by several cyber gangs which regularly publish a new version of Locky (the latest – Osiris ransomware) and Cerber, the idea of profiting from ransomware appeals to the bright minds of different nationals. While US, UK, Germany, France, Japan and South Koreans and other nationals from wealthy states are a prevalent target, the crook started to take a glance to other countries of [3]. In this regard, this virus, alternatively known as Indonesian ransomware, v3 virus, or IDRANSOMv3 malware, also exclusively prefers targeting Indonesia netizens. For now.

EnkripsiPC virus targets Indonesian users

Furthermore, the hacker introduces themselves as humanpuff69. However, it is not known whether the ransomware will evolve into a major threat or it will flash like a temporary manifestation of a protest against something or someone. In comparison with the previous threat, it does not set a time limit. What is more, it demands a ridiculously low ransom – 50 000 or 100 000 Indonesian rupiahs which stand for approximately 4 USD and 7 dollars respectively. Even if the amount seems to be very low, do not expect to get your files back [3]. What is more, EnkripsiPC ransomware developers provide three email addresses in case you decide to contact them: fulldoang@gmail.com, mgfakhri@gmail.com, and muhlubaid69@gmail.com. Believe it or not, but the gearheads even provide their Facebook profile – muhammad.f.nazeeh. All in all, this ransomware does not compete with other notorious ransomware, but certain features suggest that with enough attention and development, EnkripsiPC malware might even evolve into a serious threat.

Distributing the malware

Though spam emails remain to be the main channel for spreading this sort of malware [4], this virtual infection seems to employ less popular methods of infiltration. Specifically, EnkripsiPC hijack might occur if you are not careful and install questionable tools. Virus researchers have detected that it might sneak into the device via corrupted installers, such as Installer Install Program. Afterward, Enkripsi PC malware leaves AutoUBLhack0.97.exe and CheatPBG161218.exe binaries. Then it becomes only a matter of time when the virus entangles your system.

EnkripsiPC eradication procedure

Due to the multiple new file-encrypting threats, the ransomware market has become one of the most profitable ones [5]. Fortunately, not all threats are complex. In this regard, EnkripsiPC removal should not cause any inconveniences if you entrust the procedure to Reimage or Malwarebytes Anti Malware. Update the program before the scanning the device. After that, restart the device and repeat the procedure. Keep in mind that the program does not decrypt the files. For that, you might use backups or additional tools. Check out our recommendations below. Remove EnkripsiPC virus fully and proceed to data recovery procedure.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided Anti-spyware software to remove EnkripsiPC ransomware virus you agree to our privacy policy and agreement of use.
do it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall EnkripsiPC ransomware virus. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.
More information about this program can be found in Reimage review.
Press mentions on Reimage

Manual EnkripsiPC virus Removal Guide:

Remove EnkripsiPC using Safe Mode with Networking

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove EnkripsiPC

    Log in to your infected account and start the browser. Download Reimage or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete EnkripsiPC removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove EnkripsiPC using System Restore

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of EnkripsiPC. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage and make sure that EnkripsiPC removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove EnkripsiPC from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If your files are encrypted by EnkripsiPC, you can use several methods to restore them:

Data Recovery Pro solution

If your files are inaccessible, try using this tool to recover them.

Opting for Windows Previous Versions function

If System Restore is enabled, retrieve the previously saved copies of your documents.

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

The usefulness of ShadowExplorer

The main advantage of this utility lies in recreating the files by employing shadow volume copies. They are automatically generated by Windows OS and rarely ransomware threats delete them.

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from EnkripsiPC and other ransomwares, use a reputable anti-spyware, such as Reimage, Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus or Malwarebytes Anti Malware

About the author

Julie Splinters - Malware removal specialist

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Julie Splinters
About the company Esolutions

References


  • paribus2544

    A new ransomware in town..

  • classroom1888

    Why does everyone so much sympathize to CryptoLocker?

  • CNday

    Hurry up with the decrypter!