A ransomware recovery routine from Sevenforums

loninappleton

New member
Member
VIP
Local time
10:17 AM
Messages
892
Is there a ransom ware routine at Sevenforums?

I keep a backup disk and simply changed one out when it happened today.
But there was an audio message and some other screen telling me all the nasty things
they wanted to do to me.

The message returned at reboot and the whole system seemed captured and unsable. I wiped the disk with my backup as a clone job.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Ultimate
CPU
AMD Athlon II x3 450
Motherboard
MSI 880GM
Memory
2 GB
Hard Drives
various
Browser
Firefox, Opera
There is a forum concerning ransomware within BleepingComputers.com -- I recommend trying there. If you do, simply acknowledge in this thread that you are "moving" the problem over into bleepingcomputer.com :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Antec desktop; Acer Aspire laptops
OS
Windows 7 Professional 64-bit
CPU
Desktop i5; Acers i5 & i7
Memory
desktop 16GB; 1 Acer 8GB & 1 Acer 16GB
Hard Drives
1TB split into 2 equal partitions [OS and data] usable by RJS
Internet Speed
AT&T DSL
Browser
FF, GChrome, msIE
Other Info
Windows 7 Firewall, Emsisoft AM/AV, MSE [scan-only], SpywareBlaster, Ruiware/BillP combine
Just to add to Roland's suggestion - Bleeping computer provide a totally free service which is highly tailored to a particular system, because of this please join and post asking for help with your issue. They will provide a solution for this issue only, not a "catchall" for all issue. Never follow instuctions given for another user's issue, even if it seems identical to your own, as this may lead to other major issues

They do of course have forum threads where recommended system usage policy is discussed and these areas may be most useful for planning how you go forward from here
 

My Computers My Computers

System One System Two

  • Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
Hi,
More information might be nice
What security do you use is the first basic information plus what have you ever used ?
Where do you download stuff from and what is the last items you've downloaded ?

Scanners are a dime a dozen adwcleaner/ malwarebytes/... are usually the first couple to try.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
That's a good suggestion. I'm joined at Bleeping already from other questions and they are a trusted site. It sounds like the only answer to this system takeover is one of those multiple step cleaning processes.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Ultimate
CPU
AMD Athlon II x3 450
Motherboard
MSI 880GM
Memory
2 GB
Hard Drives
various
Browser
Firefox, Opera
While viri and malware and spyware can very effectively be addressed and worked through between thread-starters and the many very fine techies in sevenforums, when I read ransomware, I knew that BC has one of the best ransomware forums found anywhere.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Antec desktop; Acer Aspire laptops
OS
Windows 7 Professional 64-bit
CPU
Desktop i5; Acers i5 & i7
Memory
desktop 16GB; 1 Acer 8GB & 1 Acer 16GB
Hard Drives
1TB split into 2 equal partitions [OS and data] usable by RJS
Internet Speed
AT&T DSL
Browser
FF, GChrome, msIE
Other Info
Windows 7 Firewall, Emsisoft AM/AV, MSE [scan-only], SpywareBlaster, Ruiware/BillP combine
What is the specific Bleeping thread or is there one? I don't have nor can even use
an individual HD analysis since it's wiped.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Ultimate
CPU
AMD Athlon II x3 450
Motherboard
MSI 880GM
Memory
2 GB
Hard Drives
various
Browser
Firefox, Opera
Hi:

Bleepingcomputer has an entire sub-forum -- "Ransomware Help & Tech Support" -- devoted to ransomware.
The landscape changes daily, with new ransomware variants, new decryption methods, etc.
It's a highly complicated, specialized area of computer security and malware cleanup/mitigation.

A few general points -- for all intents and purposes, as a general explanation, your encrypted files are "toast", UNLESS:

  • A decryption solution is devised or published; OR
  • You have data backups on another, separate drive/device that was not encrypted; OR
  • You pay the ransom.
The malware/ransomware usually removes itself from the affected machine once it has done its work. So, there is usually not much specific cleanup to do for the ransomware itself. However, it's possible that the other system may have other malware on it, too.

As such, it's probably worth seeking out expert, guided help with checking/cleaning the affected system.
But, depending on the particular ransomware variant, it may not be possible to recover the encrypted files at this time. Unless you have backup copies of the data files, they are pretty much "gone".

Some experts have recommended the following:

  • Copying the affected, encrypted files to a separate USB EHD and holding that drive for a possible future decryption solution that may allow them to be recovered some time in the future; AND/OR
  • Removing and saving the entire affected hard drive and replacing it with a brand new drive, new Windows install, etc. (you can hold the old drive for a possible future decryption solution, as mentioned above).
Needless to say, practicing safe computing practices in order to minimize the risk of ransomware infection in the first place is the best strategy.


HTH,
MM
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Studio XPS 8500
OS
OEM Windows 7 Ult (x64) SP1
CPU
Intel Core-i7 3770 @ 3.4 GHz
Motherboard
"Dell" branded
Memory
16 GB DDR3 SDRAM @ 1333 MHz
Graphics Card(s)
NVidia GeForce GT620 1 GB
Sound Card
THX TruStudio PC
Monitor(s) Displays
Dell U2410 Full HD
Hard Drives
2.0 TB SATA2 @ 7200 RPM
PSU
350W
Keyboard
MS 4000 Ergon - Wired
Mouse
Logitech Anywhere MX
Internet Speed
Cable HSI w/Turbo (router)
Antivirus
KIS-MBAM Premium-MBAE Premium
Browser
Fx (current version); IE
Other Info
And a Win7/64 Pro laptop; And a Win10/64 Pro desktop.
On your last point about buying a new drive. Is it not enough to clone a drive from backup?

In the past I have used HDD Guru's programs for disk setup and utility.

I know of no better disk tools for refreshing a drive.

HDDGURU: Software: HDD diagnostics and recovery

And a thought occurred to me about SSD's. How is an SSD effected differently if at all from a ransom ware attack?

Also I did take a peek at Bleeping Computer. The ransom ware list is dauntingly long.


As to the source of the ransom ware it was in the process of simply clicking on a news item at a site. It's possible that news is submitted without careful scrutiny.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Ultimate
CPU
AMD Athlon II x3 450
Motherboard
MSI 880GM
Memory
2 GB
Hard Drives
various
Browser
Firefox, Opera
Hi,
A lot of website are not monitored very well if at all except to add more content
Yahoo is a good example they didn't even monitor their own adds for corruption
email servers were always getting hacked....

If you ever click on a link it's always best to right click it and select open in new in-private window to minimize anything
But it's really up to your security to block attacks.
Panda free and mbam premium works well together that I've noticed :)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
Opening in a separate window is a good tip though I don't know exactly what it accomplishes that is different. Plus it'd be hard to remember if not ingrained in my fingers.

If ransom ware only targets encrypted files, what if I am using no encryption tweaks? I don't and never have. I'm also lax on security as I find that less is better. I know that is contrarian, but the suspicion remains for me over the years, as with the Yahoo you mentioned, that any program monitoring of activity
can work both ways. I actively use Malwarebytes Anti Exploit-free version.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Ultimate
CPU
AMD Athlon II x3 450
Motherboard
MSI 880GM
Memory
2 GB
Hard Drives
various
Browser
Firefox, Opera
Back
Top