Windows 10: I got a notification of a ransomware but none of my files encrypted - Ransom:Win32/Zudochka!MSR

Discus and support I got a notification of a ransomware but none of my files encrypted - Ransom:Win32/Zudochka!MSR in AntiVirus, Firewalls and System Security to solve the problem; Detected : Ransom:Win32/Zudochka!MSRStatus : Removed or restoredThis threat or app was removed from quarantine or restored to the deviceAffected items:... Discussion in 'AntiVirus, Firewalls and System Security' started by Huzi cool, Oct 9, 2022.

  1. Huzi cool Win User

    I got a notification of a ransomware but none of my files encrypted - Ransom:Win32/Zudochka!MSR


    Detected : Ransom:Win32/Zudochka!MSRStatus : Removed or restoredThis threat or app was removed from quarantine or restored to the deviceAffected items: file: G:\images.exeBackstory: I wanted to copy something into a usb. I had an old usb stick which i plugged it and received this notification. I didnt open anything only formatted the usb stick. None of my file are encrypted does that mean im safe????

    :)
     
    Huzi cool, Oct 9, 2022
    #1

  2. Filed encrypted by Tor ransomware

    More information is needed to determine specifically what infection you are dealing with since there are many variants of crypto malware (file encrypting ransomware).
    RSA-4096 / RSA-2048 / RSA-1024 / AES-256 / AES-128 are
    encryption algorithms
    and not an explicit way of identifying a particular ransomware infection.

    Are there any obvious file extensions appended to or with your encrypted data files (i.e. several random hexadecimal characters, words or email addresses)? If so, is the extension the same for each encrypted file or is it different?

    What is the actual name of your ransom note? These infections are created to alert victims that their data has been encrypted and demand a ransom payment. Check your documents folder for an image the malware typically uses for the background note. Check the
    C:\ProgramData (or C:\Documents and Settings\All Users\Application Data) for a randomly named
    .html, .txt, .png, .bmp, .url file. Most ransomware will also drop a ransom note in every directory/affected folder where data has been encrypted.

    The best way to identify the different ransomwares is the ransom note (including it's name), the malware file itself, any obvious extensions appended to the encrypted files, samples of those encrypted files and information related to the email address used
    by the cyber-criminals.

    You can submit samples of encrypted files and ransom notes to ID Ransomware for
    assistance with identification and confirmation. This is a service that helps identify what ransomware may have encrypted your files and then attempts to direct you to an appropriate support topic where you can seek further
    assistance. Uploading both encrypted files and ransom notes together provides a more positive match and helps to avoid false detections.

    After gathering that information, please read and follow the instructions below.

     
    quietman7 - MVP, Oct 9, 2022
    #2
  3. How crypto ransomware spreads... is it decryptable...should I pay the ransom

    Locky Ransomware encrypts data using
    AES Encryption
    and completely changes the filenames. Any files that are encrypted with
    Locky will have the .locky extension appended to the end of the filename and leave a file (ransom note) named _Locky_recover_instructions.txt. When Locky encrypts a file it will actually rename the file to the format [unique_id][identifier].locky...(i.e.
    something like F67091F1D24A922B1A7FC27E19A9D9BC.locky).

    Unfortunately, at this time, there is no known way to decrypt files encrypted by Locky. More information in this BC News article.

     
    quietman7 - MVP, Oct 9, 2022
    #3
  4. I got a notification of a ransomware but none of my files encrypted - Ransom:Win32/Zudochka!MSR

    Ransomware

    Did you find any ransom notes? These infections are created to alert victims that their data has been encrypted and demand a ransom payment. Check your documents folder for an image the malware typically uses for the background note. Check
    the C:\ProgramData (or C:\Documents and Settings\All Users\Application Data) for a randomly named
    .html, .txt, .png, .bmp, .url file. Most ransomware will also drop a ransom note in every directory/affected folder where data has been encrypted.

    Nemucod,

    Win32/Filecoder.E
    and
    Win32/Filecoder.J
    all append a .crypted extension to the end of filenames.

