malwarebytes banner

Tutorials

Useful tutorials on various PC troubleshooting topics. Video tutorials.

How to remove CURATOR Ransomware and decrypt .CURATOR files

0
CURATOR is another version of ransomware infections that puts up a lock on victims' data demanding a fee for its return. The basic symptom of CURATOR leaving its traces in your system is the appendance of new extensions onto affected files. For example, a file like 1.mp4 will emerge as 1.mp4.CURATOR after interacting with ransomware. To recover your data, extortionists offer to read instructions in the !=HOW_TO_DECRYPT_FILES=!.txt note that is created soon after encryption. According to the provided note, attackers have encrypted your files with strong algorithms (ChaCha+AES), which restrict attempts to restore files on your own. As a result, the only feasible way appears to buy the decryption key stored on the server of cybercriminals. Once you make a decision, extortionists kindly ask you to contact them via e-mail to get further instructions. You can also take advantage of a special offer - send up to 3 files (not more than 5 MB) for free decryption. Although such a move can instill trust in gullible users, we recommend against paying the ransom. There is always a risk of getting money-naked and not receive any of the promised tools for data recovery.

How to fix Print Spooler errors on Windows 10

0
First of all, Print Spooler is a type of service that is initially integrated into your system and implements the function of sending printing queues to the printer server. Therefore, it is responsible for running multiple printing jobs correctly without setbacks. However, there has been a couple of users repeatedly facing different printer-related issues. Actually, it does not matter which one you are currently facing because all of these errors are typically caused by other services that might not be working properly. The main dependency usually lies in RPC (Remote Procedure Control) services that play a significant role in printing. Therefore, it is more likely that you are facing this error because RPC is either malfunctioned or not started at all. Although, with our help, it will not be a big struggle to fix this problem with the full kit of radical solutions that are mentioned in the article below.

How to fix Windows cannot find cmd error

0
Some users experience a problem opening Command Prompt in Windows systems. The issue is followed by a message saying that "Windows cannot find cmd. Make sure you typed the name correctly, and then try again". This can be damaging for those using Command Prompt to overcome other issues related to system performance. What is even worse is that Command Prompt can be used by other programs to run certain processes as well. The issue means that the "cmd.exe" file is missing and cannot be found by Windows. Usually, this can happen due to malware presence that hijacked and messed up the folder of cmd. Thus, we will start by running a scan and then try other methods later on.

How to remove Dharma-BLM Ransomware and decrypt .[blacklivesmatter@qq.com].blm files

0
Being part of the Dharma family, Dharma-BLM is a malicious piece that pursues financial gain by encrypting personal data. It does so by assigning a string of symbols including unique ID, cybercriminals' e-mail, and .blm extension at the end of each file. Here is an example of how infected data will look like 1.mp4.id-C279F237.[blacklivesmatter@qq.com].blm. When the encryption process is done, the virus moves on to the next step and creates a text note (FILES ENCRYPTED.txt) containing ransom instructions. The message justifies that all data has been successfully encrypted and requires action within 24 hours - to contact cybercriminals via e-mail and receive payment details to buy the decryption tools. Victims are also warned that any manipulations with files like name change will lead to permanent loss. Additionally, developers propose you to send a file for free decryption, which has been a trick used by many ransomware creators to instill trust in gullible users and make a deal. Unfortunately, more often than not, the decryption of data without the involvement of developers will give no fruits, unless ransomware contains some bugs or flaws that will allow third-party tools to crack open the assigned cipher.

How to remove BitRansomware and decrypt .readme files

0
BitRansomware is known as a file-encrypting virus meant to block user's data and keep it under lock until a ransom is paid. Such malware earns a lot of money on inexperienced users who have been given no choice but to pay a fee because their data is encrypted with unbreakable ciphers. Imagine all of your personal data becomes inaccessible - this is what BitRansomware does. It assigns the new .readme extension at the end of each file to highlight them from the original ones. A sample of encrypted data looks like this 1.mp4.readme. After this process, extortionists will display a text note called Read_Me.txt explaining the decryption process. It is said that all important files have been successfully encrypted and the only possible way to implement full decryption is to pay a fee through a Tor link attached in the note. Usually, this is the truth, because files can be decrypted only if ransomware contains some flaws or bugs overlooked by developers. Whatever the case, we do not recommend paying a ransom, because trusting extortionists is a quite tricky thing.

How to remove LockDown Ransomware and decrypt .LockDown files

0
LockDown is a file-encrypting software created to earn money on unprotected users. The virus acts using AES+RSA algorithms to set up strong encryption on stored data and appends .LockDown extension. Many kinds of data will be changed according to this example 1.mp4.LockDown. After the encryption is done, LockDown creates a text note (HELP_DECRYPT YOUR FILES) containing ransom instructions. Users are said that only a private key held by cybercriminals can lead to successful data decryption. To obtain it, victims have to send approximately 460$ worth of Bitcoin to the attached wallet. Although extortionists ostensibly prove their integrity by allowing users to decrypt 1 file for free, we still advise against paying the ransom, because there is a risk that swindlers will not provide recovery tools eventually. For now, there are no official tools that could guarantee 100% file decryption.

How to remove Yatron Ransomware and decrypt .Yatron or .Down_With_Usa files

0
Using a mix of AES and RSA algorithms, Yatron Ransomware encrypts user's data and demands victims to pay a so-called ransom. It is known to be advertised on Twitter as "Ransomware-as-a-Service". There is a bunch of file types that can be affected by this ransomware after penetration. Almost all files stored on your PC will be assigned either with .Yatron or .Down_With_Usa extension. Here are the samples of infected files - 1.mp4.Yatron and 1.mp4.Down_With_Usa. Then, once the encryption process is done, the virus drops a text note (Read@My.txt) in each folder and force-opens a pop-up window that states ransom instructions. The content explains that your data has been encrypted. The only way to revert the consequences is to pay 300$ in BTC to the attached address. Sometimes the required amount can vary depending on which version attacked your system. Additionally, the window shows a clock saying that you have 3 days to make a payment, otherwise, your data will be removed completely. Despite manual decryption is usually impossible, you should not trust cyber criminals and follow their steps. The danger is that there is no guarantee they will fulfill their promises and provide necessary tools for data recovery.

How to fix BAD_SYSTEM_CONFIG_INFO error in Windows 10

0
A number of reasons can be the culprit for BAD_SYSTEM_CONFIG_INFO appearing on PCs. Usually, this error can be related to registry, drivers, configuration, hardware, and other issues. The most obvious symptom reflecting the BAD_SYSTEM_CONFIG_INFO issue is an abrupt shutdown and display of the BSOD (Blue Screen of Death). Sometimes Windows cannot fix the problem and keeps crashing without having a chance to finish the boot up successfully. Users have to correspond to other devices to learn fixing instructions. Luckily, there are some options designed by Windows to solve issues without accessing the desktop itself. You will find instructions upon the problem elimination in the article below.