Important files came under attack by ransomware. They are encrypted.

ykcud

New member
Local time
10:28 AM
Messages
5
Original post below:
------------------------------------------------------------------------------------------
I was using google chrome and none of the pages were loading correctly (including settings). This made me think I needed to do an immediate virus scan. On doing so it detected "ransonware", which I am uneducated about (no longer the case, I have used other browsers since this incident to educate myself). I found a few moments later that many of my documents, movies, ect were encrypted. I figured I would do a restore to a previous addition, but my virus removal program erased any such thing for the whole computer including for the documents as far as I can tell. I used shadow explorer and it does not show ANY file back ups for anything.

These documents are VERY important. I can not stress this enough. And as I can not seem to find a viable solution online, I am left on my own ideas to recover these files.

I am desperately asking the community here for two things:

Is there a program I can use that can potentially break the code for these encrypted files? I do not care if I have to wait a month or more before said program is successful.

Any other solutions that I may have over looked?
-----------------------------------------------------------------------
End of original post.

Thank you all for your offer of help. I have solved the issue by doing some research immediately after my last post yesterday. This method may or may not work for everyone, but if you have some files that are important that are encrypted, give what I did a try:

The way I did it was using a website to identify the ransomware (I used "https://id-ransomware.malwarehunterteam.com/identify.php").

Follow the sites instructions and if done correctly, it should be able to identify exactly what is that has encrypted you files (note that what is in the notepads or however the infection leaves its ransom (granted it does so) can be intentionally misleading.)

If there is a current known means of decrypting the files with said infection, the site should let you know of how to do so. This usually (if not, always) will be via a program. Follow the instructions of the site and of the installation procedure.

From this point onward, it may differ if you are not using "Rannohdecryptor" as was recommended by the website. Although, it may be similar. If so, keep following instructions below:

Make sure you have at least 45% of your :C (Hard Drive) empty. If the program is successful, it may not delete the encryted files, but rather make a duplicate of them that is decrypted.

After installing the program, click on "Scan" (or its equivalent). You will need to open both an encrypted file as well as a duplicate of said file that is not encrypted. (if you do not have a file(s) that has both an encrypted and non encrypted version, see the end of this post, after the dotted line.) It will identify if it is able to decrypt your files.

For the sake of the explanation, I will assume that the program says it is able to decrypt your files. If not, dont give up! If there is a will there is a way! Keep at it, doing research or what not. Do not give in to these cyber crooks. Waiting until there is a known way to decrypt your files IS an option, and there will be for all given enough time. (Sorry for going off topic) Allow it to do its thing (decrypt your files that is). This process is just like a typical virus scan; it checks every file and will take some time (in my case over two hours and it could take longer for you, so please be patient).

After it has completed, allow the program some extra (as I have learned) to finish its job. It will not say this, but I recommend it (I have a few left over video files that were not yet decrytped in a folder where some are).

Double to check to make sure the files are decrypted, and then celebrate.

Give the finger to the cyber criminals by spreading the message.

---------------------------------------------------------------------

A note for those that do not have duplicates of files. There is a chance that perhaps you may have an open document or simular that is still open. If so, save it (with the same as the crypted file, sans the "crypted" part of course). Another option is to look online for a video/music/game or other media that you can get redily online that you already had. For instance I had a Youtube video I made a few years ago that I forgot about. I had a copy of it on my computer that was downloaded then encrypted. I then redownloaded it; voila!

Another example is if you burned a dvd to your computer that became encrypted. Use the same software you used before (redownload it online if you need to) and burn it again. The same can of course be done with music CDs. You may even have an mp3 or other music player with some files.

what I am getting at, is give it some thought and you may have a duplicate file of something hanging around somewhere.
 
Last edited:

My Computer My Computer

At a glance

Windows 7 64bit
Computer type
PC/Desktop
OS
Windows 7 64bit

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
The ransomware was acquired via a torrent. I hope this little tidbit here will give more info than I can. It is in every folder that has encrypted files in it:
 
Last edited by a moderator:

My Computer My Computer

At a glance

Windows 7 64bit
Computer type
PC/Desktop
OS
Windows 7 64bit
Last edited:

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
Wow! That is odd. I actually did use malware bytes before I uploaded that (and it was updated prior to use). I am going to copy the text of the file into a new notepad. I also happen to have a document that was open when the virus hit, and while the original was encrypted, I was able to save the current one. I am going to upload them both, hoping that maybe having duplicates of the same file, one normal and the other encrypted will shed some light. I use open office by the way.

