Windows 10: Malware Help - Infected by 'Redeemer' ransomware virus

Discus and support Malware Help - Infected by 'Redeemer' ransomware virus in Windows 10 Software and Apps to solve the problem; I was just using my PC until it suddenly restarted, I thought it was a simple malfunction until I saw that it had been rebooted into Windows 10 Safe... Discussion in 'Windows 10 Software and Apps' started by SeanLX, Mar 19, 2023.

  1. SeanLX Win User

    Malware Help - Infected by 'Redeemer' ransomware virus


    I was just using my PC until it suddenly restarted, I thought it was a simple malfunction until I saw that it had been rebooted into Windows 10 Safe Mode I am using Windows 10 OSI am trying to access basic Windows 10 functions that should still work in Safe Mode such as the Windows Start Menu or even Settings, but the shortcuts nor buttons work. Whenever I click the start menu nothing happens.I open task manager in curiosity, and I find the process called Isass.exe which was using practically 100% of my CPU. I killed the process.I searched online on Google to find out what it was and multi

    :)
     
    SeanLX, Mar 19, 2023
    #1

  2. I have been infected with Ransomware

    Oh.

    I see that a Community Moderator converted your thread from a Discussion to a Question.

    Do you have a question?

    It is not quite clear (to me at least) why you've created this thread....

    In case that you do indeed have a problem with ransomware:

    It would be helpful if you would describe your problem more precisely, see:
    Suggestions for asking a question on help forums


    Without knowing more details, suggestion to read/do:

    Try to identify with what Ransomware you're dealing here:
    https://id-ransomware.malwarehunterteam.com/index.php


    and read/follow this guide:
    How to remove ransomware the right way: A step-by-step guide


    Also: See the pinned threads here:
    https://www.bleepingcomputer.com/forums/f/239/ransomware-help-tech-support/


    Might be the best to get free expert help in above mentioned bleepingcomputer forum....

    =======================

    Also suggestion to read:

     
    Jsssssssss, Mar 20, 2023
    #2
  3. Ransomware infection?

    Any files that are encrypted with MRCR1 Ransomware will have the the
    .MRCR1.PEGS1, .RARE1,
    .RMCM1
    or .MERRY extension appended to the end of the encrypted data filename and leave files (ransome notes) named YOUR_FILES_ARE_DEAD.HTA as explained

    here
    . The ransom note instructs victims to contact the cyber-criminals at "L: *** Email address is removed for privacy ***" or "TELEGRAM @comodosecurity" to get payment instructions.

    You can submit samples of encrypted files and ransom notes to ID Ransomware for
    assistance with identification and confirmation. This is a service that helps identify what ransomware may have encrypted your files and then attempts to direct you to an appropriate support topic where you can seek further
    assistance. Uploading both encrypted files and ransom notes together provides a more positive match and helps to avoid false detections.

    Fabian Wosar released a decryptor tool for victims of this type of infection.

    There is an ongoing discussion in this topic where you can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.


    Most crypto malware ransomware is typically programmed to automatically remove itself...the malicious files responsible for the infection...after the encrypting is done since they are no longer needed. That explains why many security scanners
    do not find anything after the fact. The encrypted files do not contain malicious code so they are safe. Unfortunately, most victims do not realize they have been infected until the ransomware displays the ransom note and the files have already
    been encrypted. In some cases there may be no ransom note and discovery only occurs at a later time when attempting to open an encrypted file. As such, they don't know how long the malware was on the system before being alerted or if
    other malware was downloaded and installed along with the ransomware. If other malware was involved it could still be present so be sure to perform full scans with your anti-virus.
    Disinfection will not help with decryption of any files affected by the ransomware.

    If your antivirus did not detect and remove anything, additional scans should be performed with other security programs like

    Malwarebytes 3.0
    ,
    HitmanPro
    and
    Emsisoft Anti-Malware
    . You can also supplement your anti-virus or get a second opinion by performing an

    Online Virus Scan
    ...ESET is one of the more effective online scanners.
     
    quietman7 - MVP, Mar 20, 2023
    #3
  4. bruinator Win User

    Malware Help - Infected by 'Redeemer' ransomware virus

    steps taken for infected Pc's.


