Malware Trying to Encrypt my Hard Drives

Page 1 of 3 123 LastLast

  1. Posts : 28
    Win 10 Pro 64bit Enterprise
       #1

    Malware Trying to Encrypt my Hard Drives


    Hi all,

    I have somehow acquired some malware that keeps trying to encrypt my files but I have a program running called CyberReason which blocks it everytime it tries to do its evil deed. Yet it does not clean the ransomware from my PC.

    What is the best ransomware cleaner, preferably free?

    The ransomware keeps adding folders to all of my drives with different name and tries to hide them. But I can see them since I have Show Hidden Folders enabled. Every time I delete them, they come back with a different name within a minute or so. Here are some of the names:

    Adate167
    Zconfig194
    Acdata102
    Xpackage86

    Inside these folders are files of various types like "wise align.doc" and "cigarette.liberal.xls" with a total of 10 files in each folder. They amount to 1.68 MB.

    I have included wise align.doc as an attachment but I DO NOT advise anyone to open it! I include it only in the hope that someone knows how to analyze it and let me know what the name of this ransomware is.

    Does anyone recognise this particular ransomware and know of a good cleaner that will kill it dead?
    Last edited by essenbe; 13 Oct 2017 at 20:56. Reason: remove attachment
      My Computer


  2. Posts : 2,075
    Windows 10 Pro
       #2

    Setting aside name calling and politics.......download Malwarebytes, it's free and use the trial period. This will give you real time protection and highly recommend you buying it. Then run it and let it do it's thing and when it finds malware let it clean it. Next, download Norton Power Eraser and run it and select for root kits and a restart will be required. It should find some stuff that's deeply embedded
      My Computer


  3. Posts : 28
    Win 10 Pro 64bit Enterprise
    Thread Starter
       #3

    Plankton said:
    Setting aside name calling and politics.......download Malwarebytes, it's free and use the trial period. This will give you real time protection and highly recommend you buying it. Then run it and let it do it's thing and when it finds malware let it clean it. Next, download Norton Power Eraser and run it and select for root kits and a restart will be required. It should find some stuff that's deeply embedded
    OK, I have tried both of these scanners and the problem still exists. This malware is hidden really well and is putting these folders back on all four of my drives within a minute of my deleting them--with new names of course but still easily identifiable.

    Any other ideas?
      My Computer


  4. Posts : 31,651
    10 Home x64 (22H2) (10 Pro on 2nd pc)
       #4
      My Computers

  5.   My Computer


  6. Posts : 28
    Win 10 Pro 64bit Enterprise
    Thread Starter
       #6

    Thanks for your help folks! I really appreciate it!

    It will be until at least Saturday night before I can get to trying these solutions.

    One problem I have had with the offline AV scanners is that they say they can't remove any viruses they find because Win 10 (latest edition) won't let them access the files in a way that they can delete them.

    Does anyone know why this is and how to get around it?

    I download the AV program and run it from a CD in its own program before Win 10 can boot. But they just won't delete the viruses they claim to find due to this problem with the latest builds of Win 10, like Creator's Update.
      My Computer


  7. Posts : 15,485
    Windows10
       #7

    Forget trying to remove issue!

    Once infected, the bigger issue is what else has been compromised?

    Change online passwords immediately, especially banks, ebay, amazon, paypal etc. Do this from another pc or phone etc.

    Check those accounts have not ben compromised.

    Then forget trying to fix issues. Backup valuable data to an external drive, and do a clean reinstall.

    Overkill maybe but it is not a question if you can afford to take time to do this, but whether you can afford NOT to take time.
      My Computer


  8. Posts : 39,956
    Win 7 32, Win 7 64 Pro, Win 8.1 64 Pro, Win 10 64 Education Edition, Win 11 Pro
       #8

    These articles my give you some helpful advice.

    How to rescue your PC from ransomware | PCWorld

    The No More Ransom Project
      My Computer


  9. Posts : 2,075
    Windows 10 Pro
       #9

    cereberus said:
    Forget trying to remove issue!

    Once infected, the bigger issue is what else has been compromised?

    Change online passwords immediately, especially banks, ebay, amazon, paypal etc. Do this from another pc or phone etc.

    Check those accounts have not ben compromised.

    Then forget trying to fix issues. Backup valuable data to an external drive, and do a clean reinstall.

    Overkill maybe but it is not a question if you can afford to take time to do this, but whether you can afford NOT to take time.
    Yep....totally agree.
      My Computer


  10. Posts : 16,325
    W10Prox64
       #10

    Todd said:
    Hi all,

    I have somehow acquired some malware that keeps trying to encrypt my files but I have a program running called CyberReason which blocks it everytime it tries to do its evil deed. Yet it does not clean the ransomware from my PC.

    What is the best ransomware cleaner, preferably free?

    The ransomware keeps adding folders to all of my drives with different name and tries to hide them. But I can see them since I have Show Hidden Folders enabled. Every time I delete them, they come back with a different name within a minute or so. Here are some of the names:

    Adate167
    Zconfig194
    Acdata102
    Xpackage86

    Inside these folders are files of various types like "wise align.doc" and "cigarette.liberal.xls" with a total of 10 files in each folder. They amount to 1.68 MB.

    I have included wise align.doc as an attachment but I DO NOT advise anyone to open it! I include it only in the hope that someone knows how to analyze it and let me know what the name of this ransomware is.

    Does anyone recognise this particular ransomware and know of a good cleaner that will kill it dead?
    Can you give us a screenshot of what CyberReason says when it blocks something? Curious to know what this is. Does it happen all the time, or any time, or just when you're visiting certain websites?
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:29.
Find Us




Windows 10 Forums