This being said, make sure to scan my files before opening them.

I am now downloading spybot search and destroy as I speak and immediately going to use it to do a scan.

(The site is not letting me upload the two document files. It is giving me an error saying that it does not recognize the format (I use open office). Is there a safe alternative I can use instead?)
 

My Computer My Computer

At a glance

Windows 7 64bit
Computer type
PC/Desktop
OS
Windows 7 64bit
That file is still infected. Please do as I asked and paste the contents into your post. Also which program did I point you to? Sybot S&D isn't a full antimalware program.
 

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
I will rescan everything with malwarebytes and post the history tomorrow. My time on the internet is limited and by the time the scan is complete I wont be somewhere I can post anything today. Is there anything else that you asked that I have missed?

I also read somewhere that what is said that the virus used to encrypt in said notepads may be misleading. (which is part of the reason why I want to upload the documents).
 

My Computer My Computer

At a glance

Windows 7 64bit
Computer type
PC/Desktop
OS
Windows 7 64bit
Well you wanted me to look at a document however it is infected so I'll only look at it if you copy and paste the contents. From what I saw on google it seems that some ransomware only had a few encryption algorithms since identified by certain security companies (which I posted the links for) however until you determine what the infection was there really isn't any way to decrypt the files since the decryption programs (if any) are based on the virus. Using a brute force attack against an encrypted file can take months to even years depending upon the encryption strength.
 

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
I also read somewhere that what is said that the virus used to encrypt in said notepads may be misleading. (which is part of the reason why I want to upload the documents).

It may or may not be, but it is getting flagged so uploading those documents is not an option.

We can't allow that to be posted, it's just not safe and we have to err on the side of caution.
 

My Computer My Computer

At a glance

Win 10 Pro x64Intel I5-2500K @3.3GHz16GB G.Skill Ripjaws X (4x4GB)EVGA GeForce 750 Ti SC 2GB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
We don't want to risk our own systems by opening up that file. You can easily post the contents of the file without posting the file.
 

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
I figured I would do a restore to a previous addition, but my virus removal program erased any such thing for the whole computer including for the documents as far as I can tell. I used shadow explorer and it does not show ANY file back ups for anything.

These documents are VERY important. I can not stress this enough. And as I can not seem to find a viable solution online, I am left on my own ideas to recover these files.

Reading your post several times, thinking this through, I think there's nothing much you can do.

To start with, a system restore would not help you in any way. System restore restores the Windows system and installed programs as they were at the moment of creating the restore point but leaves all your personal files intact. That's the whole idea of system restore, restoring Windows system but not touching your documents, videos, music and so on. If a document is encrypted when restoring the system, it will be encrypted also after the restore.

Paying the criminals to get files decrypted is not a good idea; you can see by searching information about this that in most cases even after people have paid for it, the decryption does not work as hoped and in some cases a payment results no decryption at all. They'll take your money but that's it.

Your only options, as far as I can tell and recommend are to either restore a full system image containing all hard disks, or a clean install wiping all disks.

The ransomware was acquired via a torrent.

Again a good example about the dangers in piracy! Of course I know there are some also valid, legal torrents but as we all know most of torrenting is piracy. How can you expect criminals stealing copyright protected content and distributing it through torrents to other criminals to do nothing else criminal, like adding nasty surprises to their torrents?

Kari
 
Last edited:

My Computer My Computer

At a glance

Windows 10 Pro x64 EN-GB1.6 GHz Intel Core i7-720QM Processor6 GBATI Mobility Radeon HD 5850 Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
HP ENVY 17-1150eg
OS
Windows 10 Pro x64 EN-GB
CPU
1.6 GHz Intel Core i7-720QM Processor
Memory
6 GB
Graphics Card(s)
ATI Mobility Radeon HD 5850 Graphics
Sound Card
Beats sound system with integrated subwoofer
Monitor(s) Displays
17" laptop display, 22" LED and 32" Full HD TV through HDMI
Screen Resolution
1600*900 (1), 1920*1080 (2&3)
Hard Drives
Internal: 2 x 500 GB SATA Hard Disk Drive 7200 rpm
External: 2TB for backups, 3TB USB3 network drive for media
Cooling
As Envy runs a bit warm, I have it on a Cooler Master pad
Keyboard
Logitech diNovo Media Desktop Laser (bluetooth)
Mouse
Logitech Performance Mouse MX
Internet Speed
50/10 Mbps VDSL
Antivirus
Windows Defender 4.3.9431.0
Browser
Maxthon 3.5.2., IE11
Performing a google search I did find some decryption programs by companies like Kaspersky however those are dependent upon knowing the specific virus. It appears that for some of the viruses a list of the decryption keys has been compiled. Without knowing the virus we could try some of them however like with using brute force tactics the decryption attempts would likely fail. I agree that paying off the hijackers would be risky and possibly fruitless but I think I read an article once stating that according to the FBI users should pay up if the data is that important to them. However he has removed the program so that isn't possible. I agree that the system should be wiped and we consider this a lesson learned about backing up data especially if the information is important enough. If the OP's data is that important perhaps he should hire a security expert to work on the system because there is only so much we can do and almost nothing without knowing which virus he was hit with. Can we agree that there isn't really anything else that we can do? All I know to say is for him to figure out which virus he was hit with and google it or take his system to a specialist.
 

