Centurion_Legion Ransomware

What is Centurion_Legion Ransomware?

Centurion_Legion Ransomware is a new threat that has been developed to obtain money from users. Specialists say that it is quite prevalent these days, so there is a chance that it will manage to sneak onto hundreds of different computers. If your computer is one of them, you will quickly notice that it is impossible to access the majority of important files. Unlike other ransomware infections that were popular some time ago, Centurion_Legion Ransomware not only encrypts pictures, documents, music, and other personal files, but also touches almost all .exe, .zip, and .lnk files. Fortunately, it leaves files that belong to the Windows OS (system files) unencrypted. This means that you will not need to start your computer in Safe Mode in order to remove Centurion_Legion Ransomware. Of course, we still cannot say that the removal of this computer infection will be easy because this ransomware is far from an ordinary program that has an uninstaller.testtesttest

What does Centurion_Legion Ransomware do?

Centurion_Legion Ransomware sneaks onto computers with an intention of obtaining money from innocent users. Of course, the owner of this threat knows that nobody will pay money voluntarily, so this ransomware has been programmed in such a way that it could encrypt files using a strong cipher. Once it finishes encrypting files stored on the computer, it immediately sets another picture as a Desktop background. It contains the following text:

Your data is encrypted!!!

To return the file to an email email

centurion_legion@aol.com

You will also find the .txt file How to decrypt your files.txt on Desktop with this text:

DECRYPT FILES EMAIL centurion_legion@aol.com

Yes you will have to contact cyber criminals by the provided email in order to unlock files. Each encrypted file will contain the extension {ID}.centurion_legion@aol.com.xtbl, for example, picture.jpg.id-B4500913.centurion_legion@aol.com.xtbl, so it will not be hard to recognize them. We know that you see that almost all your files are locked; however, specialists do not think that it is the best idea to waste time contacting cyber criminals because there is no doubt that you will get an answer saying that you have to pay a ransom to get the decryption key. It is unclear what the size of the ransom will be; however, we are sure that it will not be small. It is not worth transferring money for two reasons: a) cyber criminals might take your money and do not send the decryption key in return and b) Centurion_Legion Ransomware does not delete Shadow Volume Copies, so there might be a possibility to recover files free of charge. You will find more information about this method on the web.

Where does Centurion_Legion Ransomware come from?

Centurion_Legion Ransomware is very similar to Vegclass@aol.com and Saraswati Ransomware, so specialists working at anti-spyware-101.com do not find the fact that it is also spread as an attachment in spam emails surprising at all. Yes, Centurion_Legion Ransomware might pretend to be a good attachment, e.g. an important document or an invoice in order to fool users into downloading the attachment. If you have done that too, this explains why you have encountered Centurion_Legion Ransomware. Of course, this threat might find other ways to sneak onto computers too. If you can detect its main file {randomname}.exe in %APPDATA% and the new Value in HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, there is no doubt that this infection has sneaked onto your computer. Of course, you will also notice that all the files are locked and your Desktop wallpaper is changed.

How can I delete Centurion_Legion Ransomware

Even though Centurion_Legion Ransomware is a serious computer infection, we are sure that you will be able to remove it with the help of our security experts. All you need to do is to follow the step by step instructions that can be found below the article. Some users might not find these instructions helpful at all because they do not know anything about the deletion of malware and have no idea what Registry Editor is. Do not worry; if you are one of those users, you can eliminate Centurion_Legion Ransomware in an automatic way. You need to acquire SpyHunter ant then scan the system. This tool will eliminate all other infections from your computer as well.

Remove Centurion_Legion Ransomware manually

  1. Open the Windows Explorer (Win+E).
  2. Type %APPDATA% in the address bar and tap Enter.
  3. Remove the .exe file whose name consists of random letters.
  4. Go to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup.
  5. Remove these files: How to decrypt your files.jpg, How to decrypt your files.txt, and the .exe file with the random name.
  6. Remove How to decrypt your files.jpg from %UserProfile%.
  7. Delete How to decrypt your files.txt from Desktop.
  8. Tap Win + R.
  9. Type regedit.exe into the box and click OK.
  10. Go to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
  11. Find the Value with the random name, e.g. odgdgdem. Remove it.
  12. Move to HKEY_CURRENT_USER\Control Panel\Desktop.
  13. Delete the Wallpaper Value.
  14. Close the Registry Editor.
  15. Empty the recycle bin and restart the computer.
100% FREE spyware scan and
tested removal of Centurion_Legion Ransomware*
Disclaimer
Disclaimer

Leave a Comment

Enter the numbers in the box to the right *