    Based on infection rates we see, you are most likely dealing with Nemucod.

    However, you can submit samples of encrypted files and ransom notes to ID Ransomware for assistance with identification
    and confirmation. This is a service that helps identify what ransomware may have encrypted your files and then attempts to direct you to an appropriate support topic where you can seek further assistance. Uploading both encrypted files and ransom notes together
    provides a more positive match and helps to avoid false detections.
     
    quietman7 - MVP, Oct 9, 2022
    #4
Thema:

I got a notification of a ransomware but none of my files encrypted - Ransom:Win32/Zudochka!MSR

Loading...
  1. I got a notification of a ransomware but none of my files encrypted - Ransom:Win32/Zudochka!MSR - Similar Threads - got notification ransomware

  2. Got Hit with an INC Ransome and files encrypted. can anyone help!!!

    in Windows 10 Gaming
    Got Hit with an INC Ransome and files encrypted. can anyone help!!!: Got Hit an INC Ransome and i am freaking out. All my files got encrypted "literally shaking as i type this". Please can anyone help me on this...
  3. Got Hit with an INC Ransome and files encrypted. can anyone help!!!

    in Windows 10 Software and Apps
    Got Hit with an INC Ransome and files encrypted. can anyone help!!!: Got Hit an INC Ransome and i am freaking out. All my files got encrypted "literally shaking as i type this". Please can anyone help me on this...
  4. Files encrypted by ransomware

    in AntiVirus, Firewalls and System Security
    Files encrypted by ransomware: ATTENTION! Don't worry, you can return all your files! All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key. The only method of recovering files is to purchase decrypt tool and unique key for you. This...
  5. Recover files on Onedrive encrypted by ransomware

    in AntiVirus, Firewalls and System Security
    Recover files on Onedrive encrypted by ransomware: Some of my files on Onedrive can't be opened due to being encrypted by ransomware. They've been added .iqll. It may be a kind of Offline Key infection as I've checked them using EmisoftMy Onedrive account is a 365 Education one. Are there any ways to recover/repair those...
  6. Ransomware infection restore encrypted files

    in AntiVirus, Firewalls and System Security
    Ransomware infection restore encrypted files: Decryption did not work for me and I used a lot of different tools... My files still have .erif extension. When I ran EMSISOFT Decryptor the results were: Starting... File: "THE NAME OF THE FILE"Error: No key for New Variant online ID: "ONLINE ID" Notice: this ID appears to...
  7. Ransom: Win32 / Cobra.AA! MTB

    in AntiVirus, Firewalls and System Security
    Ransom: Win32 / Cobra.AA! MTB: Guys i need help my files are encrypted! to .Cobra extension! https://answers.microsoft.com/en-us/protect/forum/all/ransom-win32-cobraaa-mtb/ef263997-4e34-4d06-9a16-bf022de2981e
  8. Files encrypted by ransomware

    in AntiVirus, Firewalls and System Security
    Files encrypted by ransomware: Split from this thread. Cumulative updates - February 11th 2020 hi i have a problem on my computer i got a message that reads like this: ATTENTION! Don't worry, you can return all your files! All your files like photos, databases, documents and other important are...
  9. Files encrypted by (.ACFJKSO extension) ransomware

    in AntiVirus, Firewalls and System Security
    Files encrypted by (.ACFJKSO extension) ransomware: Dear Team, I am facing an issue with my windows 10 PC that some of my documents are renamed with '.ACFJKSO' extension. If I am trying to rename the file nothing is happening. From these symptoms I realized that it is a Torjan- Ransom like CBT- Locker. Does any one have a...
  10. All files got encrypted by Gandcrab ransomware

    in AntiVirus, Firewalls and System Security
    All files got encrypted by Gandcrab ransomware: i got affected with Gandcrab ransomware .All my files are encrypted by the ransomware .So could you help me out from this. all the files are encrypted and have the extension: .VSBCZPFRJG Cant open any file Below is the message given by the Ransomware :...