Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2017

How to remove Panda ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

Developers of Panda ransomware virus set the size of the ransom individually

Panda ransom note

Panda ransomware is a variant of Globe Imposter[1] malware that appends .PANDA file extension to targeted files. Following data encryption, the malware creates a how_to_back_files.html file with data recovery instructions. First victims of ransomware are reported to be from Germany.[2]

In the ransom note, crooks ask victims to send one encrypted file and unique ID number to greenpeace_wtf@aol.com or greenpeace_28@india.com. Authors of Panda virus will respond with a decrypted file and tell how much money people have to pay for data recovery. Once they receive a payment, victims are supposed to get a decryption software:

After we send you instruction how to pay for decrypt and after payment you will receive a decryptor and instructions We can decrypt one file in quality the evidence that we have the decoder.

However, security experts warn that this “guarantee” might be a hoax to make people pay the ransom. The purpose of Panda malware is the same as any other crypto-virus – to swindle the money from computer users. Thus, once criminals get what they want, they might leave users with nothing.

After ransomware attack, it’s recommended to focus keeping the system safe instead of trying to getting back your files. Thus, your primary task should be Panda removal. Elimination of file-encrypting virus won’t remove .PANDA extension, meaning files remain inaccessible. However, if you have backups, you should not worry about it.

Additionally, you can try third-party software to restore data. However, Panda ransomware is not a decryptable virus, so chances to recover all corrupted images, documents, and other files are not high. However, negotiating with criminals or keeping malware installed on the computer might cause you more problems because:

  • criminals might blackmail you and threaten into paying more Bitcoins once the ransom is paid;
  • malware might install additional harmful files or open the backdoor;
  • the virus modifies Windows Registry and injects malicious code into legit system process;
  • the computer becomes vulnerable, slow and unable to use normally because all new files will be encrypted as well;
  • developers might install other malicious programs, including spyware and track sensitive information about users.

Therefore, infiltration of crypto-malware damages not only files but the system as well. For this reason, users are advised to remove Panda ransomware virus from the device immediately using reputable malware removal software, such as FortectIntego.

Image of Panda ransomware virus

Attackers spread malicious program via different channels

In order to reach as many potential victims as possible, criminals have to employ several distribution strategies. However, most of the time they remain the same: malspam, malvertising, bogus updates, and downloads, exploit kits.

During the past years, the most popular distribution method was malicious spam emails with infected attachments.[3] It goes without saying that Panda virus is most likely enter the system from the malicious Word, PDF or ZIP file. Security experts suggest being vigilant and not trusting emails that appear in the inbox.

Additionally, keeping away from suspicious pop-ups, file-sharing domains or P2P networks, high-risk websites also helps to decrease the risk of the attack. Finally, keeping system updated, installing reputable antivirus and creating backups is also recommended.

Termination guide of the .PANDA virus

Ransomware-type cyber threats are complicated, and victims should not try to get rid of them manually. As we have mentioned in the beginning, malware consists of numerous harmful files and might affect the system. Therefore, it’s important to remove Panda entirely without causing more damage.

In order to achieve this goal and succeed in Panda removal, victims have to employ reputable anti-virus or anti-malware software, such as FortectIntego or MalwarebytesMalwarebytes. If you cannot install, update or run the tool, you should follow the guide below that will help to enable automatic elimination.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.