Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jun 2020

How to remove Syrk ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

Syrk ransomware is a cryptovirus that deletes personal files if the ransom is not paid within the given time period

Syrk ransomware

Syrk is a ransomware-type malware that was first spotted by security analyst Leo at the start of August.[1] As it turns out, it is not related to any other virus family, but was inspired by the Fortnite Hacktool still seems to be in the development stage. Nevertheless, the infection still poses a high risk to PC users, as it can result in permanent personal data loss.

As soon as Syrk ransomware infects the machine, it scans the computer for photos, videos, databases, documents, etc., and encrypts them using AES[2] cipher. Files encrypted in such a way are no longer accessible, and victims can see .syrk extension appended to them. Additionally, the malware disables the Task Manager, locks the screen and drops Readme_now.txt ransom note.

The message from hackers claims that users need to contact crooks via the panda831@protonmail.com email and pay the ransom in Bitcoins to retrieve the locked data. However, this is not the end of the unwanted changes of the malware, as Syrk ransomware also displays a timer and, once it runs out, it starts deleting all files located inside the My pictures directory, followed by desktop and documents folders.

Name Syrk
Type Ransomware
Encryption algorithm AES
File extension .syrk
Related files SyrkProject.exe, SydneyFortniteHacks.exe
Ransom note Readme_now.txt
Contact panda831@protonmail.com 
File decryption Only possible via backups or third-party recovery software
Termination Use reputable anti-malware software, such as SpyHunterCombo Cleaner
Recovery To fix damaged Windows system files, scan your PC with FortectIntego

There are a variety of methods that Syrk ransomware authors could be used to deliver a malicious payload. However, because the malware has close connections to hack tools, it is highly likely that it is spread via software cracks, hacks, and similar high-risk programs. Other methods might include:

  • Exploits
  • Web injects
  • Unprotected RDP
  • Fake updates
  • Spam emails, etc.

You should always keep security software installed on your computer to prevent most of the malware entering your computer. Otherwise, ransomware viruses like Syrk can enter without any interruptions and lock all your data.

As soon as Syrk virus encrypts the files, it locks the screen and shows a black screen with an anonymous picture on it, which also includes the following message:

*Your personal files are being encrypted by Syrk Malware. Your photos, videos, documents, etc… the only way to recover it is to contact this email: (panda831@protonmail.com) and submit your id.

After paying, you will be sent a password that will be used to decrypt your files
if you don't do these actions before the timer expires your files will start to be deleted
at the first timer the files in the photo folder will be deleted
at the second timer the files in the desktop folder will be deleted
at the third timer the files in the document folder will be deleted

So hurry up, TIME FLOWS!!!!

To see your Id click on *Show My ID*

In most of the cases, locked files remain on the compromised computer system. However, Syrk ransomware tries to prevent users from copying the data by locking the screen and disabling the Task Manager. The timer is then added, and, once expired, files start being deleted permanently. Victims can click on “Show My ID” where the password that crooks allegedly send you after you pay can be entered.

cransomware virus

Nevertheless, security experts managed to find the password hidden within files that Syrk places. It could be found in the following folders of the infected machine:

  • C:\Users\Default\AppData\Local\Microsoft\-pw+.txt (to open, use password “passwordonly”)
  • C:\Users\Default\AppData\Local\Microsoft\+dp-.txt (to open, use password “pass : password”)

Once the password is entered, all the files are decrypted, and a text message decrypted.txt is shown which claims:

Your personal files have been decrypted

Unfortunately, cybercriminals quickly fixed the bug, and users can no longer decrypt their files by using this method. The only way to retrieve the locked data is by using recovery software or backups after full Syrk ransomware removal is complete.

Security experts[3] highly advise you not to contact or pay cybercriminals, as the virus is still in development, and it is highly likely that researchers will come up with a way to recover your data for free. Instead, remove Syrk ransomware using anti-malware software and then scan your compute with FortectIntego to repair Windows OS files that were damaged during the infection.

Stay away from hack and crack tools and use reputable security software to protect yourself from ransomware infections 

As we described above, there are several methods of how cybercriminals might infect your computer with ransomware. Therefore, it is vital to make sure your machine is protected as well as possible. Note that no protection measures can prevent the infections 100%, but adequate online behavior and installed security application can significantly reduce the risk.

Syrk ransomware decryption

Therefore, always make sure you have an anti-malware software up and running and make sure that it includes a real-time protection feature. Also, stay away from software cracks, pirated programs, and hack tools. You should not open suspicious attachments or click on links inside spam emails that are sent to you by an unknown source (be aware of email spoofing[4] – email addresses can be forged and look legitimate). Finally, practice an overall safe behavior online – avoid torrent sites, use strong passwords, do not click on suspicious links, etc.

Additionally, we recommend you back up all your important files either on a virtual server or an external drive. In such a way, even if all the protection measures fail, you can negate all the ransomware consequences with ease.

Remove Syrk virus from your computer using reputable security software

As we previously mentioned, the malware locks your screen and disables Task Manager. For that reason, it is mandatory to enter Safe Mode with Networking in order to remove Syrk virus – an environment where the virus operation is temporarily disabled. Once inside, thoroughly scan your computer with anti-malware software. Be aware that the termination process should be done as soon as possible, as the malware can start deleting your files located in My Documents and other folders.

Once you complete Syrk ransomware removal, you can start the file recovery process. You should connect your external drive and connect to the virtual storage and copy all the files over. If you had no backups, chances of recovering data are relatively slim, although you should definitely try alternative methods we provide below.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.