Jump to content

Hi there 

Well, it seems my system has been hacked and files are encrypted. Asked me for bitcoins.... 

Funny thing I got nothing on the system it's just for playing games. Had ESET on my system this hack however or whatever deleted the antivirus didnt allow me to uninstall to install again. 

Reinstalled windows and same thing. Antivirus deleted, deleted partition only and installed windows. This time didnt install antivirus and left the PC on for few hours on and this encrypted thing happened. 

Any idea how to clean the system from anything left on it? 

256gb SSD 

1Tb hard drive

 

Currently nothing is installed on it. How do I clean the system making sure whatever is on it is gonna be taken care of

Link to comment
https://linustechtips.com/topic/1201388-pc-hacked-encrypted-files/
Share on other sites

Link to post
Share on other sites

Can you post a screenshot? Are there any other PCs on your network, particularly something old with Windows Xp or an outdated version of 7?

 

Have you completely formatted both your drives?

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to post
Share on other sites

When you isntalled windows did you delete all the partitions on your drives?

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to post
Share on other sites

10 minutes ago, Sauron said:

Can you post a screenshot? Are there any other PCs on your network, particularly something old with Windows Xp or an outdated version of 7?

 

Have you completely formatted both your drives?

There is nothing to show now it was a ransomware attack, and system is totally gone.

I deleted the windows.

 

I have a separate laptop not infected creating ubuntu flash now. 

I thought first just to delete partitions while installing the windows and creating new one and simple format in windows 10 installation would work but nope. I dont even trust my bios now and have to flash that. 

 

Link to post
Share on other sites

It's possible that the USB drive you installed Windows with is infected,

Did you use the official iso image from Microsoft's website to install?

A PC Enthusiast since 2011
AMD Ryzen 7 5700X@4.65GHz | GIGABYTE RTX 3080 GAMING OC | 4x 8GB Micron Rev.E (D9VPP) 3800MHz 16-19-14-21-58
Link to post
Share on other sites

4 minutes ago, Enderman said:

When you isntalled windows did you delete all the partitions on your drives?

Yap did but it didnt work somehow this attack is able to survive that. 

Also, not sure how it gets Eset. I know it makes the system boot on safe mode and then does something to the antivirus. And it just stops working 

Link to post
Share on other sites

1 minute ago, Vishera said:

It's possible that the USB drive you installed Windows with is infected,

Did you use the official iso image from Microsoft's website to install?

Well, i dont trust USB drives. Using CD to install the windows. That you cant infect so it's not from that 

Link to post
Share on other sites

Just now, Iwantcookies said:

Well, i dont trust USB drives. Using CD to install the windows. That you cant infect so it's not from that 

Any storage medium can get infected with malware,including CDs...

A PC Enthusiast since 2011
AMD Ryzen 7 5700X@4.65GHz | GIGABYTE RTX 3080 GAMING OC | 4x 8GB Micron Rev.E (D9VPP) 3800MHz 16-19-14-21-58
Link to post
Share on other sites

3 minutes ago, Vishera said:

Any storage medium can get infected with malware,including CDs...

I know but I know this one is clean. It's an old cd which I use only during installation. I will try to get a new one and try it I want to format the hard drive not sure how any ideas?I know it's on boot sector I detected it on bios too 🤦‍♂️🤦‍♂️🤦‍♂️🤦‍♂️

Link to post
Share on other sites

4 minutes ago, Vishera said:

Any storage medium can get infected with malware,including CDs...

Yes, but if the disc wasn't re-writable  which is 100% this case, since there are no windows installation discs on re-writable discs.

(unless u make one)

Thus the information is already burned to disc and can't be changed.

I would do the same as last resort... 

Please quote or tag me @Void Master,so i can see your reply.

 

Everyone was a noob at the beginning, don't be discouraged by toxic trolls even if u lose 15 times in a row. Keep training and pushing yourself further and further, so u can show those sorry lots how it's done !

Be a supportive player, and make sure to reflect a good image of the game community you are a part of. 

Don't kick a player unless they willingly want to ruin your experience.

We are the gamer community, we should take care of each other !

