Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2016

How to remove BonziBuddy ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

The outcomes of BonziBuddy ransomware attack

Among the newly emerged ransomware threats, BonziBuddy virus might cause various associations. Despite its title, which is borrowed from famous interactive application distributed between 1999 and 2004, it is unwise to underestimate it. The PUP version, which spread under the Win32.adware-gen a few years ago, received attention as well. However, this cute virtual character did not cease to inspire cyber criminals. It disperses with the assistance of a trojan horse. Furthermore, evading it turns out to be a challenge. Fortunately, you can remove BonziBuddy if you employ a reliable application, such as FortectIntego. Since the ransomware spreads with an entire escort of malicious files, the elimination process should not be delayed. More explicit information about BonziBuddy removal is delivered below the article.

Pop culture, mythology, and political events spark cyber criminals’ imagination to give specific and peculiar names for the menacing file-encrypting malware. As the international virtual community still battled the latest version of Cerber and Thor, this name of this virus also originates from a popular application. This Windows assistant gained popularity in the turn of the millennium by guiding users throughout the web and their browsers. Unfortunately, the innocent image of purple gorilla was exploited for hackers’ misdeeds.

 The screenshot of BonziBuddy

According to the ransom message, the crooks are suspected to be a bunch of amateur hackers still making their way into the ransomware business. As a result, they did not perfect their creation. The ransom message is not elaborate as it only mocks victims by throwing offensive remarks. There is no indicated email address or explicit instructions to recover the files. What is more, they are unaffected as BonziBuddy malware does not employ standard AES-128 or RSA-1024 encryption techniques. In addition, the ransomware does not limit your access to the device. It might be similar to Smash! ransomware and zScreenLocker which did lock the screen but did not inflict bigger damage. However, its distribution method might cause concern for the members of the virtual community.

How do hackers disperse the malware?

The malware has been detected spreading via the following trojans:

  • JOKE_BONZITHREAT
  • Ransom-Joke.BonziBuddy
  • W32.Troj.Ransom.Filecoder!c
  • Win32.Trojan-Ransom.Filecoder.P@gen
  • Win32:Malware-gen

Therefore, this situation suggests that the initiators of BonziBuddy ransomware have huge potential to improve their viruses in the future. You should arm up with proper security tools to reduce the vulnerability of your operating system. Keep in mind that other ransomware viruses tend to spread via spam messages. The crooks have mastered the techniques how to forge realistic and persuasive fake FBI alerts or trial invitations, though usually the victims are bombarded with fake package delivery and invoice attachments. Recklessly reviewing them might activate BonziBuddy hijack or trigger the infiltration process of another virus. Regardless if the message addresses you directly, do not fall for such bait. Curiosity might cost you the personal data!

Elimination steps of the ransomware

Quickly and effectively eliminate BonziBuddy virus with the help of an anti-spyware application, such FortectIntego or MalwarebytesMalwarebytes. These tools will do all the necessary preparations and finish the removal process quickly. Therefore, you will do not need to go all the trouble to remove BonziBuddy from the device. After the virus is removed, you should check whether all your important files are unaffected. In case, you encounter BonziBuddy removal problems, scroll down to find the access regain instructions.

2 comments

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.