I'm Running Windows 8.0 on a Asus MB11 12GB RAM 2 - 1TB HD(s) partitioned into 6 drives
-Ransomware found on computer when I noticed weird file names and decoding instrucs (300$)
-Installed Avast, Avast but it couldn't load GUI so I used command line to schedule a boot time scan, which found 4 malicious programs. Moved to chest. Finish boot - Avast still not working. Uninstall.
-Download EEK (Emsisoft) - Find 4 MORE viri - Quarantined
-Go to ID-Ransomware.com - which points me to and I Download: Amnesia2 decrytor - works - somewhat. ##more details below##
- Unable to go to FRST download page (CAN browse the entire rest of this site, but not the FRST DL page) - closes every window instantly on every attempt from any browser Chrome, Firefox, Safari or Opera.
- No longer have Write, Modify or Full Control access to D: drive and all subfolders with any user Including Admin or SYSTEM. (C: Drive (windows /system drive) not affected.
- An item in the start menu Startup folder (I haven't seen a program use this folder since Win95) -"lgudug.lnk" points to - "iwxuj.ligi", Every attempt to delete the link and the file it points to end up with it reappearing 2 seconds later.
-FYI .ligi is the file extension, my OS doesn't hide extensions.
-Also try "re-aiming" the link to launch another program. The edited link stays edited. But new Program I linked it to doesn't launch and the weird one does.
-Now my E: drive is "read only" for all users EXCEPT "Authenticated Users" Group which has Read, List & Write(Can I attach Pics?)
-Am able to download Farbar (FRST) and run it in Safe mode. (still can't open DL page or FRST64.exe without instant shut down in normal mode)
- Now the virus is deleting connections in (Control Panel\Network and Internet\Network Connections) I rebuild WiFi connection 4 times before giving up at "WiFi(4)" I connect to the network, then load a page, and it deletes before the page finishes loading(Most of the page downloads properly, so it is connected)
I am now staying in Safe Mode (with networking) until this issue is resolved!
## Ransomware issue continued##
-I downloaded "decrypt_Amnesia2.exe" by Fabian Wosar, Version220.127.116.11.
-The decrypter runs for a few minutes, and then stops decrypting. Everything I've tested is decrypted properly and perfectly, however, it just stops after decrypting between 5-15 files. It still shows 60%-100% processor usage for the decrypt program, but it just stays decrypting the same file for up to 8 hrs. Once I get ^^^^^ those issues fixed, would love to figure out how to tweak this!
Thanks for listening guys!!
Links to pics of D: and E: properties showing no control:
Edited by Joecool6969, 17 December 2017 - 09:48 PM.