What is Pay virus?
Pay will add its own .Pay extension to the name of every encrypted file. For instance, an image named “photo.jpg” will be renamed to “photo.jpg.Pay”. Likewise, the Excel sheet named “table.xlsx” will be altered to “table.xlsx.Pay”, and so on.
In each folder with the encrypted files, a HOW TO DECRYPT FILES.txt file will appear. It is a ransom money note. Therein you can find information about the ways of paying the ransom and some other information. The ransom note most probably contains instructions on how to purchase the decryption tool from the tamperers. That is it.
| Name | Pay Virus |
| Ransomware family1 | Xorist ransomware |
| Extension | .Pay |
| Ransomware note | HOW TO DECRYPT FILES.txt |
| Detection2 | Ransom:Win32/Cryptolocker.PAL!MTB, UDS:Trojan-Banker.Win32.Bandra, Trojan:MSIL/AgentTesla.EPQ!MTB |
| Symptoms | Your files (photos, videos, documents) have a .Pay extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Pay virus |
In the screenshot below, you can see what a directory with files encrypted by the Pay looks like. Each filename has the “.Pay” extension appended to it.
How did my machine catch Pay ransomware?
There are currently three most popular methods for evil-doers to have ransomware acting in your system. These are email spam, Trojan injection and peer networks.
If you access your mailbox and see letters that look like familiar notifications from utility services companies, postal agencies like FedEx, Internet providers, and whatnot, but whose addresser is strange to you, be wary of opening those letters. They are very likely to have a harmful item enclosed in them. Thus it is even more dangerous to open any attachments that come with emails like these.
Another option for ransom hunters is a Trojan horse scheme3. A Trojan is an object that infiltrates into your machine pretending to be something different. For example, you download an installer for some program you want or an update for some software. But what is unpacked turns out to be a harmful agent that encodes your data. As the update package can have any name and any icon, you have to make sure that you can trust the source of the things you’re downloading. The best way is to use the software developers’ official websites.
As for the peer-to-peer file transfer protocols like torrent trackers or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. Our suggestion is that you use trustworthy websites. Also, it is a good idea to scan the directory containing the downloaded files with the antivirus as soon as the downloading is complete.