Home > Berta Bilbao

Author Archive: Berta Bilbao - Page 38

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

THREAT REMOVAL
stf-ishtar-ransomware-virus-russian-protonmail-ransom-message-note

Remove Ishtar Ransomware and Restore ISHTAR- Files

A ransomware cryptovirus called Ishtar is encrypting victims’ files over the past few days. The name is that of a Mesopotamian goddess of war and love, but the cybercriminals might have named their malware after the famous Israeli singer. Encrypted…

THREAT REMOVAL
stf-versiegelt-ransomware-virus-jigsaw-variant-german-ransom-message-note

Remove Versiegelt Virus (Jigsaw) and Decrypt .versiegelt Files

The Versiegelt seems to be a German variant of the Jigsaw ransomware cryptovirus. All encrypted files will have the extension .versiegelt appended to them. The virus does not seem to have any particular theme as past variants do. The ransom…

THREAT REMOVAL
stf-winnix-cryptor-ransomware-virus-wnx

Remove Winnix Cryptor Virus and Restore .wnx Files

The Winnix Cryptor Team have developed a ransomware virus named after themselves – Winnix Cryptor. The cryptovirus will encrypt your files while appending the extension .wnx to each file. The ransom price that is asked for decryption is 4 Bitcoins,…

THREAT REMOVAL
stf-ifn643-malware-readme-ransomware-virus-ransom-message-note

Remove IFN643 Virus and Restore .ifn643 Files

IFN643 is the name of a newly-found ransomware virus. This virus encrypts your files by placing the .ifn643 extension to them. After the encryption process is finished, it will put a file named “IFN643_Malware_Readme”. That file contains the ransom demand,…

THREAT REMOVAL
stf-esmeralda-ransomware-virus-apocalypse-aes-encryption-ransom-note

Remove Esmeralda Ransomware and Restore .encrypted Files

Esmeralda ransomware is believed to be a new variant of the Apocalypse cryptovirus. The new strain uses the same domain for an e-mail contact and encrypts files by placing the same extension. That extension is .encrypted and is placed on…

THREAT REMOVAL
stf-megabackup-com-mega-backup-adware-ads-main-site-page

Remove MegaBackup Adware

MegaBackup.com is a website of a supposed backup platform. The website distributes lots of advertisements and can redirect you and affect your browsers and other applications, so it is considered adware. Pop-ups and banner ads are among the popular choices…

THREAT REMOVAL
stf-encryptile-ransomware-deposithere-e-mail-ph-ransom-note-message

Remove Encryptile Ransomware and Restore .EncrypTile Files

A new ransomware cryptovirus called Encryptile has appeared. All encrypted files will have the .EncrypTile extension appended to their names. The ransomware claims to use AES and RSA encryption algorithms. The ransom note gives a contact email with a Philippine-based…

THREAT REMOVAL
stf-chinimplants-website-chin-implants-ads-adware-main-web-page

Chinimplants.website Ads Removal

Chinimplants.website is a domain page for an ad-pushing platform. The site generates bulks of advertisements and redirects on other websites. So, it is considered adware. Website owners make money from these adverts and also can extract information about you. To…

THREAT REMOVAL
stf-searchoko-com-search-oko-browser-hijacker-redirect-google-imitator-main-site-page

Remove Searchoko.com Redirect

Searchoko.com is a search redirect and a domain for a browser hijacker. The logo of this hijacker is intentionally very similar to that of Google referring to its letters and their coloring. The hijacker will redirect you to the results…

THREAT REMOVAL
stf-axzbryg-trade-fake-tech-support-scam-serious-malfunction-pop-up

Remove Axzbryg.trade Tech Support Scam

Axzbryg.trade is a website hosting a tech support scam. The scam tries to scare you into calling the (877)-337-7936 phone number. It is said on the site that you need to contact Microsoft technicians on that helpline, but they are…

THREAT REMOVAL
stf-popads-net-pop-ads-pop-up-ad-network-main-website-page

Popads.net Ads Removal

Popads.net is a website of an ad network that is also a big monetization platform. The website will distribute a bulk of advertisements and can redirect you to various websites, so it is considered as adware. Owners of such websites…

THREAT REMOVAL
stf-pcmethodsteadfastcloud-online-pc-method-stead-fast-cloud-fake-tech-support-scam-website-page

Remove PCmethodsteadfastcloud.online Scam

Pcmethodsteadfastcloud.online is a website that is related to a tech support scam and hosts it on its main page. The phone number +61-1800-737-431 is used for contacting the supposed support technicians. The scam tries to implement that your computer has…

THREAT REMOVAL
stf-locky-ransomware-virus-thor-thor-extension-ransom-note-html

.thor Files Virus – Remove Locky’s Latest Strain

A brand new strain of the Locky ransomware has been found overnight by malware researchers after the variant with the .shit extension had been discovered. The authors of the virus have decided to bring the Norse mythology theme back to…

THREAT REMOVAL
stf-bart-ransomware-perl-perl-locky-virus-decryptor-page-ransom-instructions

.perl Virus Removal – New Bart Ransomware

Bart ransomware has been discovered in the wild by the malware researcher Jakub Kroustek from Avast. The new string of malware encrypts files with the .perl extension. Seems identical to Locky ransomware in its note and payment instructions page. To…

THREAT REMOVAL
header-bitcoin-stforum

Remove .shit Files Virus (New Locky Ransomware)

The latest iteration of Locky ransomware is here. Files are encrypted with a new extension – .shit, but it is possible for other extensions to appear as well. The cryptovirus now uses HTML files (.hta) and brings back the usage…

THREAT REMOVAL
stf-lock93-ransomware-lock-93-virus-russian-ransomware-note

Remove Lock93 Ransomware and Decrypt .lock93 Files

Lock93 is a newly-emerged ransomware cryptovirus. The ransom note which is displayed after the file encryption process is complete can be written either in Russian or English. All encrypted files will have the extension .lock93 appended to them. The origin…

THREAT REMOVAL
stf-suppteam01-india-com-ransomware-virus-cryptolocker-crypto-locker-copycat-ransom-note

Remove Suppteam01@india.com Virus and Restore Your Files

Suppteam01@india.com is the name given to a cryptovirus that mimics the Cryptolocker ransomware. As it is not the first copycat and there are no other distinguishable characteristics for this virus except the email given as a contact detail, researchers named…

THREAT REMOVAL
stf-aviso-ransomware-crypt888-virus-mircop-brazil-ransom-note

Remove Aviso Ransomware (Crypt888) and Decrypt “Lock” Files

The Crypt888 ransomware cryptovirus is back and has a new variant called “Aviso”. The new variant targets users from Brazil, hence the ransom note is written in Portuguese. Aviso means “Warning” in Portuguese. The ransom note starts with that word…

THREAT REMOVAL
stf-internetspeedpilot-com-internet-speed-pilot-hijacker-redirect-saferbrowser-safer-main-website-page-download

Remove InternetSpeedPilot.com Redirect

InternetSpeedPilot.com is the web address for a browser hijacker named Internet Speed Pilot. The developers of the hijacker work for the company known as SaferBrowser. The company is famous for its browser hijacker applications. The undesirable software changes the new…

THREAT REMOVAL
stf-rotor-ransomware-cocoslim98-gmail-com-virus-ransom-message-small

Remove Rotor Virus (cocoslim98) and Restore .tar Files

Cocoslim98 is a newly emerged cryptovirus, which is called like that, because of the email that it leaves for contacting the criminals behind it. Malware researchers say that its real name is “Rotor”. The virus will encrypt files on a…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree