This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Ransomware Found

1 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from September 7, 2021, 2:35 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

caotuan
Malwareremoval Team:

I received notice from Windows Defender of threats found. Upon receipt of the notice, I ran a scan with Windows Defender which reported clean. I tried to run FRST64 to post to this forum, but the application would immediately close. I ran Adaware, which reported a fraud-click trojan, powelik. I cleaned through Adaware. I ran SpyBot Search & Destroy 2.0, which uncovered Win32.Ransomware.loc. I clean, quarantined, and purged the Ransomware through Spybot.

Upon startup, I receive a Script Error notice. It reports the following:

Line: 1
Char: 78
Error: Invalid root in registry key "HKCU\software\jqaf\jxkm".
Code: 0
URL:

When I click No to continuing the scripts, I receive another popup with a title concerning javascript, ActiveXObject("WScript.Shell.") for the same registry key above.

The FRST.txt and Addition.txt logs are attached.
Attachments
Addition.txt
Addition.txt
(52.54 KiB) Downloaded 5 times
FRST.txt
FRST.txt
(57.77 KiB) Downloaded 3 time
Gary R Administrator
You have not attached your FRST.txt and Addition.txt to your post.

To attach them in your next reply ....

  • Click on Full Editor button to open the forum's post editor.
  • Click on the Upload attachment button and browse to your Frst.txt file.
  • Click on the Add the file button to attach the file.
  • Click on the Upload attachment button again and browse to your Addition.txt file.
  • Click on the Add the file button to attach the file.
  • Click on the Submit button to complete things.


PS .... if you did have a Ransomware infection on your machine, then you should not have tried to remove it, as by removing it you will have removed any potential decryption key, which means that any files it has already encrypted are not likely to be recoverable.

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.