SystemCrypter is a ransomware-type virus that borrowed several aspects of EncryptServer2018 file locker

SystemCrypter ransomware is cryptovirus that was first spotted in the wild in the mid-June 2019. The malware is written in Python programming language and has many similarities to EncryptServer2018 ransomware, although it is not known whether developers are connected in any way.
Soon after the infiltration, SystemCrypter ransomware searches for files located on the local hard drive and all the connected devices and encrypts them with the help of AES-256 encryption algorithm,[1] appending .crypted extension (which was previously used by Crypted virus, as well as other crypto-malware families). From that point, users cannot access their personal data like photos, videos, documents, databases, and others.
SystemCrypter virus also spawns a pop-up window under the name “System Crypter v2.40,” which is essentially a note from hackers. It explains that users need a decryption tool, and to receive it, victims have to send 0.066 Bitcoin to the 18ixe82TGy3hUwmmvZVU75tCVoRyeNoYvY Bitcoin address.
| Name | SystemCrypter |
| Type | Ransomware |
| Encryption algorithm | AES-256 |
| File extension | .crypted |
| Related files | Crypter.exe, key.txt, encrypted_files.txt, WARNING.txt |
| Ransom note | System Crypter v2.40 |
| Ransom size | 0.066 BTC |
| Bitcoin address | 18ixe82TGy3hUwmmvZVU75tCVoRyeNoYvY |
| Removal | Delete malware with the help of security tools like FortectIntego or SpyHunterCombo Cleaner |
| Decryptable? | Yes, contact Michael Gillespie or use third-party recovery software |
However, no contact information is provided by the malware author. Therefore, transferring 0.066 BTC (which is currently worth around $600) into the provided wallet is absolutely unnecessary. Instead, users should remove SystemCrypter ransomware with the help of reputable anti-malware software, such as FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
Luckily, there are no victims currently that decided to pay the ransom, as the provided wallet address remains empty. Finally, the malware can be decrypted with the help of security researcher Michael Gillespie, so System Crypter ransomware victims should contact him on Twitter. Note: victims should not delete the key.txt file uploaded onto the system, as without it the decryption is not possible.

There are multiple ways of how you could get infected with SystemCrypter ransomware, such as:
- Spam emails;
- Exploit kits;[2]
- Pirated software and its cracks;
- Fake updates;
- Web injects, etc.
Users who are careless when browsing the internet and do not use anti-virus software are mostly at risk. To find out how to protect yourself from parasites like SystemCrypter, refer to the second part of this post.
As soon as SystemCrypter payload is executed, malware will modify Windows system files and delete shadow volume copies. After encrypting all personal data on the device, victims are greeted with the following message from the hackers:
ATTENTION !!!
All your files on this computer have been encrypted. After payment we will send you a decryption tool that willdecrypt all your files.
GUARANTEES!!!
You can send us up to 3 files for free decryption.
-files should not contain important information
-and their total size should be less than 1 MBHOW TO OBTAIN BITCOINS!!!
The easiest way to buy bitcoins is the LocalBitcoins website.
You need to register, click “Buy bitcoyne” and select theseller
by method of payment and price
https://localbitcoins.com/buy_bitcoinsIMPORTANT !!!
Do not rename encrypted files
Do not try to decrypt your data with third-party software,this can lead to permanent data loss!

Even if you would like to contact hackers, it is not possible as no contact details are provided. Because the malware also includes key.txt file that allows copying the personal key, which can consequently help to decrypt files with the help of security researchers.
However, before you attempt file recovery, you should make sure that SystemCrypter ransomware removal is performed correctly and all traces of malware are gone. To find out how to do that, check the bottom section of this article.
Install security software and backup your files to negate ransomware infection damage
Fortunately, virus authors failed to deliver proper encryption of files, so users can retrieve their data in most cases. However, other ransomware victims are not so lucky, as the pictures, videos, documents, and other files will stay permanently locked. In general, the file locking feature is what makes ransomware so devastating.
Therefore, it is best to prevent ransomware infections altogether, although no protection method would guarantee 100% resistance to malware. For that reason, you should always make sure that you store backups of your files on a virtual server or an external device such as an HDD or flash drive.
Security experts[3] also advise the following when performing the daily tasks on computers that are connected to the internet:
- Install powerful anti-malware software and keep it updated;
- Update Windows OS, along with all the installed software;
- Beware of spam email attachments (.pdf, .zip, .html, .doc, etc.) and inserted hyperlinks, no matter how believable they look;
- Do not download pirated software and its cracks or keygens;
- Install an ad-blocker;
- Use strong passwords for all your accounts;
- Enable two-factor authentication where possible.
System Crypter virus removal steps
To remove SystemCrypter ransomware, you will have to employ anti-malware software. If you still haven't installed one of those (you should!), we can suggest you using FortectIntego, SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or other reputable security application. Be aware that AV engines use different databases, so not all of them might be able to detect[4] and terminate the malicious payload. For that reason, we recommend scanning your device a few times with different anti-virus programs.
Additionally, SystemCrypter ransomware removal might not succeed if the virus is tampering with your security software. In such a case, you should access Safe Mode with Networking – this environment should temporarily disable the malware and allow you to remove it without problems.
As soon as you are sure you terminated SystemCrypter virus, you can then proceed with file recovery process: backups, experts' help or third-party tools – use these methods to recover all the .crypted files.

Did this guide help?
Be the first to comment