Category Trojans/Viruses

How to remove Kangaroo ransomware and decrypt .crypted_file files

The Kangaroo Ransomware is a serious threat to your computer. It’s a Trojan virus, that encrypts all the data placed on your hard drive. Still you can get your files and folders back, because Kangaroo Ransomware does not damage, move or delete them. After finishing the encryption process, this virus demands payment in order to "help" you with decryption. These criminals usually demand 500 - 1000 US Dollars in Bitcoins. After the payment is done, there is no guarantee that it will help you to get your data back. So please do not invest into this criminal scheme.

How to remove Angry Duck ransomware and decrypt .adk files

Angry Duck is ransomware-type virus that uses encryption with AES-512 cryptography. Virus is very weird because it demands huge ransom (10 BitCoins or $6500), however, authors do not provide any contacts or instructions to pay this ransom like e-mail or electronic wallet. But Angry Duck actually encrypts files and appends .adk extension to all affected ones. Usually, ransomware targets pictures, videos, documents and other types of personal files. Feedback shows, that hackers never or rarely send decryption keys or decryption tools after users pay them.

How to remove Thor ransomware and decrypt .thor files

Thor is another variant of Locky ransomware that uses RSA-2048 and AES-128 encryption algorithms to encode files. Virus got its name because it adds .thor extension to all ciphered files. It also modifies filenames using random characters and numbers, so it becomes hard to distinguish files. Mostly malware affects user documents, pictures, videos, game files. Thor ransomware demands ransom of 3 BitCoins (~$1950). Ransomware creates 2 files: _WHAT_is.html and _WHAT_is.bmp. This files contain instructions for users to pay the ransom and get decryptor.

How to remove Shit ransomware and decrypt .shit files

Shit ransomware is new virus from Locky family. Actually, it infects files using the same way - like previous variants, ransomware is installed using a DLL that is executed by Rundll32.exe. After execution it attacks files of 380 various file extension and encrypts them using AES encryption. After this it appends .shit extension to all encoded files and demands ransom of 3 BitCoins (~$1950). Ransomware creates 3 files: _WHAT_is.html, _[2_digit_number]_WHAT_is.html, and _WHAT_is.bmp. This files contain texts encouraging users to pay the ransom.

How to remove Odin ransomware and decrypt .odin files

Odin ransomware is new cryptographic virus from family of Locky and Zepto ransomware. It uses system process (rundll32.exe) to execute and encrypt user files. Usually, infection affects user personal files such as documents, photos, videos and music. In this version virus adds .odin extension and modifies filename, changing it to random set of numbers and letters. Virus creates 3 files: _5_HOWDO_text.html, _HOWDO_text.bmp, and _HOWDO_text.html. Image file is used as desktop background and contains text with instructions to pay the ransom.