Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jun 2017

How to remove VINDOWS DEFENDOR ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

VINDOWS DEFENDOR prank related to Levis ransomware enables actual data encryption

VINDOWS DEFENDOR virus

VINDOWS DEFENDOR virus is a new screenlocker [1] parasite which suspends users from accessing data stored on the infected computer. This parasite doubles both as an encryption and lockscreen ransomware.

It has a basic encryption mechanism which renders victim’s documents, pictures, video/audio files, archives and other data unreadable. It is most likely that the infection uses RSA and AES ciphering to achieve data encryption.

If you got infected and want to learn more about VINDOWS DEFENDOR removal, please continue reading through this article or initiate the elimination immediately by launching FortectIntego or similar malware detection utility.

This cyber is clearly related to another previously released ransomware called Levis Locker which uses the same ransom note style and also demands all the ransom payments to be sent to Levis. Nevertheless, VINDOWS DEFENDOR appears to be a few steps further than its initial version which was merely a scareware [2] and did not actually affect the files in any way.

Luckily, the new improvements to the virus code did not have any impact to the amount of ransom that the criminals demand for the data decryption. Just like in the Levis version, it is still 500 dollars and must be paid in Bitcoin using MoneyPak code. Below you can see a full transcript of the ransom note:

VINDOWS DEFENDOR
Your dextop have Been locked due to a Following ilegal activitys on line:
Gay Porn
Scamming
Bestiality
Rape
DO NOT TURN OFF COMPUTER OR YOU LOSE FILES
You Must Pay $500 to “Levis”
YOUR COMPUTER WILL BE DELETED FROM:
23:59:43

There is no doubt that the virus was created as a joke or a tool of revenge, because it is highly unlikely that anyone would take things implied in the note seriously. The harsh grammar and spelling mistakes should also be an incitement to remove VINDOWS DEFENDOR rather than give your money away to the unpredictable cyber criminals.

Image of VINDOWS DEFENDOR virus

Spreading of the infectious executable

While ransomware giants such as Locky or Cerber employ major botnets and spam campaigns to spread their malicious files around, less sophisticated parasites such as VINDOWS DEFENDOR are sticking to simpler and less automated distribution techniques. Their infectious components may reach victims’ computers via Peer-2-Peer file sharing networks, unsafe websites or fake software update notifications. Be careful, as you may also find a disguised virus executable inside your email inbox.

Taking all the different ways VINDOWS DEFENDOR may reach your PC into account, we should emphasize that it is necessary to keep backup copies of your files just to be safe from losing them in case the file-locking parasite slips into your system.

Strategies you can choose for VINDOWS DEFENDOR removal

Considering the fact that the malware you are dealing with is a file encrypting virus which endangers your files and may corrupt them entirely, you should be especially careful when performing VINDOWS DEFENDOR removal.
Manual ransomware elimination will barely bring you anticipated results. It will most likey be more damaging than beneficial to your computer, thus you should better let the anti-malware tools to remove VINDOWS DEFENDOR instead.

Professional computer security software vendors know what they are doing and they will make sure your PC is wiped of any dangerous components and is safe to use as well as store your future data.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.