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
If I had to fix this troubled computer, I would completely wipe everything.
Then I would do a clean install and update of Windows 7. At that point I would make a image using Macrium.
Then I would install my needed and wanted programs. I would not install any torrent programs.
Then when everything was working properly I would make another Macrium image. All images would be on a external drives.

The next step is the hard one.
I would try to explain to the owner of the computer the do's and don't of computer security.
How well that works will very. I have had some people that refuse to learn and comply. Oh well.

Then I would make a list of programs I use and trust and hand to the owner of the computer and then remind him/her that if questions come up; this forum is open 24/7/365.
Asking for help before one makes a boo boo is always best.

**When I use to fix friends computers this was my methods.**
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.

My Computer My Computer

At a glance

W7 home premium 32bit/W7HP 64bit/w10 tp insid...E5300 dual core3gbNvidia Geforce 7100 Nforce 630i
Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Hi.
Until you determine what particular ransomware hit you, there's not much anyone can do. Some have had decryptors released, some are defeat-able by running a recovery program to grab the original deleted files. Still others, can be defeated by using Shadow Copy. Some have no resolution, and the best thing to do is save a copy of your encrypted data in the hopes that something breaks in the future (Yes, it does happen).
Just my 2-cents.
 

My Computer My Computer

At a glance

W7 64bit
Computer type
PC/Desktop
OS
W7 64bit
Thank you all for your offer of help. I have solved the issue by doing some research immediately after my last post yesterday. This method may or may not work for everyone, but if you have some files that are important that are encrypted, give what I did a try:

The way I did it was using a website to identify the ransomware (I used "https://id-ransomware.malwarehunterteam.com/identify.php").

Follow the sites instructions and if done correctly, it should be able to identify exactly what is that has encrypted you files (note that what is in the notepads or however the infection leaves its ransom (granted it does so) can be intentionally misleading.)

If there is a current known means of decrypting the files with said infection, the site should let you know of how to do so. This usually (if not, always) will be via a program. Follow the instructions of the site and of the installation procedure.

From this point onward, it may differ if you are not using "Rannohdecryptor" as was recommended by the website. Although, it may be similar. If so, keep following instructions below:

Make sure you have at least 45% of your :C (Hard Drive) empty. If the program is successful, it may not delete the encryted files, but rather make a duplicate of them that is decrypted.

After installing the program, click on "Scan" (or its equivalent). You will need to open both an encrypted file as well as a duplicate of said file that is not encrypted. (if you do not have a file(s) that has both an encrypted and non encrypted version, see the end of this post, after the dotted line.) It will identify if it is able to decrypt your files.

For the sake of the explanation, I will assume that the program says it is able to decrypt your files. If not, dont give up! If there is a will there is a way! Keep at it, doing research or what not. Do not give in to these cyber crooks. Waiting until there is a known way to decrypt your files IS an option, and there will be for all given enough time. (Sorry for going off topic) Allow it to do its thing (decrypt your files that is). This process is just like a typical virus scan; it checks every file and will take some time (in my case over two hours and it could take longer for you, so please be patient).

After it has completed, allow the program some extra (as I have learned) to finish its job. It will not say this, but I recommend it (I have a few left over video files that were not yet decrytped in a folder where some are).

Double to check to make sure the files are decrypted, and then celebrate.

Give the finger to the cyber criminals by spreading the message.

---------------------------------------------------------------------

A note for those that do not have duplicates of files. There is a chance that perhaps you may have an open document or simular that is still open. If so, save it (with the same as the crypted file, sans the "crypted" part of course). Another option is to look online for a video/music/game or other media that you can get redily online that you already had. For instance I had a Youtube video I made a few years ago that I forgot about. I had a copy of it on my computer that was downloaded then encrypted. I then redownloaded it; voila!

