Author Topic: Buddy needs help with Computer  (Read 3662 times)

SGT Kahrs

  • 11B Infantryman
  • Combat Element
  • Posts: 106
Buddy needs help with Computer
« on: June 17, 2016, 02:34:07 PM »
Hey guys,

So I have a friend of mine who, in his infinite wisdom, downloaded something unsafe. It seems to be a virus, but I'm not that great with software. Anyways, he has lost all his pictures and videos and such and is quite upset. I was wondering if anyone might have heard of something like this or run into a similar issue and could help us in solving the problem.

Thanks!
SPC Kahrs
A. KAHRS
SGT, USA
Infantryman, 1-506 Infantry


R. F. Nelson

  • Posts: 493
Re: Buddy needs help with Computer
« Reply #1 on: June 17, 2016, 03:44:11 PM »
First thing's first; your buddy needs to ensure whatever malicious software has been removed. First, I would have your buddy check his Recycle Bin. Depending on the malicious software, it may have simply deleted them, and they might be located there. However, most types of malicious software aren't in the business of deleting media files; e.g., could be a trojan where a person on the other end swiped said goodies. Most malware these days are after those sweet sweet digital monies; credit card numbers, etc.

All that said, you may want your bud to download and try this https://www.piriform.com/recuva for the attempted recovery of the media. It's a program I've used myself, to recover data off HDDs of old (including those that had been re-formatted), and it had some decent success. It's the same company that makes CCleaner, so they're rather reliable.

Hope it helps.

SGT Kahrs

  • 11B Infantryman
  • Combat Element
  • Posts: 106
Re: Buddy needs help with Computer
« Reply #2 on: June 17, 2016, 04:14:19 PM »
Thanks for the help! It turns out that it is actually ransomware. While the program has been taken care of, the files are now encrypted. If anybody knows how to fight ransomware, your knowledge would be greatly appreciated! Specifically it is Cerber Ransomware.
« Last Edit: June 17, 2016, 04:15:55 PM by SPC Kahrs »
A. KAHRS
SGT, USA
Infantryman, 1-506 Infantry


akoch

  • Posts: 257
Re: Buddy needs help with Computer
« Reply #3 on: June 17, 2016, 04:32:48 PM »
Thanks for the help! It turns out that it is actually ransomware. While the program has been taken care of, the files are now encrypted. If anybody knows how to fight ransomware, your knowledge would be greatly appreciated! Specifically it is Cerber Ransomware.

I'm afraid there's not much you can do. Either your friend will have to pay the ransom and get his files back, or pray he had them backed up somewhere.

Source: I deal with ransomware response at work

R. F. Nelson

  • Posts: 493
Re: Buddy needs help with Computer
« Reply #4 on: June 17, 2016, 05:05:19 PM »
1.) Never ever ever pay money. They will insist on a credit card, and have a form to fill out. I'm sure you can guess the kind of information required; birth date, address, credit card number and security code, and so forth.

2.) There are a few things you buddy can do. The first, is if there's a restore point from a couple of days ago, then a system restore back to that point, should do the trick.

Kaspersky has a removal tool for some of the .crypt and might work, so long as the virus itself has been removed. You can find the instructions, and the download for the tool (which is free), here: https://support.kaspersky.com/viruses/disinfection/8547?_ga=1.184281509.2049776603.1466197312#block1

akoch

  • Posts: 257
Re: Buddy needs help with Computer
« Reply #5 on: June 17, 2016, 05:10:43 PM »
1.) Never ever ever pay money. They will insist on a credit card, and have a form to fill out. I'm sure you can guess the kind of information required; birth date, address, credit card number and security code, and so forth.

They use Bitcoin most of the time, so they don't know said details

2.) There are a few things you buddy can do. The first, is if there's a restore point from a couple of days ago, then a system restore back to that point, should do the trick.

Won't normally help since it doesn't store files with the restore points, only system files and applications

Kaspersky has a removal tool for some of the .crypt and might work, so long as the virus itself has been removed. You can find the instructions, and the download for the tool (which is free), here: https://support.kaspersky.com/viruses/disinfection/8547?_ga=1.184281509.2049776603.1466197312#block1

This may work, my bad!

SGT Kahrs

  • 11B Infantryman
  • Combat Element
  • Posts: 106
Re: Buddy needs help with Computer
« Reply #6 on: June 17, 2016, 07:20:48 PM »
Thanks guys! I will try a little later this evening and let you know how it turns out.
A. KAHRS
SGT, USA
Infantryman, 1-506 Infantry