Avast + RANSOMWARE as a bonus!

   / Avast + RANSOMWARE as a bonus! #1  

Welshman

Platinum Member
Joined
May 22, 2009
Messages
533
Location
Northeast Ohio
Tractor
NH T1520
I have been experiencing some relatively minor but annoying issues with my computer in the last few weeks. I have been using Norton Anti-Virus for years and have never been aware of any viruses on any of the computers that I have. A friend suggested that I download a copy of Avast free, run a scan with it and see if it would detect anything that Norton didn't. I've always thought that I should disable my existing AV while installing a new program, to avoid installation conflicts, so I did. I believe that was a HUGE mistake.

After downloading, I ran a scan with Avast, and it found A BUNCH of "threats" which it "resolved". One threat in particular (debrovorda?) kept registering about every 5 seconds. After about 45 minutes, since this was the only threat it was finding, I stopped the scan. I then got a prompt to restart the computer so Avast could complete the install, and do a boot scan, which I did. Avast indicated a threat, resolved it, and my computer started normally.
When I attempted to open my email program (Outlook), I got a message that the file could not be found, and Outlook wouldn't open. I then tried to open Word (which I use as my email editor), and noticed in my "recent files" a file called "Decrypt Instruction". I opened it and read that all my files (which seem to be Word ands Excel) had been encrypted and if I wanted the decryption key to click a link and apparently PAY for the key - RANSOMWARE!

I've searched the web and so far, my results have not been promising. I did find a site - FireEye-Fox IT - that claimed they could decrypt if a sent a sample file, but when I did, they said the files were not encrypted. I suspect that I have a newer version of the ransomware than they have a fix for.

All my files are there, but when I open them, it's just gibberish. I had created a restore point before I downloaded Avast, and restored, but the malware is still there. I even went back and restored from a day earlier - still there.

Of course, I don't have a very current back-up of these files (lazy), but even so, I don't know how to make sure the virus is removed, so that I don't have this happen again.

Any ideas? I'm sick about this. I'm a spreadsheet kind of a guy, and can't get to any of them - nor emails, contacts or documents.

I'm a fairly cautious guy. I never open any strange emails or go to odd sites or click on or download anything that I don't know. I think it's ironic that in attempting to get "extra" protection, I ended up in this mess.

Thanks for any help.
 
   / Avast + RANSOMWARE as a bonus! #2  
Where did you download Avast? There are lots of websites out there offering downloads and you really have to be careful where you get the code. My quick search found about six Avast download sites and only one was directly from Avast.

Try contacting Avast and see if they have a solution. You won't be the first person that has been hit.

Good Luck,
Dan
 
   / Avast + RANSOMWARE as a bonus!
  • Thread Starter
#3  
Where did you download Avast? There are lots of websites out there offering downloads and you really have to be careful where you get the code. My quick search found about six Avast download sites and only one was directly from Avast.

Try contacting Avast and see if they have a solution. You won't be the first person that has been hit.

Good Luck,
Dan

Thanks, Dan. I got it right from the Avast site. I will call them right after lunch.
 
   / Avast + RANSOMWARE as a bonus!
  • Thread Starter
#4  
Well, I just got off the phone with Avast. They took control of my computer for a while, and then told me there was no way that downloading their program was what caused the problem, that it was just a coincidence (could be), but for $119.99 he could turn me over to a support certified software engineer, and "guarantee" that the computer would be restored.
I told him that the price was better than the ransom but the effect was the same. I told him I'd call him back.
 
   / Avast + RANSOMWARE as a bonus! #5  
Did you try running Malwarebytes and running it in safe mode ?
Malwarebytes | Free Anti-Malware & Internet Security Software

you may have to DL it onto a USB stick on a second system...

also have you tried killing the associated processes? this may give you some control but will only work for the current session....

The key is removing the infectious files from the registry...

Good Luck...
 
   / Avast + RANSOMWARE as a bonus! #6  
If you can go into the Control Panel, create a new user account with admin function.

Now shut down the PC, then fire it back up log on as the new admin. You should now be able to download Malwarebytes and run it.
 
   / Avast + RANSOMWARE as a bonus! #7  
tagging this thread so i can keep track of it.

good luck to the op.
 
   / Avast + RANSOMWARE as a bonus!
  • Thread Starter
#8  
Yes I have Malwarebytes and have run it. It didn't find anything.
I've been on with Microsoft tech support for the last 4 1/2 hours. So far, no luck. There going to call back tomorrow a.m.
 
   / Avast + RANSOMWARE as a bonus! #10  
Yes I have Malwarebytes and have run it. It didn't find anything.
I've been on with Microsoft tech support for the last 4 1/2 hours. So far, no luck. There going to call back tomorrow a.m.

Did you run it in safe mode?...the program must also be able to update the library....>Safe Mode w/networking...
 
 
Top