Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Apr 2019

How to remove PacMan virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

PacMan – ransomware which targets English and German-speaking users

PacMan ransomware

PacMan virus (can also be found as PacMan ransomware) is a very malicious cyber threat, which can lead people to serious PC-related issues. This cyber threat can easily block their important files and then start asking via message to pay a ransom in exchange for unblocking them. Of course, you shouldn't even imagine about a ransom of $20. This cyber threat asks to pay $1500, which is 0,2 in Bitcoin. In addition, for further identification of PacMan ransomware, you will spot all locked files with the .encrypted extension added to the file name. If you think that your computer has already been affected by this notorious ransomware, you go straight to it. Otherwise, this ransomware[1] may try to infect your machine with additional malware and may also steal your personally identifiable information from your computer.

Name PacMan
Malware type Ransomware
Extension .encrypted
Ransom price 0,2 BTC
Target English and German speakers
Distribution Via phishing emails mostly
Detection FortectIntego can identify malicious content
Removal process Make sure you get rid of ransomware ASAP

Once PacMan ransomware infiltrates the system, it uses AES encryption for encrypting these files: 3fr, accdb, ai, arw, bay, cdr, cer, cr2, crt, crw, dbf, dcr, der, dng, doc, docm, docx, dwg, dxf, dxg, eps, erf, indd, jpe, jpg, kdc, mdb, mdf, mef, mrw, nef, nrw, odb, odm, odp, ods, odt, orf, p12, p7b, p7c, pdd, pef, pem, pfx, ppt, pptm, pptx, psd, pst, ptx, r3d, raf, raw, rtf, rw2, rwl, srf, srw, wb2, wpd, wps, xlk, xls, xlsb, xlsm, xlsx.

If your files have been locked by this dangerous file locker, note that you will be urged to pay to the crooks in order to receive a decryption tool. However, people who spread PacMan ransomware cannot be trusted as they are already committing a crime by secretly installing on victims' computers, locking files, and demanding ransom for such activity.

If you are a victim of PacMan ransomware, read the following text and analyze the ransom note:

Sorry, your files have been 
paid in. Bitcoin is required. After your payment has been made. 
Amount USD [1500] 
Amount BTC [0.2] 
Bitcoin Address [ 17yKCVNb7EQQpr5ABKGcVpGSPVWFTxhReR ] 
[Check for payment] 
Help 
How to buy Bitcoin? (click)  
Further Assistance? Write to pacman.support@protonmail.com 

We recommend declining any offers to purchase decryption tools and transfer money to the given Bitcoin wallet address. Instead of completing what the criminals say, remove PacMan virus from your Windows computer system. Use anti-malware software such as FortectIntego to detect all malware-laden content on the machine.

PacMan removal is a necessary process to perform if you want to avoid further possible damaging consequences and restore your files back to their previous states. Make sure that you boot your computer to Safe Mode with Networking and just then try our below-provided data recovery techniques.

You need to know that file locking threats are dangerous not only because you might face losses of valuable data but PacMan ransomware might also be capable of injecting other malware, modifying your Windows Registry and Task Manager[2] sections, placing rogue executables all over the system, and so on.

PacMan virus

Ransomware infects systems via phishing messages most of the time

According to tech experts from Virusai.lt,[3] ransomware is mostly spread via phishing emails. Some of them are designed to report about missing payments, others ask to confirm purchasing details and so on. To sum up, these emails are trying to fool users into downloading their infected attachments. Fortunately, most of such emails are filled with grammar or typo mistakes.

Also, they include suspicious sender and so on, so you should try to inspect every element of an email if you do not know the sender. If you ever receive questionable-looking messages, ensure that you eliminate them immediately or carefully identify their content before opening. However, note that reputable organizations will not bother you by sending informative messages by email, they are most likely to call you directly.

Remove PacMan virus from your Windows operating system and all its executables

Unfortunately, if this ransomware infects your system, it leaves you without an ability to decrypt your encrypted files. For that you need to pay a ransom and get a decryption code. However, we suggest refusing this suggestion and performing the PacMan ransomware removal from your Windows computer. Nevertheless, you can also try a backup or using file recovery tools. If you have been performing backups, you should be capable of restoring your files.

One more thing before you remove PacMan virus, you should use reputable anti-malware tools to detect all malicious content that might be hidden all over your computer system. Use programs such as FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes to achieve such goal. Additionally, take care of your files' backups in the future. Store copies of all important data on remote servers or devices, and keep them in touch only with the owner, i.e. yourself.

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.