Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2017

How to remove Patcher ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

Patcher virus attacks Mac users and leaves them without data recovery option

Patcher ransomware virus is newly discovered crypto-malware[1] that attacks Mac OS X users only. Mac users rarely have an opportunity to encounter viruses; however, earlier KillDisk and KeRanger viruses tried to cause damage to Apple machines’ users. This new file-encrypting virus is written in Swift language which is suitable for macOS, iOS, watchOS, and tvOS[2]; however, it’s poorly coded. Patcher virus spreads via Torrent sites and gets inside the machine as the ZIP file[3]. The archive might contain two bogus programs Adobe Premiere Pro and Microsoft for Mac, also known as Patchers. The trick that developers promise that after installing these programs, users do not need to pay for the license. Therefore, you should know that these kind of offers are not legitimate and potentially dangerous. Furthermore, once a user downloads this bogus software package and launches installation process, the Patcher shows a transparent window which is supposed to be a warning sign that something is not right with the installation. The window has a Start button to crack software, and when users click it, he or she launches the ransomware. Patcher malware encrypts files in “Documents” and “Photos” directories; however, some other folders might be targeted as well. Before starting data encryption, ransomware generates a random 25-character string necessary for the encoding files. When data encryption is over, the virus tries to null the free space on the root partition by trying to execute /usr/bin/diskutil. However, this process fails. However, malware deletes original files and changes the time of the encrypted files to the 13 of January 2010.

Following data encryption, Patcher virus delivers a ransom note called README!.txt file. Cyber criminals demand victims to pay 0.25 Bitcoins within seven days. Once they receive the payment, they decrypt the files within 24 hours; however, if people want to get back their files faster, they should pay the ransom of 0.45 Bitcoins. However, after the attack, it’s better to concentrate on Patcher removal instead of giving your money to cyber criminals. No matter how much Bitcoins you are willing to transfer, there’s no way that hackers would decrypt your files[4]. This poorly written virus does not communicate with the Command & Control server, which is supposed to generate a specific decryption key that would restore encrypted files. The analysis of the virus revealed quite strange aspects of the ransom paying procedure. Different victims are supposed to find the same Bitcoin wallet address where they should transfer the ransom. Usually, ransomware provides unique Bitcoin wallets to each victim. Moreover, the hackers use the free email address (rihofoj@mailinator.com) from Mailinator inbox which does not require registration or authorisation. This public email allows seeing all received messages for everyone; however, at the moment of writing their inbox is empty. After ransomware attack, you should not hesitate and remove Patcher from the Mac using strong security tools such as FortectIntego or SpyHunterCombo Cleaner.

The image of Patcher ransomware virus 

How can I protect my Mac from the ransomware?

Cyber criminals rarely launch attacks and try to hijack Mac OS X. However, it seems that the popularity and success of file-encrypting viruses inspire hackers to broaden the target field. As we mentioned before, Patcher ransomware spreads as a bogus Adobe Premiere Pro and Microsoft Office 2016 Patcher programs via Torrent. Therefore, if you want to protect your machine from the ransomware, you should avoid using Torrents and installing illegal software. There’s a possibility that virus spreads via more fake programs; hence, you should choose only safe sources for software downloads. Torrents and other file-sharing services are not safe and reliable. What is more, we highly recommend making data backups[5] and updating them regularly.

How to remove Patcher from Mac?

Patcher removal requires using a reputable malware removal tool. We highly suggest installing FortectIntego or SpyHunterCombo Cleaner. After installation, update the program and run a full system scan. Your chosen software should eliminate the virus from the Mac entirely. Nevertheless, the official decryptor hasn’t been released; you can try to restore encrypted files with R-Studio or Data Rescue software. We cannot assure that these programs will decrypt all your files; hopefully, the majority of them will be rescued. Lastly, if the virus for some reason attacked Windows OS, please follow our prepared instructions how to remove Patcher from the PC. The virus isn’t supposed to attack Windows devices; however, strange things might happen in ransomware world!

Did this guide help?

3 comments

  1. Chloe

    Cant believe that Macs are not immune to ransomware.

  2. mac user

    I dont feel safe anymore....

  3. Andrew

    Its hard to believe. I think Ill stop using Torrents.

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.