computer infected with malware please see screenshot

what do I use to get rid of it?
Who is Participating?
Russ SuterConnect With a Mentor Commented:
That isn't just malware. It's ransomware. Removing it is not the hard part. If you don't have a backup of your files you will have to make a choice:

1. Pay the ransom and hope that it works (not a guarantee and not a good idea)
2. Give up on your data and reformat your PC.

The 2nd option is probably extreme but if your data is a gonner anyway you might as well start fresh.

Basically what has happened is that a malicious program has gone through your computer and encrypted most, if not all, of your documents. A very few ransomware programs don't use very good encryption and have been cracked. You can try one of the tools designed to do that. Here are a couple of links to help you out.
A Google search for "decrypt ransomware" will reveal more.

Unfortunately, the only solid defense against this sort of ransomware is a good backup strategy. If you don't have that your chances are slim for recovering your data. Sorry, I wish I had better news for you.
frankbustosAuthor Commented:
You kidding me?
Russ SuterCommented:
Unfortunately I'm not kidding you. See those shortcuts on your desktop that look like plain documents? They are probably links to files that are now encrypted and therefore not recognized by the operating system.

There's a very good chance that all of your text documents, pictures, music files, videos, Microsoft Office documents, etc... are encrypted now. Check your documents folder and see if they have different file extensions now. They probably do. :(

If you don't already have your PC set to show file name extensions you should do that now. Open a file explorer window and click the "View" tab. Check the boxes I highlighted in the screenshot.
File Explorer OptionsKnowing what the file extension is can help identify the variant of ransomware you are dealing with and may help direct you to a solution.
This online tool can also possibly help:
WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

Fadi SODAH (aka madunix)Chief Information Security Officer, CISA, CISSP, CFR, ICATE, MCSE, CCNA, CCNP and CCIPCommented:
Most ransomware is typically programmed to automatically remove itself after the encrypting is done since they are no longer needed.  Only one thing that's a guaranteed fix - good backups.
*** Hopeleonie ***IT ManagerCommented:
Russ Suter is not kidding you and I second him.
frankbustosAuthor Commented:
Ok got it thanks
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.