    I was hoping someone could give me a list of step by step instructions you use as a guide to clean virus, malware...etc. so I can keep my PC clean if it gets infected.

    thx
     
    bruinator, Mar 20, 2023
    #4
Thema:

Malware Help - Infected by 'Redeemer' ransomware virus

Loading...
  1. Malware Help - Infected by 'Redeemer' ransomware virus - Similar Threads - Malware Help Infected

  2. Help with malware infection?

    in Windows 10 Gaming
    Help with malware infection?: I have been infected by malware that has taken management rights on Edge. I also keep seeing notifications for “universal browser” updates. I went in my computer’s registry and deleted one suspicious file and have found a thing in ExtensionInstallForcelist called “1” with...
  3. Help with malware infection?

    in Windows 10 Software and Apps
    Help with malware infection?: I have been infected by malware that has taken management rights on Edge. I also keep seeing notifications for “universal browser” updates. I went in my computer’s registry and deleted one suspicious file and have found a thing in ExtensionInstallForcelist called “1” with...
  4. Malware Help - Infected by 'Redeemer' ransomware virus

    in Windows 10 Gaming
    Malware Help - Infected by 'Redeemer' ransomware virus: I was just using my PC until it suddenly restarted, I thought it was a simple malfunction until I saw that it had been rebooted into Windows 10 Safe Mode I am using Windows 10 OSI am trying to access basic Windows 10 functions that should still work in Safe Mode such as the...
  5. Malware Help - Infected by 'Redeemer' ransomware virus

    in AntiVirus, Firewalls and System Security
    Malware Help - Infected by 'Redeemer' ransomware virus: I was just using my PC until it suddenly restarted, I thought it was a simple malfunction until I saw that it had been rebooted into Windows 10 Safe Mode I am using Windows 10 OSI am trying to access basic Windows 10 functions that should still work in Safe Mode such as the...
  6. My computer is infected by ransomware virus

    in AntiVirus, Firewalls and System Security
    My computer is infected by ransomware virus: My all data is infected by extention [.boop] on my computer ransomware virus attack [ATTACH][ATTACH][ATTACH] https://answers.microsoft.com/en-us/protect/forum/all/my-computer-is-infected-by-ransomware-virus/f9519a2d-3413-42a6-8b74-9e634e4e6a6a
  7. Computer infected with Trojan Virus and Malware

    in AntiVirus, Firewalls and System Security
    Computer infected with Trojan Virus and Malware: My computer has a problem as it has been infected with Trojan virus and malware and adware as well and the keys are not working the desktop icons are not appearing and I can't use the desktop itself and even the local C drive is also affected in user data now how to repair...
  8. Help with Virus Infection

    in AntiVirus, Firewalls and System Security
    Help with Virus Infection: What in the registry needs to be changed after infection with"LogiCampNotifier"? [Original Title: virus] https://answers.microsoft.com/en-us/protect/forum/all/help-with-virus-infection/6ef0d3c9-21e9-4632-bccc-1b7015adf1e0
  9. Is my Microsoft Account infected by a virus or malware?

    in AntiVirus, Firewalls and System Security
    Is my Microsoft Account infected by a virus or malware?: Hello, a few days ago my credit card has been compromised, I thought maybe because I turn on credit card autofill in Microsoft Edge but when I entered my Microsoft Account panel "https://account.microsoft.com/?ref=MeControl" I noticed an attention mark on the URL bar when a...
  10. [HELP] I think I'm infected with UNKNOWN malware/virus

    in AntiVirus, Firewalls and System Security
    [HELP] I think I'm infected with UNKNOWN malware/virus: I have a newly bought laptop, an Acer Aspire E 15. What that lead me to think that I'm infected is because when I tried to visit my Windows folder (because I was searching for 'SystemApps' folder to disable Cortana) I saw random weird files with random names and all of the...