Help to clean my PC after BHGR ransomware

Status
Not open for further replies.

duma

New Member
Thread author
Jun 25, 2023
4
Two days ago i got infected by a virus on pc. I discovered that the virus is called BHGR ransowmare which encrypted all my PC files, asking me for a ransom in a note, and as a second thing it also inserted a Trojan, which hacked my Instagram and Facebook accounts, which fortunately I was able to act immediately (changing password etc...) and I hope I solved it. With regard to my pc files (which I tried to decrypt using Emisoft Descyptor for STOP/DJVU), on this forum I read that decryption for variants with an online key is impossible, and unfortunately the ransomware that attacked me used an online key. So, I opened this thread because now I think I have removed the virus but I'm doubtful so I would like to hope that some expert can help me to clean it eliminate any trace of the malware from my PC. Thank you
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,510
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Ensure that you are in an Administrator Account
Double-click to run it. When the tool opens click Yes to disclaimer.
Check the boxes as seen here:
L7kNU5y.jpg

Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Please attach the logs for my review.
How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
[img=[URL]http://deeprybka.trojaner-board.de/eset/eng/attachlogs.png[/URL]]

Let me know what problems persists.

Wait for further instructions

p.s.
This program is updated often.
If it's identified as suspicious by your Anti-Virus program trust it if Downloaded from the link I provided.
OR, you should restore the program from the Quarantine folder.
====
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top