Results 1 to 10 of 59

Thread: remove Generic.Ransom.VxLock.E31AD1D6

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    OK
    What was found is actually a false positive and several scanners have found this.
    We can remove all folder and quarantine files when finished.,

    What's the computer doing now?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  2. #2
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    What's the computer doing now?[/QUOTE]

    Still sitting at the Scan Results window

  3. #3
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    If the scan has finished, what was found we will remove.

    Unless more is found?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  4. #4
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    I've got to sign off for the evening.
    If all that was found related to the Farbar Recovery tool then we're in good shape.

    Let me know if your ready to remove tools and quarantine folders.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #5
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    Quote Originally Posted by Juliet View Post
    I've got to sign off for the evening.
    If all that was found related to the Farbar Recovery tool then we're in good shape.

    Let me know if your ready to remove tools and quarantine folders.
    I see that Farbar found 10 files. Trusting in your guidance, I believe that I am ready to remove tools and quarantine folders. Is there a risk in doing so?

    I note that we have seen no sign of the ransom ware. Does this surprise you?

  6. #6
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Quote Originally Posted by Chris Haslam View Post
    I see that Farbar found 10 files. Trusting in your guidance, I believe that I am ready to remove tools and quarantine folders. Is there a risk in doing so?

    I note that we have seen no sign of the ransom ware. Does this surprise you?
    The files we removed with FRST was a tidy up event, they were lose files that added nothing to the machine.
    As for having a Ransomeware infection, no signs of it.
    And there was no mention of any notes or alerts telling you your computer had been infected and of money to get your files back.

    The encrypted files for this specific infection will have the extension '.VXLOCK' appended to the end of the file name and on this machine there were none.

    I can't say why, but I think what you saw was a false-positive.

    Use this tool to remove quarantined items:

    Please download KpRm by Kernel-panik and save to your Desktop.
    • Click on KpRm.exe to run the tool.

      Vista/Windows 7/8/10 users right-click and select Run As Administrator.
    • Put a check mark next to these items:

      - Delete tools
      - Delete now
    • Click the "Run" button.



    • When the tool has finished, it will create and open a log report and delete itself.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #7
    Member
    Join Date
    Jul 2009
    Posts
    95

    Default

    Thank you for your further instructions. Your idea that this is a false positive are potentially comforting!

    I am wondering a bit about EEK's new user interface. You wrote, in Post 13, that EEK would take some time to run: it ran rapidly.

    I also see in #13 that, with the old UI, I would have needed to check Run Directly. In scan...txt, I see Direct Disk Access: Off. Should I have turned it on in Settings?

    Another thought: I do not use Outlook. Is the email application I am using protecting my PC?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •