NMCRYPT crypto-virus is the ransomware that demands to pay almost $7000 ransom in Bitcoins for the alleged file recovery tool

NMCRYPT is a dangerous crypto-ransomware virus[1] that is currently being distributed via unprotected Remote Desktop Services, malicious email attachments, and rogue software updates. Its developers exploit AES-256 and RSA-2048 encryption algorithms to take victim's files hostage. The ransomware is known for targeting video, audio, photos, text, database, spreadsheets, and presentations in particular. Encrypted files get the particular suffix, which is why the virus is also dubbed as .NMCRYPT file extension virus. Upon successful unraveling, the victim is presented with a Recover your files.html ransom note, which demands to pay $6,705.02 ransom in Bitcoins asap.
| NMCRYPT file virus | |
|---|---|
| Classification | Ransomware |
| Danger level | High. Locks personal files and corrupts system's settings. Free decryptor is not available. |
| Symptoms | Personal files inaccessible. File extensions changed to .NMCRYPT. Each folder contains Recover your files.html file |
| Size of redemption | $6705.02 in Bitcoins |
| Encryption applied | AES-256 and RSA-2048 |
| Elimination | The threat can be terminated with the help of anti-malware tools |
| Automatic virus damage removal available. Download FortectIntego and run a full system scan to find and fix any altered or corrupted files | |
NMCRYPT is the second ransomware virus after Vurten demanding a huge ransom in exchange for a decryptor. Typically, the size of the redemption ranges from $200 to $500, does not exceed $2000.[2] Thus, it seems that we're currently dealing with a real gold-digger.
The ransomware virus has been spotted in the wild in the middle of April 2018. Recognized as a Generic.Ransom.XRatLocker.5E892A47, Ransom.Haknata.S1240226, Ransom_AIRACROP.SM, Trojan.Win32.Deshacop.enxprt, and similar detections by reputable anti-virus engines, seems to be targeting English-speaking in particular.
Ransomware researchers have currently analyzed the infection and disagree upon its origin. While some of them claim it to be derived from NMoreira ransomware, the others assert that it's yet another crypto-malware based on HiddenTear open-source ransomware. Anyway, it's a fact that the NMCRYPT virus encrypts files that can not currently be decrypted without paying the ransom.
Once installed, it opens Command Prompt under administrative privileges and runs a script to delete Volume Shadow Copies, which are created by Windows by default. Besides, it disables all previous Windows versions that have been created using the Windows Recovery option. This way, hackers minimize the possibility to unlock files encrypted by ransomware and maximize revenue.
Personal files are locked using AES-256 and RSA-2048 ciphers, which allow hackers to ensure strong-coded encryption. The combination of double-layered encryption makes it practically impossible to crack the code manually. Therefore, hackers ask for $6705.02 redemption to be transferred in Bitcoins using the Tor browser and a Bitcoin wallet to get the unique identification numbers necessary for the decryption.
To prove credibility, cybercriminals ask the victim to select a couple of DOCS, XLS, XML or JPG files that do not exceed 2MB in size and send them to them via http://wikisend.com/ channel.
The victim can find the initial information on the Recover your files.html file, which appears by default on each folder and desktop. It contains the instructions on how to download Tor browser and several links redirecting to a Bitcoin purchase website. The text of the note says:
Encrypted files!
All your files are encrypted.Using AES256-bit encryption and RSA-2048-bit encryption.
Making it impossible to recover files without the correct private key.
If you are interested in getting is the key and recover your files
You should proceed with the following steps.
The only way to decrypt your files safely is to buy the Descrypt and Private Key software.
Any attempts to restore your files with the third-party software will be fatal for your files!
Important use Firefox or Chrome browser
To proceed with the purchase you must access one of the link below
https://lylh3uqyzay3lhrd.onion.to/
https://lylh3uqyzay3lhrd.onion.link/
If neither of the links is online for a long period of time, there is another way to open it, you should install the Tor Browser
If your personal page is not available for a long period there is another way to open your personal page – installation and use of Tor Browser, etc.
If your PC has been attacked by this virus, do not fall for paying the ransom note because it's excessive, but also there's no guarantee that hackers won't leave you without a key. The best way to deal with ransomware is to eliminate them and then try to recover data using third-party recovery tools. Therefore, we would strongly encourage you to remove NMCRYPT ransomware using SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes.
Don't worry if the automatic removal is blocked by some ransomware components. To bypass the interrupter, you should restart the system to the safe environment and then launch the anti-virus. You can find a guide down below this post.

Hackers use multiple distribution channels to spread ransomware
Ransomware virus is a number one cyber threat of 2018. It does not reside in this position for almost a decade and does not seem to shrink in the near future. The increasing number of attacks can be explained by a variety of intricate distribution strategies that hackers exploit. These are the main ransomware distribution channels distinguished by semvirus.pt[3] currently in use:
- Spam email attachments. DOC, DOCX, PDF, PNG, JPG formats. They usually mimic well-known companies or authorities like IRS, Amazon, eBay, etc., and talk over relevant subjects, such as obligations, debts or parcels.
- Exploit kits. Hackers use specific software packs to attack system vulnerabilities. Exploited vulnerability then serves as a gateway to inject ransomware. Exploits might travel along with software updates like Adobe or Flash.
- Unprotected Remote Desktop services. Crooks often manage to reveal RDP passwords open to the Internet and, therefore, can easily enter the system using sysadmin privileges.
- Fake software updates. Crooks might create a phony browser, Windows, Java, Flash Player, or even browser's font updates, and display them on hacked websites. If an unsuspecting netizen clicks on the Download button, he or she executes a ransomware payload.
Although there are many other ways that ransomware developers might exploit, the four mentioned above are most frequently used. Thus, be careful when browsing the Internet and make sure to keep a reputable anti-virus enabled.
A guide on how to remove NMCRYPT ransomware virus
Do not try to remove the virus manually because it's not possible. The malware runs multiple commands and scripts to alter the core system's settings and root deeply to evade elimination. Besides, it installs a package of related files and keeps running malicious processes.
The only way to execute NMCRYPT removal is to download a professional anti-malware or update the one that is already running on the system. Then launch it let the scanner do its job. In case the virus uses helper objects to block a security tool, follow the guide given below.
Did this guide help?
Be the first to comment