Jump to content

suspecting that I have rensomware

ahmhaf

I am suspecting that there is some ransomware in my device encrypting my files, how do I clear the doubt?

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Electronics Wizardy said:

Why do you think you havea ransomware?

 

Restore backups? Reinstall windows?

The resources in my pc are used higher than often and higher than expected!

 

I cannot do that, although I have a back but it is not practical for me until I know for sure that I have the ransomeware!

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, ahmhaf said:

The resources in my pc are used higher than often and higher than expected!

 

I cannot do that, although I have a back but it is not practical for me until I know for sure that I have the ransomeware!

What programs are using the resources?

 

Or just wait and see if you have it.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, ahmhaf said:

The resources in my pc are used higher than often and higher than expected!

 

I cannot do that, although I have a back but it is not practical for me until I know for sure that I have the ransomeware!

Are you experiencing high disk usage even at idle? 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, BlueChinchillaEatingDorito said:

Are you experiencing high disk usage even at idle? 

no, not to my knowledge. But can ransomware reduce system resourse usage the moment you open task manger?

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, ahmhaf said:

no

Open task manager (Ctrl+Shift+Esc) and if there is a button at the bottom where it says "More details" click that, it will show you what is using your resources and how much its using.

😳
Not that active so I may not respond.

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Electronics Wizardy said:

What programs are using the resources?

 

Or just wait and see if you have it.

there are plenty, the probelm is I cannot tell with are something windows is using or I am using or other malicious software is using, not inclined enough to tell the difference

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Cool_Evlo said:

Open task manager (Ctrl+Shift+Esc) and if there is a button at the bottom where it says "More details" click that, it will show you what is using your resources and how much its using.

there are plenty, the probelm is I cannot tell with are something windows is using or I am using or other malicious software is using, not inclined enough to tell the difference

Link to comment
Share on other sites

Link to post
Share on other sites

If you had ransomware, wouldn't it, you know, demand ransom for your files?

Corps aren't your friends. "Bottleneck calculators" are BS. Only suckers buy based on brand. It's your PC, do what makes you happy.  If your build meets your needs, you don't need anyone else to "rate" it for you. And talking about being part of a "master race" is cringe. Watch this space for further truths people need to hear.

 

Ryzen 7 5800X3D | ASRock X570 PG Velocita | PowerColor Red Devil RX 6900 XT | 4x8GB Crucial Ballistix 3600mt/s CL16

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, ahmhaf said:

there are plenty, the probelm is I cannot tell with are something windows is using or I am using or other malicious software is using, not inclined enough to tell the difference

Can you show a screenshot? What are the names?

 

If disk io is low, its a pretty low chance.

 

Just now, Middcore said:

If you had ransomware, wouldn't it, you know, demand ransom for your files?

The ransom isn't immediate.  There can be a big delay the install of the malware, and the message appearing. Programs need time to do things like encrypt your files, upload your files, and work around the network.

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, ahmhaf said:

The resources in my pc are used higher than often and higher than expected!

 

I cannot do that, although I have a back but it is not practical for me until I know for sure that I have the ransomeware!

Lots of things can be causing high usage. Doesn't have to be ransomware doing it. Open up Task Manager and take a look at your disk usage and your network usage. If there's one program or process chewing through a ton of either/both, post the name of that program or process here. If there's not a program eating up a ton of disk or network usage, it's probably not ransomware, and a full scan with Windows Defender is highly advisable.

 

4 minutes ago, Middcore said:

If you had ransomware, wouldn't it, you know, demand ransom for your files?

Ransomware has to encrypt the files first, and even then it might sit dormant for a while after it's finished. It's not like you just open an email and it goes, "YOU'VE GOT RANSOM!". It takes its time to make itself as difficult to notice as possible.

Aerocool DS are the best fans you've never tried.

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Middcore said:

If you had ransomware, wouldn't it, you know, demand ransom for your files?

It would have to finish encrypting your files or whatever the payload is before demanding money to reverse the damage. If it were to ask you money immediately upon infection, well you have plenty of time to mitigate the damage. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

I really don't think you have "ransomware" but on the other hand, there could be the possibility that you may have a "virus".  The reason I think that is because with "ransomeware" someone would have contacted you and asked you for money before they released your system (files), back to you.

 

Good Luck.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Middcore said:

If you had ransomware, wouldn't it, you know, demand ransom for your files?

well, what I know that it needs time to encrypt my data before asking!

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Electronics Wizardy said:

Can you show a screenshot? What are the names?

 

If disk io is low, its a pretty low chance.

 

The ransom isn't immediate.  There can be a big delay the install of the malware, and the message appearing. Programs need time to do things like encrypt your files, upload your files, and work around the network.