Link to post
Share on other sites

11 minutes ago, Iwantcookies said:

I want to format the hard drive not sure how any ideas?I know it's on boot sector I detected it on bios too 🤦‍♂️🤦‍♂️🤦‍♂️🤦‍♂️

Download Hiren's BootCD PE,and make a bootable CD or USB drive out of it.

Boot into it then open "AOMEI Partition Assistant",click on the drive and click on "Wipe Hard Drive".

 

Hiren's BootCD PE download page:

https://www.hirensbootcd.org/download/

A PC Enthusiast since 2011
AMD Ryzen 7 5700X@4.65GHz | GIGABYTE RTX 3080 GAMING OC | 4x 8GB Micron Rev.E (D9VPP) 3800MHz 16-19-14-21-58
Link to post
Share on other sites

17 minutes ago, Void Master said:

Yes, but if the disc wasn't re-writable  which is 100% this case, since there are no windows installation discs on re-writable discs.

(unless u make one)

Thus the information is already burned to disc and can't be changed.

I would do the same as last resort... 

Ya I dont think it's the cd but it a normal DVD_R 

Link to post
Share on other sites

10 minutes ago, Vishera said:

Download Hiren's BootCD PE,and make a bootable CD or USB drive out of it.

Boot into it then open "AOMEI Partition Assistant",click on the drive and click on "Wipe Hard Drive".

 

Hiren's BootCD PE download page:

https://www.hirensbootcd.org/download/

Thank you very much really appreciate it, any idea which antivirus would work best against this? ESET seems to be useless 

Link to post
Share on other sites

4 minutes ago, Iwantcookies said:

Thank you very much really appreciate it, any idea which antivirus would work best against this? ESET seems to be useless 

Hiren's BootCD PE has multiple anti-virus solutions in it,It's a bootable emergency environment after all.

 

In Hiren's BootCD PE open Malwarebytes,update it and then start a scan.

A PC Enthusiast since 2011
AMD Ryzen 7 5700X@4.65GHz | GIGABYTE RTX 3080 GAMING OC | 4x 8GB Micron Rev.E (D9VPP) 3800MHz 16-19-14-21-58
Link to post
Share on other sites

1 hour ago, Vishera said:

Hiren's BootCD PE has multiple anti-virus solutions in it,It's a bootable emergency environment after all.

 

In Hiren's BootCD PE open Malwarebytes,update it and then start a scan.

Sorry for the late reply I was busy with linux trying to erase the hard drive with linux and then with hiren's boot cd 

Do you think the usb is safe to use after this? Or could the virus have jumped into it?

received_2537839706317503.jpeg

Link to post
Share on other sites

Just now, Iwantcookies said:

Sorry for the late reply I was busy with linux trying to erase the hard drive with linux and then with hiren's boot cd 

Do you think the usb is safe to use after this? Or could the virus have jumped into it?

received_2537839706317503.jpeg

You can scan it in Hiren's BootCD,there is Malwarebytes in there you just need to update it and scan.

A PC Enthusiast since 2011
AMD Ryzen 7 5700X@4.65GHz | GIGABYTE RTX 3080 GAMING OC | 4x 8GB Micron Rev.E (D9VPP) 3800MHz 16-19-14-21-58
Link to post
Share on other sites

1 hour ago, Void Master said:

Yes, but if the disc wasn't re-writable  which is 100% this case, since there are no windows installation discs on re-writable discs.

(unless u make one)

Thus the information is already burned to disc and can't be changed.

I would do the same as last resort... 

Sorry for late reply, to be honest I'm not sure what happened if the windows closed it or the DVD is still open to be written on and if it's possible for the virus to do that. Now I'm using linux to format the drive. I'm gonna do the hard drive first then the SsD separately and bios is already flashed. Do you think this is enough?

received_2537839706317503.jpeg

Link to post
Share on other sites

3 hours ago, Iwantcookies said:

It keeps finding the same thing over and over again, any idea how to fix it?

 

Spoiler

20200529_030756.jpg

 

It's possible that the Windows image you are using for installation is infected,

Try downloading the latest version from Microsoft and use that.

A PC Enthusiast since 2011
AMD Ryzen 7 5700X@4.65GHz | GIGABYTE RTX 3080 GAMING OC | 4x 8GB Micron Rev.E (D9VPP) 3800MHz 16-19-14-21-58
Link to post
Share on other sites

  • 4 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×