After successful infiltration, the SafeFinder potentially unwanted application modifies users’ Internet browser settings by assigning the homepage and default search engine fields to Search-document.com All encrypt victims’ files and make ransom demands. As with Search-document.com, applications protected], [email In fact, these false claims are merely attempts to trick users to install. is promoted as a ‘bundle’ with regular software. After infiltration on browsers (Internet Explorer, Google Chrome, and Mozilla Firefox), Search-document.com tracks users’ Internet browsing activity. Search-document.com is a deceptive application identical to PlayLunar, FunOnlinePlay, Froovr, and many others. Files encrypted by this ransomware continue to get the .encrypted extension. The ransomware window contains a timer of 60 minutes, which indicates the time until the next file deletion. In fact, all are designed only to generate revenue for the developers.