What is Pscrypt virus?
Pscrypt will append its own .pscrypt extension to the title of every encrypted file. For example, a file named “photo.jpg” will be changed to “photo.jpg.pscrypt”. In the same manner, the Excel sheet with the name “table.xlsx” will end up as “table.xlsx.pscrypt”, and so forth.
In each directory that contains the encoded files, a Paxynok.html text file will be found. It is a ransom money note. Therein you can find information on the ways of contacting the racketeers and some other remarks. The ransom note usually contains instructions on how to buy the decryption tool from the racketeers. That is basically the scheme of the felony.
| Name | Pscrypt Virus |
| Extension | .pscrypt |
| Ransomware note | Paxynok.html |
| Detection1 | Cydoor.Adware.Advertising.DDS, Trojan-Ransom.Win32.Blocker.pef, Win32/GenKryptik.GCGO |
| Symptoms | Your files (photos, videos, documents) have a .pscrypt extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Pscrypt virus |
In the image below, you can see what a directory with files encrypted by the Pscrypt looks like. Each filename has the “.pscrypt” extension appended to it.
How did my computer get infected with Pscrypt ransomware?
There are currently three most popular ways for tamperers to have ransomware settled in your digital environment. These are email spam, Trojan introduction and peer-to-peer file transfer.
If you access your mailbox and see emails that look just like notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is unknown to you, beware of opening those letters. They are most likely to have a viral item attached to them. Therefore, it is even riskier to download any attachments that come with emails like these.
Another thing the hackers might try is a Trojan virus model2. A Trojan is a program that infiltrates into your machine pretending to be something different. Imagine, you download an installer for some program you want or an update for some program. However, what is unboxed reveals itself a harmful program that encodes your data. Since the installation file can have any name and any icon, you’d better be sure that you can trust the resource of the stuff you’re downloading. The best way is to use the software developers’ official websites.
As for the peer-to-peer networks like torrents or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. So you’d better be using trustworthy websites. Also, it is reasonable to scan the folder containing the downloaded objects with the antivirus as soon as the downloading is complete.