Another example is if you burned a dvd to your computer that became encrypted. Use the same software you used before (redownload it online if you need to) and burn it again. The same can of course be done with music CDs. You may even have an mp3 or other music player with some files.

what I am getting at, is give it some thought and you may have a duplicate file of something hanging around somewhere.
 

My Computer My Computer

At a glance

Windows 7 64bit
Computer type
PC/Desktop
OS
Windows 7 64bit
Hmm for my two cents worth I would have given this a go and there others by Bitdefender etc but I usually head for this one and because it runs in a non Windows environment makes it all the better

Kaspersky Rescue Disk 10
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Hmm for my two cents worth I would have given this a go and there others by Bitdefender etc but I usually head for this one and because it runs in a non Windows environment makes it all the better

Kaspersky Rescue Disk 10
Those are useless for this problem - all they do is scan for malware. By then, its already too late.
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Agreed. In the case of ransomware the problem isn't over when the virus is removed. The OP had reportedly removed the ransomware already using his AV but that still left the files encrypted. It is a truly horrible virus to get because of the real possibility of losing data which is yet another reason why users should be taking good regular backups on an external drive that isn't usually connected to their pc. The developers seem to be really good with scare tactics as well.
 

My Computers My Computers

  • At a glance

    Windows 7 pro/Windows 10 ProIntel i7 860 Quad core 2.8 ghz8 gbATI Radeon HD 5770 1 gb ram
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    HP Pavillion Elite HPE-250f
    OS
    Windows 7 pro/Windows 10 Pro
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF & Viewsonic
    Screen Resolution
    1920 x1080 & 1680x1050
    Hard Drives
    WD blue 1 tb & 500 gb.
    Browser
    FF of course.
    Other Info
    https://www.bestbuy.com/site/hp-pavilion-elite-desktop-intel-core-i7-processor-8gb-memory-1tb-hard-drive/9921493.p?skuId=9921493
  • At a glance

    Windows 2012 R2 Data center/Linux Minti3 9100 3.6GHz, 8M cache, 4C/4T8GB 2666MT/s DDR4 ECC UDIMM
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    Dell Poweredge T140
    OS
    Windows 2012 R2 Data center/Linux Mint
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Monitor(s) Displays
    Viewsonic
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 750 GB
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
Those are useless for this problem - all they do is scan for malware. By then, its already too late.

Ok point taken just a suggestion I thought may help :huh:
 

My Computer My Computer

At a glance

Desk1 7 Home Prem / Desk2 10 Pro / Main lap A...Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i...Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop...Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build (new) Desk1 / Asus ROG Win 7 / Desk2 1st build
OS
Desk1 7 Home Prem / Desk2 10 Pro / Main lap Asus ROG 10 Pro 2 laptop Toshiba 7 Pro Asus P2520 7 & 10
CPU
Desk1 i5 3750K / Laptop i7 GTX 860M / Desk2 i5 2500
Motherboard
Desk1 Asus P877-V / Desk2 Gigabyte H67 UD3H / Laptop ?
Memory
Desk1 8GB (1866) / Desk2 16GB (1333) / Laptop 8Gb DDR3
Graphics Card(s)
Desk 1& 2NVidia GTX 650 & Laptops on board Intel
Sound Card
Desk 1 & 2 -XONAR DG Realtek High Def audio Laptop
Monitor(s) Displays
Desk 1 Benq HD 2450 / Desk2 Philips 24" / Laptop 17.5"
Screen Resolution
1920x1080 D1 & D2 & Laptop 1
Hard Drives
Desk1 Samsung 120GB 830 SSD
Asus ROG 256GB 850 Pro SSD
Desk2 Samsung 840 256 SSD
Toshiba 120GB EVO
PSU
Desk 1 Corsair HX 1050/ Laptop ? / Desk 2 Corsair HX 650
Case
Desk 1 Cooler HAF XM ? Toshiba laptop / Desk2 Coolermaster
Cooling
Fans on all Desk1 -2 Desk2 - all Coolermasters 5 Laptop ?
Keyboard
Desk 1 MS Sidewinder X6 Desk 2 MS Sidewinder X 4
Mouse
Desk 1&2 - Gigabyte MS 900 gamer - laptop - Logitec wireless
Internet Speed
ADSL2+
Other Info
One other Desktop (tester) and spare Toshba laptop both with SSD's
Running Kaspersky 2016 ISS on all machines config'd identically
Logitec audio stereo systems on each machine (x3)
Canon MG5250MFC
Router/modem TP-Link running WPA2SK
Back
Top