Share via

I accidentally downloaded a virus

Anonymous
2018-12-12T18:15:56+00:00

I accidentally downloaded a virus and it deleted some important files like windows10upgrade. 

I tries rebooting my drives completly and it didnt work.

I think its because it deleted windows10upgrade. 

If anyone can help me i will be grateful

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

10 answers

Sort by: Most helpful
  1. quietman7 MVP Alumni 19,735 Reputation points Volunteer Moderator
    2018-12-13T21:26:16+00:00

    Yes, it is most likely a new variant of GlobeImposter which often uses the how_to_back_files.html ransom note among others.

    The best way to identify the different ransomwares is the ransom note (including it's name), samples of the encrypted files, any obvious extensions appended to the encrypted files, information related to any email addresses or hyperlinks provided by the cyber-criminals to request payment and the malware file responsible for the infection.

    Without the above information or if this is something new (or there is no extension or filemarker in encrypted files), our crypto malware experts most likely will need a sample of the malware file itself to analyze before anyone can ascertain if the encrypted files can even be decrypted. Samples of any suspicious executable's (installer, malicious files, attachments) that you suspect were involved in causing the infection can be submitted (uploaded) here with a link to this topic.

    Unfortunately, there is no known method to decrypt files encrypted by all the latest versions of GlobeImposter 2.0 without paying the ransom (unless the TOR site is abandoned) since there is no way to retrieve the malware developer's private key that can be used to decrypt your files. Without the master private RSA key that can be used to decrypt your files, decryption is impossible. If feasible, your best option is to restore from backups, try file recovery software or backup/save your encrypted data as is and wait for a possible solution at a later time. Ignore all Google searches which provide links to bogus and untrustworthy removal/decryption guides.

    When dealing with ransomware, there is no way to know for sure if the cyber-criminals actually steal any of the data or sensitive file information for further criminal activity but I am not aware of any such cases. Rather than the content of your data, they are more interested in obtaining a ransom payment for financial gain. These criminals are in business to make money and make it fast, then move on to the next victim. Although some criminals may threaten to release (expose) information if victims do not pay, uploading someone's data for such nefarious purposes takes too much time and could leave a trail for law enforcement authorities to follow.

    Crypto malware will scan and encrypt just about any type of data file it finds but some target more than others. Some types of ransomware (i.e. DMA Locker, Gomasom, CryptoFortress, UmbreCrypt) utilize a white list of folders and extensions that they will not encrypt. By using a white list, the malware will encrypt almost all non-system and non-executable related files that it finds. Targeting critical system files and executables which could render a system unbootable serves no purpose. Since the malware developers are in business to make money, they need their victims to pay the ransom in order to decrypt valuable data files. ..that typically means the criminals want the computer to be functional without giving the victim access to their data until after the ransom payment has been received.

    The problem with this type of infection is that most victims do not realize they have been infected until the ransomware displays the ransom note and the files have already been encrypted. In some cases there may be no ransom note and discovery only occurs at a later time when attempting to open an encrypted file. As such, they don't know how long the malware was on the system before being alerted or if other malware was downloaded and installed along with the ransomware. If other malware was involved it may be the reason for your booting issues.

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-12-13T17:43:44+00:00

    I dont really care about my files, I didnt save any credit card and i changed my email adress password no paypal, no important passwords and i only try to focus on rebooting my pc, i wanted in the past to clean my pc and i cant do that, are those files important for rebooting? because i

    get an error that says "There was an error refreshing your pc" And the precentage doesnt go more than 1% in the rebooting loading screen

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-12-13T12:00:47+00:00

    Hi,

    Thank you for writing to Microsoft Community Forums. 

    1. May I know, if you remember from where did you downloaded the virus?
    2. Have you lost any other data like Music, pictures, documents etc.?
    3. Which version of Windows is installed on the computer?
    4. May I know, what you mean when you say "I tries rebooting my drives completely and it didn’t work."?

    As you mention regarding the Windows10Upgrade folder, this folder is created when you install and run Windows 10 upgrade assistance tool, once you complete the upgrade and uninstall the tool, this folder will be removed automatically.

    If you are able to get to the desktop screen, we will have to run a Virus scan to detect the virus on the system and let the antivirus program to delete it.

    Method 1:

    1. Open Windows Defenderfrom the start menu or you can click the Windows defender icon from the taskbar at the bottom right corner of the screen.
    2. Click on Virus & threat protection.
    3. Click on Run a new advanced scan.
    4. Check the radio button Full scan.
    5. And Click on Scan now.

    Method 2:

    1. I also suggest you to run Microsoft Safety Scanner and check if that helps.

    Note: Safety Scanner only scans when manually triggered and is available for use 10 days after being downloaded. We recommend that you always download the latest version of this tool before each scan.

       2. If you still face the issue, you can check How to remove malware or viruses from my Windows 10 PC.

    If you still face the issue, please reply to this post with more information, so that we can help you fix this issue.

    Hope it helps.

    Amit Sunar

    Microsoft Community – Moderator

    3 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-12-13T16:46:00+00:00

    Might be a Globeimposter variant...

    If so, the specific help/info thread would be this one: https://www.bleepingcomputer.com/forums/t/644166/globeimposter-ransomware-support-crypt-pscrypt-ext-back-fileshtml/

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-12-13T15:50:19+00:00
    2 people found this answer helpful.
    0 comments No comments