.fairytail Files Virus (Cryakl) Ransomware - Remove and Restore Data

.fairytail Files Virus (Cryakl) Ransomware – Remove and Restore Data

This article aims to help you by showing you how to fully remove the .fairytail ransomware infection from your computer system and how to restore files that have been encrypted with the added .fairytail file extension to them.

The new variant of Cryakl ransomware virus is here and it uses the .fairytail file extension after it encrypts the files on the computers that have been infected by the virus. Alongside it, the files are also renamed with a added symbols to their original anames, making them to appear corrupt. In addition to this, the .fairytail files virus also drops a ransom note file which aims to extort the victims of this virus into paying a hefty ransom fee in order to recover their encrypted files. If you are one of the victims of the .fairytail ransomware virus, we advise that you read this article and learn how to remove this virus from your computer and how to try and restore .fairytail encrypted files without paying the actual ransom.

Threat Summary

Name.fairytail Files Virus
TypeRansomware, Cryptovirus
Short DescriptionNew variant of Cryakl ransomware virus. Encrypts documents, videos and other important files and asks to contact the cyber-crooks and cooperate to get your files back.
SymptomsDrops a Readme.txt ransom note file and encrypts the files, adding the .fairytail file extension after their original name.
Distribution MethodSpam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by .fairytail Files Virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .fairytail Files Virus.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

.fairytail Files Virus – Methods of Replication

For this virus to infect users while remaining undetected, it uses obfuscation techniques that aim to avoid conventional antivirus protection. Those techniques are usually embedded in an Exploit Kit or other form of malicious infection kit and they target vulnerabilities in Windows. The infection process is done via an infection file which is masked as a legitimate type of document or other type of important file, such as:

  • A receipt.
  • Setups of programs.
  • Invoices.
  • Fake key generators.
  • Program cracks or patches.
  • Fake banking statements.

If you receive the file via e-mail it may be an executable type of file, a JavaScript file or even a Microsoft Word .docm type of file, containing malicious macros within it. The cyber-criminals may make it so that the e-mail looks like a legitimate type of message sent to notify you that it is important to open the attachment. They often include convincing statements, for example:

.fairytail Cryakl Ransomware – More Information

As soon as an infection by this ransomware virus takes place on your computer, you may immediately begin to experience system freezes and interrupts. This is because the .fairytail ransomware performs it’s malicious activity on your computer, starting with dropping it’s malicous files in it. Those usually are located in the following Windows directories:

  • %AppData%
  • %Local%
  • %Roaming%
  • %LocalLow%
  • %Temp%

As soon as the Cryakl .fairytail files virus has had it’s malicious files dropped on the computer of the victim, the malware may immediately start to interfere with the Run and RunOnce Windows Registry sub-keys, adding values of data in them that make the malicious file of the virus which encrypts your data run automatically when your Windows boots. The sub-keys have the following locations:

→ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

In addition to this, the virus may also drop a README.txt file that has the one and only purpose to get you to message the cyber-criminals via e-mail in order to receive further instructions on how to pay the ransom fee of this virus in order to get them to decrypt your files.

Furthermore, before beginning to encrypt your files, the .fairytail ransomware infection may also delete the shadow volume copies on your computer system and disable the Windows Recovery process. This is done by executing commands in Windows Command Prompt with the following parameters:

→ process call create “cmd.exe /c vssadmin.exe delete shadows /all /quiet & bcdedit.exe /set {default} recoveryenabled no & bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures”

.fairytail Ransomware – Encryption Process

The Fairytail ransomware virus has different activities when it comes to encrypting your files. Firstly, the virus is configured to search for important files on your system, such as archives, images, audio and video files, documents and others. It does this by targeting the most commonly used file extensions, some of which are the among following:


After the files match with the ones Cryakl ransomware is scanning for, the virus begins the encryption procedure by triggering the encryption mode to begin replacing bytes of data from the original files with scrambled data, breaking the original structure of the files and thus making them no longer able to be opened again. This results in the files to seem corrupt and the malware changes their file extensions, making them assume the following appearance:

The sum, demanded by the cyber-crooks may vary depending on the negotiations with them and paying the ransom is highly inadvisable, because you cannot trust them and you support them to further develop and spread their viruses to infect others.

Remove Cryakl Ransomware and Restore .fairytail Encrypted Files

If your computer has been infected by the .fairytail ransomware virus, recommendations are to remove it by following the removal instructions in the article. However, in order to perform the removal, you would need to have some experience with malware. Furthermore, experts strongly advise to do the removal automatically using an advanced anti-malware software, which will help scan for all the malicious files of .fairytail and remove them plus protect your computer against future infections as well.

In the even that your files have been encrypted by this ransomware virus, you can try the alternative methods for file recovery which we have suggested below in step “2. Restore files encrypted by .fairytail Files Virus”. They may not be 100% effective, but the tools may help you recover as many encrypted files as possible without actually having to pay ransom.


Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share