Malware yjinlk it a ransonme ware

notanotherone

VIP Member
VIP Member
Joined
Oct 4, 2005
Messages
2,401
Reaction score
49
Location
landofnevernever
ok i was looking for igo8 maps and i downloaded what i thot was a new setup ,ive had to turn my computer off cause i dont know how to cure it ,ive run malwarebytes and a few 9thers but cant seem to get rid of it ,i keep getting this file in my pictures and other things ,it starts hell your files have been decryted ,to encrypt them send an email to .......... and so on and on ,it ends if your not prepared to pay dont send an email ,i assume its a ransomeware hack ? i tried a removal tool but didnt change anything i tried a system restore , also tried running malware bytes in safe mode it found nothing ,its mostly my pictures i cant see every time i open my photo files it has a document in there with 73i87a at the end ,and it also says ENCRYPTED ,yes i could wipe it but its my photos i want ,its affected 2 external hard drives he only problem is that the dam thing changed or corrupted my photos on my extrnal hard drives also all my music wont play ,on my photos side it says the file cant be opened it may be corrupted or changed and photo programe needs to be updated ,but its all up to date ,iit mite stil,be around ,i also tried trend micro wnd malware bytes , but they both found nothing after i ran combofix ,but i cant seem to run it on my external hard drives as its seems to be a command programme im so pissed off with this dam thing ts changed my pictures and all my music with this extention 73I87A File (.73i87A) ive run trend micro trend anit threat software and nothing has been found now ,done it on all my stuff ,just the extention files have been changed Ive tried panda security ,infraview ,trend micro ,malwarebytes i dont mind about the music but its the photus of my late mother and father and some of my grandaughter ohh i managed to get rid of with a lot of hard work
 
Switch off system restore because if you just do a restore it will still be in there
also must delete that last Restore before going in to safe mode
You must switch it off then boot in Safe mode and use Malwarebytes (PRO) do you have the Pro version?
 
If its ransomware, I've had it on several client machines and none of anti-virus or malwarebytes cured it for me. In may cases, it puts some files such as help_decrypt in the main folders and subfolders it affected. I had to right click on the folders and then use "restore to previous versions" to get the files back. Then removed all the help_decrypt (were 5-600 on on some pcs). Still good to run malwarebytes, ccleaner etc afterwards.
 
ok found about 95% of my pictures on an old iphone plus an ipod theres about 5% of important pictures i can find the music i can get back np but im going to have to live with that ,im thinking of doing a fresh install of both hdd and computer , question is there a way i can save my book marks from fire fox?
 
If the 5% cannot be saved why not open them up and take screen print of each one and save them?
Picture open it up
press Prt/Scr on your keyboard then open up Paint in windows and click Paste then you will see the picture
crop if needed and save as PNG or JPeg.
 
This virus generates a "key" during the encryption process and then sends it to the "hacksholes". If you pay them, you might receive a program and the key file to decrypt your files.

The only way to do it for free, is to have installed and running a packet sniffing tool when your pc sends the key to their servers, and do some modifications to it.

Fresh install is the only way for me, cause you never know if you gonna get a key back, and you're 100% sure that your computer is clean.

Had several issues with a few clients of mine. Good Luck!
 
So in order to learn from poor @notanotherone 's unfortunate experience, how best to prevent it from happening in the first place?
I know the obvious answer is only download s/w from known/trusted sources. But, as so many of us like to get our stuff from "other" sources is there a sure-fire way of making sure this won't happen?
I presume it isn't as easy as simply having anti-virus running.
 
Last edited by a moderator:
From my experience, most of our clients get infected with Ransomware via email attachments. The anti-virus software do not pick these up. Only thing I've found so far is opendns have a product that stops the ransomware from calling out to their servers and its that point it encrypts the files. Not really looked in to it any further.
 
So in order to learn from poor @notanotherone 's unfortunate experience, how best to prevent it from happening in the first place?
I know the obvious answer is only download s/w from known/trusted sources. But, as so many of us like to get our stuff from "other" sources is there a sure-fire way of making sure this won't happen?
I presume it isn't as easy as simply having anti-virus running.


Code:
You don't have permission to view the code content. Log in or register now.
 
ok guys done a freshj install ,.formatted all my hard drives as ,only problem now is ive lost all my folders and emails from mozzila thunderbirds,i did do a back up but i think i over wrote them lol
 
ok i found another hdd that wasnt connected and it had loads of back up files and pictures music and everything,ive lost about 12 pictures that are really important to me ,i have done a complete new build and wiped all the hdd
 
Back
Top