How to remove Scarab-Rebus Ransomware and recover .REBUS files

Scarab-Rebus (Rebus) is the newest variant of Scarab Ransomware. It renames all targeted files with Base64 encoding scheme and appends them with .REBUS extension. For example, file “mydoc.doc” will turn into “2wHNr2iP509NNRi4UQYgc.REBUS”. As usual, virus places a ransom note (REBUS RECOVERY INFORMATION.TXT) on the desktop at the end of the process where the victim will find pay method to restore encrypted files.

Learn More

How to remove Horsia Ransomware and recover .horsia@airmail.cc files

Horsia is a cryptovirus that belongs to the group of Scarab Ransomware family. After infiltration, it starts to encrypt all sensitive files on victim’s computer and then demands a ransom. All found files are encrypted with AES-256 cipher getting .horsia@airmail.cc extension. For example, “mydoc.doc” will turn into “mydoc.doc.horsia@airmail.cc”. At the end of encryption procedure, the virus creates TXT file (“HOW TO RECOVER ENCRYPTED FILES.TXT”) placing it in each folder as well as replaces your desktop wallpaper with a new one.

Learn More

How to remove HPE iLO Ransomware and recover your files

HPE iLO is a new ransomware-type virus that encrypts data on server systems HPE iLO 4. Notably, the distribution method is very different from many similar viruses. To get into victims’ computers, cybercriminals exploit remote control system (HPE Integrated Lights-Out). After this, they mount malicious ISO image into computers, by opening which, the encryption process is activated.

Learn More