Tutorials

Useful tutorials on various PC troubleshooting topics. Video tutorials.

How to remove STOP Ransomware and decrypt .pdff, .tro or .rumba files

This article contains information about version of STOP Ransomware that adds .pdff, .tro or .rumba extensions to encrypted files, and creates _openme.txt ransom note file on the desktop and in the folders with affected files. This variation first appeared in January, 2019 and almost identical to previous .puma Ransomware and .djvu Ransomware. Ransomware virus still uses AES encryption algorithm and still demands ransom in BitCoins for decryption. All three varieties belong to one author, because they are using the same e-mail addresses for communication: pdfhelp@india.com and pdfhelp@firemail.cc. From the file above we can learn, that hackers offer 50% discount for decryption, if ransom amount is paid within 72 hours. However, from our experience, this is just a trick to encourage person to pay the ransom. Often malefactors don't send decryptor after this. We recommend, that you remove active infection of STOP Ransomware and preserve your files until decryption tool appears. Until that time, you can try manual instructions on this page to attempt restoring encrypted files.

How to remove GandCrab v5.1 Ransomware and decrypt your files

GandCrab v5.1 Ransomware is fifth generation of very dangerous and harmful GandCrab Ransomware. It is yet unknown what type of encryption algorithm it uses. Virus assigns randomly generated identification code to each particular user. It looks like set of 8 letters and GandCrab v5.1 Ransomware uses it to create .[random-letters] extension and ransom note filename will look like this: [random-letters]-DECRYPT.txt and [random-letters]-DECRYPT.html. The contents of this ransom note is slightly different from previous versions of this malware. Unfortunately, files encrypted by GandCrab v5.1 Ransomware are currently not decryptable. However, as some of the previous versions had decryptor from BitDefender, we will provide download link for this tool below. There is a possibility, that they will update the program to decrypt latest instances of GandCrab Ransomware. We also provide general manual instructions, that can, in many cases, help you restore some or even all encrypted files. All these methods are worth trying.

How to remove Dharma-Gif Ransomware and decrypt .gif files

Monro Ransomware is subtype of Crysis-Dharma-Cezar ransomware family, that adds .monro extension to encrypted files. Virus uses composite extenion, that consists of e-mail adress and unique 8-digit identification number (randomly generated). Monro Ransomware developers extort from $500 to $1500, that have to be paid in Monero, Dash or BTC (BitCoins) for decryption. Due to the fact, that hackers often do not send decryption keys, or just ignore e-mails from victims, who paid the ransom, it is not recommended to send any funds. Usually, after some time security specialists and individual researchers break the algorithm and release master key. Also, some files can be recovered by using backups, recovery software and instructions given on this page.

How to remove Scarab Ransomware and decrypt .enter or .lol files

Scarab-Enter Ransomware is one of the varieties of Scarab Ransomware family. Scarab Ransomware has typical malicious activity: it encrypts user files using AES encryption and demands ransom of 0.3 BitCoins for decryption. Virus-extorsionist appends .enter or .lol extensions to encrypted files. Depending on version, after encryption Scarab Ransomware creates text files HELP HELP HELP.TXT or HOW TO RECOVER ENCRYPTED FILES.TXT text files with instructions to pay the ransom. Some of the previous Scarab versions were decryptable, however, if you won't succeed in decryption, do not pay the ransom. There are a lot of reports from the victims, that malefactors don't send decryptors. If Dr. Web Decryption Service fails for you, try manual instructions on this page and file-recovery software. In most cases this helps to restore some important files. In this article we collected, consolidated and structured available information about this malware and possible ways of removal and decryption.

How to remove Evolution Ransomware and decrypt .evolution files

Evolution Ransomware is new ransomware with currently unknown genealogy. There are some indications, that it is based on hte code of Everbe 2.0 Ransomware. Virus encrypts user's files using AES encryption algorithm and adds .evolution extension to encoded files. After contacting the developers via one of the provided e-mails, they demand 2 BitCoins for decryption and offer to decrypt 1 file for free as a proof. After this they send wallet for sending funds. 2 BitCoins at the time of righting this article had equivalent of $8000. We do not recommend paying the ransom as there is no guarantee malefactors will send final decryptor. Currently, there are no decryption tools available for this type of crypto-virus. The only way to get all files back is to restore from backups. You can also try to use instructions and tools below to recover some important files.