Dealing with a Ransomware Attack: A full guide

Dealing with a Ransomware Attack: A full guide

The PC Security Channel

4 года назад

484,019 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

The PC Security Channel
The PC Security Channel - 23.12.2019 02:56

Response to certain concerns in the comments:
I’m aware that “pulling the plug” can destroy evidence for forensic investigators, but the value of potentially preventing a large amount of data from being encrypted in the first place can be much greater for the user than the slim chance of finding file traces or the encryption key in memory through a high cost forensic investigation. Of course it only makes sense if done early, and as with everything not everyone agrees. This video is meant to be a general guide for most people but of course it cannot tell you how to perfectly deal with every possible scenario.

Ответить
luffy
luffy - 27.12.2022 23:47

you know demon slay? he helped me decrypt the ransomware I got from 3 years

Ответить
Garden of Words
Garden of Words - 15.12.2022 17:38

Hi, I got hit by a ransomware attack and they got ahold of a few gmails that didnt have much important info except one bank card that didnt have funds on it which I promptly sort a replacement for and now the old card is destroyed. I reset my pc and os but I still think there is some virus on it. I checked my task manager and it is showing "system" using upwards of 50% of my cpu among a few other processes that lead by to a "System32" folder when I check their original file location and I cant delete these files as they say I need access from "TrustedInstaller". I also cannot connect to my personal router which was connected to the pc through an ethernet cable when I was hit. Just wanted to confirm if the methods like malwarebytes and such would work still and if changing my hard drive would have to be an option.

Ответить
Randish
Randish - 02.12.2022 23:44

I hope I'll never have to actually watch this video

Ответить
Trevor Eyre
Trevor Eyre - 21.11.2022 18:08

Aren't there some ransomwares that prevent you from running certain applications, such as anti-malware or decryptors?

Ответить
go4sens
go4sens - 02.11.2022 02:11

👏Back👏up👏your👏data

Ответить
Khanh Dang Phuc
Khanh Dang Phuc - 26.10.2022 11:48

Thank you for this tutorial.

Ответить
MrVictorgrigoras
MrVictorgrigoras - 18.10.2022 00:39

this video helped me. thanks

Ответить
OmGi
OmGi - 12.10.2022 19:18

Bro, so many bots in the comments...

Ответить
Josiah S. Cooper
Josiah S. Cooper - 11.10.2022 23:19

Don't store lots of your data on the mounted hard-drive. Use removable USB or SD cards. Upload files to the cloud. Have a backup version of your favorite OS on a USB or CD ready to go, so you can simply clean-install and never be touched. That way you can skip all of this.

Ответить
shakespeareswingman
shakespeareswingman - 05.10.2022 02:29

💋 an exemplary video. It is the 911 of the computer world. Hello: what's your issue? Let's deal with it. Boom.

Ответить
NOSTALGIA
NOSTALGIA - 29.09.2022 21:38

Emsisoft saying "impossible to decrypt"

Ответить
Graham Drew
Graham Drew - 23.09.2022 02:50

The only real answer to Ransomware is to eliminate the source. In one building in Russia most of these operations are housed and overseen by the FSB. Rather than pay millions in ransom some companies will opt for the nuclear option. Pay mercenaries to topple the building onto the hackers and keep targeting them till the message gets out. Hack for the FSB or Mafia and risk death. Simple but effective deterrent is the knowledge you will be tracked and eliminated for and with the money you were trying to steal.

Ответить
SSJ Reacts!
SSJ Reacts! - 13.09.2022 15:41

I believe you can but tNice tutorials will depend what version you have.

Ответить
Rajesh Rajendran
Rajesh Rajendran - 24.08.2022 16:07

I m used emisoft decryption but it show the results remote not resolved

Ответить
Rajesh Rajendran
Rajesh Rajendran - 24.08.2022 16:04

Hi Bro i have fdvc infected files in external drive. So how to recover pls help me

Ответить
CarCar26
CarCar26 - 23.08.2022 14:02

But the Annabelle ransomware is full screen mode and it doesn’t let you do anything else. A lot of ransomware nowadays don’t let you use your internet browser and you said yourself that i need to remove the network. I mean, i can use my phone for it, but then how am i supposed to upload a file

Ответить
khel sem
khel sem - 09.08.2022 22:57

I suggest you contact Cleedenz directly on Instagram for help, he's a certified white hat and he's legit and reliable enough when it comes to cyber security jobs

Ответить
Jake Turbo Productions
Jake Turbo Productions - 07.08.2022 02:36

I got a Trojan virus a few months ago and windows defender actually got rid of it instantly

Ответить
Akash Call of duty mobile
Akash Call of duty mobile - 05.08.2022 04:12

Does one drive can effect by virus

Ответить
sam wang
sam wang - 02.08.2022 21:35

still works! followed steps exactly and it works, thx a ton and keep up the awesome videos

Ответить
rafael martinez
rafael martinez - 30.07.2022 07:59

reconded to use headphone for best experience

Ответить
Eva Amanda Samlie
Eva Amanda Samlie - 30.07.2022 07:47

production. Thanks again!

