The 'Crypto Virus' infection - infected

Status
Not open for further replies.

Franc_828

Estimable
Dec 14, 2015
3
0
4,510
0
Hello yall,

Right as im writing this, I am infected by a virus i know well now - because a few months ago, i was infected by the same thing.

That thing, months ago, if you give it enough time, it can encrypt your entire disk drive, so all your personal files will become unavailable to even use.


Anyways, back to the main subject:

my PC have an infection. i know it.

But I dont know where inside the drive the virus lies ! I mean i looked everywhere !!

I used malwarebytes, i scanned 2 times now.


I know the virus my pc have :

its a thing that mess around a few places, notably /AppData/Temp

at this directory, it creates multiples random files

the files you are only able to remove them if you kill their processes first.

anyways,

everytime im log on the internet , the virus seems to work. it creates more and more encrypted files.

and also to note, even if i delete anything weird, at the next reboot, the directories come back.

anyways,

i dont know what to do.

I want to know where those 'Crypto Virus' hides within our hard drive - their core - so we can delete them by the core at first.

but seems i cant find.

Googling , i cant find any site that explains where those things hide.

they only say that mainly, crypto viruses have a part in the registry, may have a part in the Startup, ... but also have a part in the temp files.

can anyone help ?

thanks
 

Petrossa

Honorable
Jan 30, 2014
176
1
10,910
71
Format and re-install!
That is the only way to effectively kill it.
If you don't have backups of your data, you're out of luck. (You could always pay the ransom)
 

Franc_828

Estimable
Dec 14, 2015
3
0
4,510
0


thanks for helping on this, but how can you say 'its the only way' ?

if a pc get infected, then the virus has to be somewhere .

we have to know
 

Petrossa

Honorable
Jan 30, 2014
176
1
10,910
71
Since no anti-virus/malware scanner is able to pick it up, you are not able to be sure that you have found all instances of the nasty, hence the suggestion to re-install and be done with it.
We've had the same issue with some of our workstations being infected and thus infecting a server. There is no time to sift through thousands of files trying to find it. Format, re-install, set user up again, restore server data from backup. Easy.
 

ss202sl

Honorable
May 23, 2012
757
0
11,960
115
The virus changes. The Antivirus companies try to keep up, but it's impossible, and while they may catch it, once you're infected, they haven't created a 100% way to clean your PC. That leaves re-installing the OS as the best option - or you end up playing the game of trying to clean your PC for the next few weeks or months, and maybe getting nowhere.
 
Mar 30, 2015
123
0
4,710
27
Good old Linux is your friend. You can copy all your old files off without worrying about a spreading infection, but although you probably could remove the virus using Linux with enough work it still would be safer to reinstall.
 

Nonpossible

Estimable
Jan 3, 2015
7
0
4,510
0

He's right, these crypto-lockers are very sophisticated and cannot simply be deleted by you and in most cases can't even be detected by antivirus. Format and reinstall Windows, don't pay the ransom. There is no guarantee that if you pay them they won't leave the locker on to hit you up in the future (they are criminals after all).

 

Nonpossible

Estimable
Jan 3, 2015
7
0
4,510
0
It looks like you have already gotten the same advice here so let me leave you with this, do frequent backups of your data. If you have an external HDD somewhere, make a clone of your C: drive once a week or once a month or as frequently as you need. Make two backups, keep them in separate storage areas. Then when you get hit up for a ransom you won't have to worry about losing more than a week or a few days of data.
 
Status
Not open for further replies.
Thread starter Similar threads Forum Replies Date
C Antivirus / Security / Privacy 4
A Antivirus / Security / Privacy 2
E Antivirus / Security / Privacy 2
ArtisticBatling Antivirus / Security / Privacy 11
ethanxx Antivirus / Security / Privacy 0
Tubucu246 Antivirus / Security / Privacy 46
The KiWeeD Antivirus / Security / Privacy 1
J Antivirus / Security / Privacy 1
K Antivirus / Security / Privacy 1
Z Antivirus / Security / Privacy 4
S Antivirus / Security / Privacy 4
i_need_help_123 Antivirus / Security / Privacy 1
Anajoy Antivirus / Security / Privacy 8
CGoody564 Antivirus / Security / Privacy 3
G Antivirus / Security / Privacy 1
D Antivirus / Security / Privacy 2
Tomus63528 Antivirus / Security / Privacy 2
T Antivirus / Security / Privacy 4
D Antivirus / Security / Privacy 6
I Antivirus / Security / Privacy 5

ASK THE COMMUNITY