Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2018

How to remove Danger ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

Danger ransomware — a virus that is related to Scarab crypto-virus family

 Danger ransomware

Danger ransomware is a virus that locks your files and demands ransom[1]. The virus is related to Scarab ransomware which already has more than ten different variants discovered this year. This money-extortion virus family uses a combination of AES-256 and RSA-2048 encryption algorithm. During this procedure, the virus appends either  .fastrecovery@xmpp.jp, .fastsupport@xmpp.jp or .onlinesupport@airmail.ccfile extensions to make targeted images, documents, videos or archives useless for the victims unless they decide to pay authors of the ransomware for a specific data recovery tool.

Name Danger
Type Ransomware
Family Scarab 
Extension .fastrecovery@xmpp.jp, .fastsupport@xmpp.jp, .onlinesupport@airmail.cc
Ransom note “HOW TO RECOVER ENCRYPTED FILES-fastrecovery@xmpp.jp.TXT“ or “HOW TO RECOVER ENCRYPTED FILES-fastsupport@xmpp.jp.TXT”
Distribution Insecure spam email attachments
Danger level High. Can lead to permanent data or money loss
Decryption  Not available yet
Elimination  Best tool for ransomware removal is FortectIntego

Immediately after files has been changed, you could spot “HOW TO RECOVER ENCRYPTED FILES-fastrecovery@xmpp.jp.TXT“ or “HOW TO RECOVER ENCRYPTED FILES-fastsupport@xmpp.jp.TXT” text files on your computer. Virus places copies of these in every existing folder. This is the ransom notes where authors of Scarab-Danger ransomware put the most important information:

Danger: Our contacts change every 3 days, do not hesitate, contact us immediately. Then we will not be available. 
Attention: if you do not have money then you do not need to write to us! 
The file is encrypted with the RSA-2048 algorithm, only we can decrypt the file . 
================================================= 
the Jabber : fastsupport@xmpp.jp 
the If you do not have a jabber. The write us to the To register to: hxxps://www.xmpp.jp 

As you can see in the ransom message quoted above, the Danger virus developers change their contact information every three days and this is why victims should not hesitate and contact these cybercriminals quickly. Currently known addresses used for the communication with victims are fastrecovery@xmpp.jp and fastsupport@xmpp.jp. However, in the near future, the list of contact email addresses should expand.

Contacting cybercriminals[2] is not recommended because they need only your money and file decryption might be only alleged and barely possible. Specialists at Virusai.lt[3] notes that often these people disappear and ignore their victims after the ransom payment is done. You'd better remove Scarab-Danger ransomware from your computer before it is too late.

Often ransomware developers display little information about the ransom but ask for the specific amount in cryptocurrencies. These criminals are not beating around the bush and stating that people without money do not need to contact them and that they want to get their payment to Jabber account. This only gives more evidence that authors of Danger ransomware virus do not care about victims and are not willing to help each of them.

Therefore, there's no need to trust people who created this malicious program. Even though the official decryptor is not available yet, malware researchers are working on it. Meanwhile, you should get rid of the virus and try alternative recovery methods. However, if you have data backups, you do not need to worry about anything. Though, before file recovery, you need to clean your PC.

Danger ransomware removal should be done with professional help and all the seriousness in mind. This is not just an intrusive program, this is a malicious virus that contains various harmful pieces. Anti-malware tools like FortectIntego can do a proper full system scan and get rid of ransomware related applications and tools.Danger ransomware virus

Multiple malware spreading ways include spam email attachments

Ransomware viruses can spread in various ways, such as:

  • fake software or tool updates;
  • malicious spam email attachments;
  • breaking through RDP unprotected configuration;
  • freeware bundles;
  • trojan viruses;
  • web injects;
  • fraudulent downloads.

The most common is a spam email. They often contain attachments that could be filled with macro viruses and those little things spread ransomware onto your computer. Also, these letters may look safe and legitimate because of the known company names on the addresses or email itself. The same trick is used with the attachments. Even though they are compromised, they still look as safe Word or another popular document.

This is the main fact that you need to pay attention while browsing throughout your email boxes. Opening and possibly purchasing anything from those attachments can lead to cyber infections or even ransomware attacks. You need to be aware of these threats behind every suspicious site or email. Caution and knowledge are critical here.

Get rid of Scarab-Danger ransomware as soon as possible and avoid more significant harm

To remove Danger ransomware from your computer entirely you should use certified and trustworthy tools or programs like FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. This option in virus elimination can ensure you are deleting all of the remains that might be with this virus. Ransomware is malicious and harmful, but also there is a possibility that they contain other tools or programs.

Those programs can do more damage to your system than the ransomware itself. The more time you give for, the more access they can gain. Scarab-Danger ransomware removal is vital to do quickly and correctly so you can avoid any repetition in the future. We have a step-by-step guide below for better explanation and virus removal.

However, we do not recommend to focus on file decryption until you double-checked your system is clean. Only then you can insert an external backup and recover your data. Because you plug in any device to the insecure system, your files could be corrupted again, and this means you lose your data permanently.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.