Help! Ransomware! Multiple drivers affected..

Page 1 of 2 12 LastLast

  1. Posts : 630
    Windows 10 Pro 64 bit
       #1

    Help! Ransomware! Multiple drivers affected..


    You would think that with more than 20 years experience I would have control. But No.. I`m cocky I know.. Here's were I stand. My system has 3 dedicated HDD. And The boot Drive is SSD. So. Me and the wife went out. And when we came back the desktop had changed. See Image. I opening this file you see and I`m thinking YA Shite! I made an image of my system a week ago so I shut my system down.. Disconnected all my HDD drives. Connected my HDD with the image of my system and booted up. I using Easeus Todo Backup and it ran flawlessly.. So I shut down and reconnected my other drives and booted up. What I found is that all the files no matter what the extension is are all changed to .DOCM. Except for the SSD boot drive.. For example see the image.. So the question! How to change all the file extensions on all 3 drive! I`m looking around myself.. HELP!
    Attached Thumbnails Attached Thumbnails Help! Ransomware! Multiple drivers affected..-untitled.png   Help! Ransomware! Multiple drivers affected..-docm.png   Help! Ransomware! Multiple drivers affected..-ssd-boot.png  
      My Computer


  2. Posts : 630
    Windows 10 Pro 64 bit
    Thread Starter
       #2

    You know! never mind. I have a TB drive with all my important data on it that`s on the shelf. My Main SSD OS is fine. so I`m cleaning off all that old useless data that I should have gotten rid of years ago anyway. My wife calls me a data hoarder and I have come to the conclusion that she is right. Time to start clean. Definitely getting better protection on my system from now on that`s for sure. This has been a wakeup call for me that`s for sure. It`s going to be fun starting from scratch. There's so much new stuff to find out there! I'll wait till tomorrow to see if someone may have a solution.

    I Ran:

    Avast
    Malware bytes
    Spy hunter

    Nothing came of it. I`ll check in the morning. If there`s no posting! I`m blowing it all away.
      My Computer


  3. Posts : 2,468
    Windows 7 Ultimate x64
       #3

    There isn't much doing right now, your system is already infected and your data probably compromised or destroyed. So the best advice is just the standard.

    Stop using the computer right now. Reformat it. Restore your data from backups.
    There is no other way to reaction to an infected system.
      My Computer


  4. Posts : 630
    Windows 10 Pro 64 bit
    Thread Starter
       #4

    Alejandro85 said:
    There isn't much doing right now, your system is already infected and your data probably compromised or destroyed. So the best advice is just the standard.

    Stop using the computer right now. Reformat it. Restore your data from backups.
    There is no other way to reaction to an infected system.
    As to my first post I restored an image form a week ago and the OS is up and running clean. I scanned the new image install with M-Bytes Spyhunter 5 and avast and came up clean. As for my other drives.. Just for fun I'm running decryption software on then right now. Data Recovery Pro is the first one. This tool is not free. I'm running it as an evaluation. If it can decrypt even one file I'll pay for it. If not.. I'll go for the next one on the list which is EmsiSoft Decryptor (Free) And if it works! Free is better. I tried the payed version first as it had the higher rating. And if nothing work... I'll miss my collection of many years. But I have had to start form scratch before from HDD death.. Anyway I'll keep this post updated as to any success or failure.
      My Computer


  5. Posts : 3,786
    win 8 32 bit
       #5

    Depending on the infections it may well jump to other devices on the network that's how it killed the NHS
      My Computer


  6. Posts : 2,468
    Windows 7 Ultimate x64
       #6

    Lance1 said:
    As to my first post I restored an image form a week ago and the OS is up and running clean. I scanned the new image install with M-Bytes Spyhunter 5 and avast and came up clean.
    That's not a reliable way to ensure your system is safe, as the image from that point could be as well infected too. You cannot tell for sure if the virus that caused havoc originally wasn't present at that point, you can only tell for sure that you haven't noticed it, which isn't the same.

    As for the antiviruses, they're not a reliable way of telling for sure that a system is virus-free. For one, they've already failed to stop the infection the first time, so I find difficult to believe that they'll catch it on a second chance, if it really is there.

    So my advice remains, the only safe choice at that point is a clean install. It's generally best practice not to take any chances against viruses, specially ransomware.
      My Computer


  7. Posts : 1,363
    Win7 pro x64
       #7

    1) Hope you get it worked out, wish I had some advice for you.
    2) This thread will be super helpful to a lot of people if after you get it worked out, you post what specifically you could have done to prevent it from happening.
      My Computer


  8. Posts : 630
    Windows 10 Pro 64 bit
    Thread Starter
       #8

    well that was a waste of time. That's a no go on the recovery. Other than that Image I also another TB drive with selected file backup from 2 or 3 weeks back. Redundancy... It's a good thing! I'm going to take Alejandro 85 advice and go completely clean on all drives. Thanks for everyone's input. I hope you don't take this as a cop out on my part. I just don't want this recurring. I'm glad I'm broke or I'd have a case of beer beside me right now. Well I might as well get to it.
      My Computer


  9. Posts : 22
    Win 7 Ultimate 64-bit
       #9

    Have you tried contacting the evil doers? They said they can decrypt one file for free. Worth the try!
      My Computer


  10. Posts : 3,786
    win 8 32 bit
       #10

    The encryption you have seems secure and no solutions yet a lot seem to be getting it GlobeImposter Ransomware Support (.Crypt & .PSCrypt ext - !back_files!.html ) - Ransomware Help & Tech Support
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:29.
Find Us