I have 970 evo plus

image.thumb.png.a3d6be91926ed22be9f58dfd56cd03e4.pngimage.thumb.png.91614f7d88a40e2c93556eea6e94b383.pngimage.thumb.png.f54ee46be4fb610cf81e4c8037fd9684.pngimage.thumb.png.7c9eb8fe8b6f8dc753d1a8d8c70a4002.png

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, ahmhaf said:

I have 970 evo plus

image.thumb.png.a3d6be91926ed22be9f58dfd56cd03e4.pngimage.thumb.png.91614f7d88a40e2c93556eea6e94b383.pngimage.thumb.png.f54ee46be4fb610cf81e4c8037fd9684.pngimage.thumb.png.7c9eb8fe8b6f8dc753d1a8d8c70a4002.png

I don't see anything off here. Seems just like your have higher usage as you have a antivirus scan running. Is there a antivirus scan running?

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, kb5zue said:

I really don't think you have "ransomware" but on the other hand, there could be the possibility that you may have a "virus".  The reason I think that is because with "ransomeware" someone would have contacted you and asked you for money before they released your system (files), back to you.

 

Good Luck.

 

1 hour ago, aisle9 said:

Lots of things can be causing high usage. Doesn't have to be ransomware doing it. Open up Task Manager and take a look at your disk usage and your network usage. If there's one program or process chewing through a ton of either/both, post the name of that program or process here. If there's not a program eating up a ton of disk or network usage, it's probably not ransomware, and a full scan with Windows Defender is highly advisable.

 

Ransomware has to encrypt the files first, and even then it might sit dormant for a while after it's finished. It's not like you just open an email and it goes, "YOU'VE GOT RANSOM!". It takes its time to make itself as difficult to notice as possible.

 

1 hour ago, Electronics Wizardy said:

Can you show a screenshot? What are the names?

 

If disk io is low, its a pretty low chance.

 

The ransom isn't immediate.  There can be a big delay the install of the malware, and the message appearing. Programs need time to do things like encrypt your files, upload your files, and work around the network.

I got a hit on "trojan.script.miner.gen" using the free trial of kaspersky. It is mining virus or so i seems. I f*ck*ng know it, I thought I was beinng paranoid!

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, Electronics Wizardy said:

I don't see anything off here. Seems just like your have higher usage as you have a antivirus scan running. Is there a antivirus scan running?

yes, i did that

 

14 hours ago, Arika S said:

Kaspersky is only slightly better than ransomware, get rid of it.

 

everything else looks normal

 

14 hours ago, Electronics Wizardy said:

I don't see anything off here. Seems just like your have higher usage as you have a antivirus scan running. Is there a antivirus scan running?

Is there a specific sofware that scans for ransomeware that is free or comes with a free trial!

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, Arika S said:

Kaspersky is only slightly better than ransomware, get rid of it.

 

everything else looks normal

And rely on Windows Defender? 😆

VGhlIHF1aWV0ZXIgeW91IGJlY29tZSwgdGhlIG1vcmUgeW91IGFyZSBhYmxlIHRvIGhlYXIu

^ not a crypto wallet

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, ahmhaf said:

 

Is there a specific sofware that scans for ransomeware that is free or comes with a free trial!

Malwarebytes Free and HitMan Pro are my go-to on-demand scanners. Bear in mind that they DO NOT provide active protection unless you pay for them.

Desktop: KiRaShi-Intel-2022 (i5-12600K, RTX2060) Mobile: OnePlus 5T | Koodo - 75GB Data + Data Rollover for $45/month
Laptop: Dell XPS 15 9560 (the real 15" MacBook Pro that Apple didn't make) Tablet: iPad Mini 5 | Lenovo IdeaPad Duet 10.1
Camera: Canon M6 Mark II | Canon Rebel T1i (500D) | Canon SX280 | Panasonic TS20D Music: Spotify Premium (CIRCA '08)

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Biohazard777 said:

And rely on Windows Defender? 😆

Windows defender and common sense is all you really need. People like to hang shit in WD but it's actually one of the better anti-virus programs you can use short of a proper paid one.

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

Apart from the sheer number of Chrome tabs you seem to have, it all looks fine fine to me. 

6 minutes ago, Biohazard777 said:

And rely on Windows Defender? 😆

It's all you really need and from my experience, yields a smaller performance penalty and (ironically) less annoying than other Anti-virus programs. It's not like Malwarebytes, or AVG where it'll constantly show pop up messages from the task bar. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

Kaspersky is ransomeware in a way because if you don't pay them every month they totally screw up your system.  Get rid of it.  Between Windows Defender and a little common sense about which websites you visit, you will be fine.

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×