help virus 50$ all files encrypted

jasem

New member
Local time
1:35 AM
Messages
18
i have windows 7

all files ( music photo dada ........all) encrypted

this warning in folders

File Decryption costs ~ $ 50

In order to decrypt the files, you need to perform the following steps:
1. You should download and install this browser [removed by admin]
2. After installation, run the browser and enter the address: 4sfxctgp53imlvzk.onion
3. Follow the instructions on the web-site. We remind you that the sooner you do, the more chances are left to recover the files.


Guaranteed recovery is provided within 10 days.

please help me my data very important
 

My Computer

OS
09157460573
CPU
intel
Motherboard
nec
Memory
320maxtor
Graphics Card(s)
nvdia
Sound Card
jasemkadkhodaee
First off, please read this, and DO NOT DO ANYTHING THAT RANSOMWARE tells you to do. Late with your ransom payment? Never mind, CryptoLocker crooks will, er, give you a break ? The Register . I will try to look into a solution, but perhaps someone more knowledgeable can help while I search. You can try these things.

Step 1.
Start in safemode with networking and scan for malware. To do so you need to
Press and hold the F8 key as your computer restarts.Please keep in mind that you need to press the F8 key before the Windows start-up logo appears.
Note: With some computers, if you press and hold a key as the computer is booting you will get a stuck key message. If this occurs, instead of pressing and holding the “F8 key”, tap the “F8 key” continuously until you get the Advanced Boot Options screen.
On the Advanced Boot Options screen, use the arrow keys to highlight Safe Mode with Networking , and then press ENTER.

If your computer has started in Safe Mode with Networking, you’ll need to perform a system scan with Malwarebytes Anti-Malware and HitmanPro ( update these programs before you scan, in the safemode with networking )to remove the malicious files from your machine. If does not work, you can try reverting your machine to a previous state using the system restore utility. Once restored, go into safemode again with networking and repeat step 1.
 

Attachments

  • safemode.jpg
    safemode.jpg
    22.9 KB · Views: 76
  • system-restore.png
    system-restore.png
    16.8 KB · Views: 75

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Ultimate x64
CPU
FX 8350 @ 4.8ghz, turbo clocked to 5.4ghz
Motherboard
Asus Sabertooth FX990 Gen 3.0 R2.0
Memory
Mushkin Enhanced Blackline 16GB 1760mhz 10-10-9-24 T1
Graphics Card(s)
Gigabyte-660 Windforce OC- GPU Clock 1212MHz /3504MHz ram
Sound Card
Creative Sound Blaster Recon3D PCIe Sound Card
Monitor(s) Displays
Samsung SyncMaster S27B350H (HDMI)
Screen Resolution
1920x1080 60HZ
Hard Drives
1 x SSD Crucial M4 256GB (Primary OS)
3 x HDD WD 1TB
4 x HDD 2TB
1 x HDD 160GB (Secondary Backup OS)
Raid SATA III 6GB/s 4-port PCI-e Controller Card, Marvel 88SE9215 chipset
PSU
Chieftec-650-14CS (Modular) 80 Plus Gold-650 Watt
Case
Akasa Venom Toxic Gaming Big tower ( Custom Black ) Ver 2.0
Cooling
Water 2.0 PRO / GEIL Cyclone VRM / 6x120mm 2x220mm 2x140mm
Keyboard
Logitech G19
Mouse
Wireless Notebook Presenter Mouse 8000
Internet Speed
Fiber GBS
Antivirus
Don't Announce it to the world :)
Browser
Gotta have at least 1!
1st - disconnect from the internet.

There are a number of 'crypto' ransomwares out there. Depending on which one is on your system, your files might be safe. The newest versions actually encrypt files with a key only on their system.

The 1st step to clean up your box is to know what virus is on it.

CrankyPenguin gave you some tools to use that might identify the bug, but if you have screens showing waht you see, please post an image (use your phone or camera) thanks.

Read only - no action suggested: http://www.sophos.com/en-us/mediali...ers/SophosRansomwareFakeAntivirus.pdf?dl=true
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
jaseem,

Is the ransomware, by any chance called: CryptoLocker or CryptoLocker 2.0
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
An ol' eMachines
OS
Windows 7 Home Premium
Internet Speed
Fine for me...I'm retired!
hello

thanks my freind

i going to test
 

My Computer

OS
09157460573
CPU
intel
Motherboard
nec
Memory
320maxtor
Graphics Card(s)
nvdia
Sound Card
jasemkadkhodaee
When did you get infected? Do you have "restore points" prior to it? You know exactly which folders have ben encrypted?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
my system dont have restore point please help me
 

My Computer

OS
09157460573
CPU
intel
Motherboard
nec
Memory
320maxtor
Graphics Card(s)
nvdia
Sound Card
jasemkadkhodaee

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
my system dont have restore point please help me
Why did you disable that feature? If they had been made you could go back in time using option "previous version of folders and files". http://www.sevenforums.com/tutorials/85679-previous-versions-restore-files-folders.html

Do you have a good backup of the folders? Or a system image backup? I don't have the key to unencrypt the stuff..... only the criminals have.

not work

hello i deleted windows and installed new windows
help.
 
Last edited:

My Computer

OS
09157460573
CPU
intel
Motherboard
nec
Memory
320maxtor
Graphics Card(s)
nvdia
Sound Card
jasemkadkhodaee
my system dont have restore point please help me
Why did you disable that feature? If they had been made you could go back in time using option "previous version of folders and files". http://www.sevenforums.com/tutorials/85679-previous-versions-restore-files-folders.html

Do you have a good backup of the folders? Or a system image backup? I don't have the key to unencrypt the stuff..... only the criminals have.

not work

hello i deleted windows and installed new windows
help.
??????

So you reinstalled windows? Data files are still there? On another partition?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
my files in drive d and i formated drive c windows in drive c

my files in drive d but cant open encrypted
help
 

My Computer

OS
09157460573
CPU
intel
Motherboard
nec
Memory
320maxtor
Graphics Card(s)
nvdia
Sound Card
jasemkadkhodaee

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ACER ASPIRE 5742G
OS
Microsoft Windows 7 Home Premium 64-bits 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer Aspire 5742G
Memory
4,00 GB
Graphics Card(s)
ATI Mobility Radeon HD 5400 Series
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
WDC WD5000BEVT-22ZAT0
Back
Top