Ransomware

techiemoore

New member
Local time
6:49 PM
Messages
2
I too would like to know how to completely remove Bitlocker.

<Attempting to provide relevant data only>

I upgraded to Windows 10 a few weeks ago, and today I woke up and SURPRISE; All my hard drives now read as encrypted with Bitlocker (except for my primary OS drive (SSD))

I went through the usual CMD steps playing with manage-bde and such. All signs point to some how some time during the night, all three separate physical hard drives were encrypted.

I just logged into the local administrator account (since my profiles are all on the now encrypted drive) and noticed a text document on the desktop.

Now, I have encountered variants of this from other clients - but I never thought it could happen to me.
The document reads as follows:

"Hello there.
I would like to tell you first I'm sorry about that. Your documents, files, databased most are in original places or some moved to your local data. If you want to regain access to your local disk, all your files, documents, etc please send 1 BTC (Bitcoin) to this address: 1PFkYtDbxQRTv8Xse77u7wYG5bht8QB6e2 as fast as you can and email me at [email protected] If you dont know what bitcoin is, please ask me for bitcoin website that you can buy it fast or search on google for a local Bitcoin shop or ATM and transfer 1 BTC to this address: 1PFkYtDbxQRTv8Xse77u7wYG5bht8QB6e2
It's not my fault if you are try to format disk and lose all. Here are only one way to get all back and regain access to your local hard disk drive and this way is to send 1 Bitcoin to this address: 1PFkYtDbxQRTv8Xse77u7wYG5bht8QB6e2
It's just business not trying to get your money and then to not give to you the bitlocker password. Waiting for your reply to my email address ( [email protected] ) if you wanna get the bitlocker password. Thanks for your time!"

So there you have it.
I would really like to know how this happened and how to prevent it from happening again.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Some how you have got infected with one of the several ransomeware infections.

I would suggest going to our Security section on this forum and start a thread with your problem.

http://www.sevenforums.com/system-security/

I would also report this to your police department and see if they would like this information.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Thanks for your response,
But again - i too would like to know how to completely remove Bitlocker.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
CryptoMonitor, CryptoPrevent[or is it Protect?], WinRansom Beta [this is new! wait for stable release]. Can use both Cryptos on same computer. Haven't tried WinRansom yet. I don't know if any of those, or how any of those, work on a business network.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Antec desktop; Acer Aspire laptops
OS
Windows 7 Professional 64-bit
CPU
Desktop i5; Acers i5 & i7
Memory
desktop 16GB; 1 Acer 8GB & 1 Acer 16GB
Hard Drives
1TB split into 2 equal partitions [OS and data] usable by RJS
Internet Speed
AT&T DSL
Browser
FF, GChrome, msIE
Other Info
Windows 7 Firewall, Emsisoft AM/AV, MSE [scan-only], SpywareBlaster, Ruiware/BillP combine
Back
Top