How to remove STOP Ransomware and recover .STOP, .SUSPENDED, .WAITING files

STOP is the name of the virus that encodes files on the infected computer thus making them unavailable for users. Combination of AES and RSA-1024 encryption algorithms are used for this purpose. During encryption, it appends STOP (or .SUSPENDED, .WAITING) extension to all infected files and creates TXT file (!!!YourDataRestore!!!.txt) that contains ransom-demanding message.

Learn More

How to remove Spartacus Ransomware and recover .Spartacus files

Spartacus is a cryptovirus that demands a ransom in exchange for your files. The malware spreads mostly via spam emails with attached SF.exe file and if you accidentally launch executable file, virus will start to infect your system. It scans your system to find more sensitive files like documents, photos, videos and so on. All sensitive files is encoded and gets .Spartacus or [MastersRecovery@protonmail.com].Spartacus extension, for instance, “mydoc.doc” will turn into “mydoc.doc.Spartacus”.

Learn More

How to remove Tron Ransomware and recover .tron files

Tron is a virus that instantly encrypts files once it gets on victim’s computer. Notably, the malware only targets computers outside Russia, suggesting that Tron is yet another offspring of Russian hackers. During the encryption procedure, each infected file gets .tron extension, for instance, “mydoc.doc” will turn into “mydoc.doc.tron”. Then, it displays a lock screen containing information about the amount of ransom.

Learn More

How to remove Java NotDharma Ransomware and recover .java files

Java NotDharma is a cryptovirus, the activity of which took place at the mid-April 2018. The malware got its name due to the similarity to infamous Dharma Ransomware, incidentally, many computer experts initially thought it’s just a new version of Dharma, however, this was not confirmed later. While encrypting, virus adds .java extension to all infected files. For example, “mydoc.doc” will turn into “mydoc.doc.java”.

Learn More

How to remove Iron Unlocker Ransomware and decrypt .encry files

Iron Unlocker Ransomware is a modified version of infamous Maktub ransomware that, like a previous one, makes files on victim’s computer unavailable. While encrypting, virus adds .encry extension to all infected files. For example, “mydoc.doc” will turn into “mydoc.doc.encry”. To get files back, a user is offered to pay ransom as described in the ransom note (!HELP_YOUR_FILES.HTML) which a virus creates upon completion.

Learn More

How to remove B2DR Ransomware and decrypt .bronmerkberpa1976@protonmail.com.b2dr files

B2DR Ransomware is a fresh threat released in March 2018 that already infected many computers. Following infiltration, it encrypts user’s personal files adding .bronmerkberpa1976@protonmail.com.b2dr extension to all infected files. Like other such viruses, it leaves short instruction (readme.txt) on how to restore your files for the completion of its work.

Learn More

How to remove Arrow Ransomware and decrypt .arrow files

Arrow Ransomware is a new version of infamous Dharma Ransomware which has already affected many users around the world. As a previous one, Arrow Ransomware encrypts users’ personal files using both AES and RSA ciphers and appends .[marat20@cock.li].arrow extension to all infected files. The extension may vary, depending on the version: .id-[random-characters].[vauvau@cock.li].arrow, [badfail@qq.com].arrow.

Learn More