Java Ransomware is extremely harmful file-encrypting virus, that belongs to the family of Dharma/Crysis ransomware. It adds .java extension to all encrypted files. Usually, this is complex suffix that contains unique id and e-mail. Java Ransomware uses spam mailing with malicious .docx attachments. Such attachments have malicios macros, that runs when user opens the file. This macros downloads executable from the remote server, that, in its turn, starts encryption process.
Nozelesn Ransomware is new type of ransomware, that uses AES-128 encryption to encode user files. It appends .nozelesn extension to “in cipher” files. According ro researchers Nozelesn Ransomware firstly targeted Poland, but then expanded to other european countries. After successful encryption virus drops HOW_FIX_NOZELESN_FILES.htm file with ransom-demanding message on the desktop and in the folders with affected files. The price for decryption is 0.10 BitCoins, that is currently ~$650. Malefactors promise to send decryption key within 10 days. However, cybercrooks cannot be trusted as, according to our experience, oftne do not hold out promises not to put their encryption algorithm at risk. At the moment of writing this article there is no decryptors released, but we keep abreast of the situation.
JobCrypter Ransomware is crypto-virus ransomware based on Hidden Tear code. Virus adds .locked or .css extension sto encrypted files. This crypto-extortioner encrypts user data using 3DES, and then requires a redemption to return the files back. Judging by the text of the demand for the ransom, JobCrypter is focused only on French users. However, it is noteworthy that many infected JobCrypter PCs were in Lithuania. To remove the blocking of files, the affected party needs to pay a ransom of 300 euros from the PaySafeCard.
Updated version of STOP Ransomware ransomware appends .PAUSA, .CONTACTUS, .DATASTOP or .STOPDATA suffixes to encrypted files. Virus still uses RSA-1024 encryption algorithm. All versions, except .STOPDATA, demand $600 ransom in BTC (BitCoin cryptocurrency), last one offers decryption for $200. Still malefactors offer to decrypt from 1 to 3 files for free to prove, that decryption is possible. This can be used to attempt decoding in future. At the moment, unfortunately, the only way to restore your files is from backups.
Aurora Ransomware (sometimes called OneKeyLocker Ransomware) is new crypto-virus, that started circulating the web since the end of May, 2018. It uses DES algorithm to encode files and adds .Aurora extension, after which it got its name. After encryption ransomware creates several text files HOW_TO_DECRYPT_YOUR_FILES.txt, newest version creates single #RECOVERY-PC#.txt file, containing ransom note with contact information and instructions. Usually, viruses of this type ask for $100 – $500 in BitCoins. At the moment, there are no public decryption tool available. Full recovery is only possible with help of backups. You can preserve your files till actual decryptor will be created. Some data can possibly be restored using instructions on this page.