Hi, it all started with i started my computer few weeks ago where the background changed to something like the attached file. Some of my files where also decrypted and had names like this: RendererInfo.txt.SNemail@example.com_worldcza@email.cz where the RendererInfo.txt is the normal file, the numbers are some sort of serial code i think and the firstname.lastname@example.org_worldcza@email.cz thingy where also on my background.
My Chrome browser also changed to startpageing123 and i found out it was a virus and unistalled that.
I tried to remove the virus with security program and after that i opened steam which looked veery weird because of the many hashtags, as you can see in the other attached file. Can't really remember what else that happened besides that i thought i finally removed the virus at least i didn't see much more about that for a while(I didn't remove all the encrypted files because they actually didn't affect me so i thought it was fine).
But then few days ago My browser changed back to startpageing123 so i got scared because i thought i dint remove it all and it maybe like made a backdoor in or something.
I downloaded SpyHunter 4 and ran it it quickly found something related and ended up with like 100 different things. i removed the most dangerous of them with regedit and the files but something named winsnare couldt be removed however i tried that many times. SpyHunter also asks me sometimes if i want to run it which means its still there.
So how do i cleanly remove all this without affecting my files?
-Andreas 14 yrs
Edited by hamluis, 01 April 2017 - 02:06 PM.
Moved from W10 Spt to Ransomware - Hamluis.