Ответить
Nitesh Wawre
Nitesh Wawre - 29.07.2022 22:11

.VVWQ ransomware

Ответить
Geomaster
Geomaster - 17.07.2022 02:43

what about the ransomware that creates non minimazable window?

Ответить
Crystal Lezo
Crystal Lezo - 14.07.2022 06:22

Cm l
W

Bwwww,lvl. The c
J

Ответить
Kit Jasper Hernandez
Kit Jasper Hernandez - 09.07.2022 12:20

Will reformatting the system completely remove the ransomware?

Ответить
Taivnaa Taivankhuu
Taivnaa Taivankhuu - 03.07.2022 18:45

Dude my id is online and i tried everything and attanded every professionals who could decrypt it but they said without virus it couldn't be decrypted bcuz in order to unlock the online code it mustn't be uninstalled so what should i do bro help me plz😢😢😭😭

Ответить
Dranoel Holland
Dranoel Holland - 02.07.2022 23:04

I suggest you all reach out to MARCTECH247 for your extension recovery. He’s tested and trusted

Ответить
WhyNotDon
WhyNotDon - 02.07.2022 01:07

Marctech247 was able to guide me on how to recover my encrypted files in less than an hour. They’re the best when it comes to recovery issues. Give them a try now

Ответить
WhyNotDon
WhyNotDon - 02.07.2022 01:06

Marctech247 was able to guide me on how to recover my encrypted files in less than an hour. They’re the best when it comes to recovery issues. Give them a try now

Ответить
PeBoVision
PeBoVision - 29.06.2022 01:57

I use non-network connected external drives, that I write my data out to every few days. As a retiree, anything on my computer is likely a bunch of media files or games that I can re-download. I've always enjoyed the performance increase of a fresh windows install (a relatively quick task in 2022), so that's how I'd cure a ransomware attack. Wipe everything and move on.

Personal files are always safe using offline storage solutions. Just don't plug the drive into an infected machine.

Ответить
T-800
T-800 - 27.06.2022 09:29

if pull off the internet plug, how do you search for the Decrypt site?

Ответить
Beautiful
Beautiful - 25.06.2022 18:52

Can ransomeware attack zip files or is there any solition to be protected thanks

Ответить
Beautiful
Beautiful - 25.06.2022 18:51

I have .bbzz

Ответить
TechEra
TechEra - 25.06.2022 10:33

What if decryptor is not available....?

Ответить
Parveen
Parveen - 16.06.2022 00:06

I'm in trouble. Ransomware Attack in my PC I want help can you please Help me now? Gtys and Egfg Extension at all files.

Ответить
Tarone Fields
Tarone Fields - 14.06.2022 23:04

.You can message SCOTTS_HACK

Ответить
Tarone Fields
Tarone Fields - 14.06.2022 23:03

.You can message SCOTTS_HACK

Ответить
Tarone Fields
Tarone Fields - 14.06.2022 23:03

.You can message SCOTTS_HACK

Ответить
Myra Malabanan
Myra Malabanan - 09.06.2022 10:37

I can't delete my encrypted files

Ответить
llamaskank
llamaskank - 05.06.2022 07:01

My system was attacked several days ago. Watched this video and then visited ID-Ransomware and uploaded a sample encrypted file and it immediately identified the type of ransomware I am dealing with (DcRat/Lime). It says it's decryptable. Great! So then it says to click for more info. and takes me to a random Twitter thread from years ago and says to leave a message for someone and link them an uploaded sample encrypted file. I did this and have heard nothing back :( It's frustrating to learn that there is hope for my files but then basically to be taken to a dead end by this website. I don't think this is an active Twitter thread anymore because no one has commented on it for years. I had hoped that the "more information" it's going to provide me with some useful tool or decryption program or something but now I'm just at a dead end.

Ответить
jessdouard
jessdouard - 01.06.2022 17:53

🆙 Everyone take a look at this contact 🆙 on WhatsApp for your removal of viruses affecting your documents he was the one that helped me decrypt mine

Ответить
jessdouard
jessdouard - 01.06.2022 17:53

🆙 Everyone take a look at this contact 🆙 on WhatsApp for your removal of viruses affecting your documents he was the one that helped me decrypt mine

Ответить