Maze Ransomware 2019 - couple of questions

pollux

New Member
Thread author
Oct 30, 2019
1
Hi friends,

It seems I have troubles. I've catch a virus that encrypted all my files (actually, only 90% of them for some unknown reason) and a .txt file showed on my desktop (and in every single folder) that tells me I should pay 500 dollars to hackers and they provide me the key to decrypt the data.
I've found out the virus is called Maze Ransomware 2019.

It
1) encrypted all my files
2) put in every single folder the .txt with the announcement
3) It seems it deleted all my restore points because I have none
4) it blocks certain websites, mostly antivirus related, probably preventing me to look for a help
5) I checked regedit and some registers look totally broken (Chinese symbols and such)

So I am totally screwed.

More info:
- Their website offers to decrypt only three files as a demonstration it works, then you have to pay
- Kaspersky and other antiviruses don't seem to detect it for some reason
- All info I have found about this virus seems to be from October 2019, so it's a new thing.

I have couple of questions regarding to the virus.

1) Do you think there is a way to save my files or I can just say bye bye to them? There is probably no way to decrypt them and while all my restore points are deleted/gone, than I am terminally screwed?

2) Should I keep the files? Some sources I googled said there is a possibility that in the future there could be a new way to decrypt them and someone could create some tool and such... but is it likely? Would you keep them being me?

3) Actually the most important question - is there a way to get rid of it? What I googled, only SpyHunter 5 is recommended for this virus. But I don't know this software. Is this trustworthy? The articles about it are strange, using strange language like "This totally amazing tool will totally help you" and so on. Also it's not a free tool, so I am not sure.

4) Do you think it got into my computer using Flashplayer, Java or Adobe? Because that's the only weak-points I kinda have in my computer (except myself of course).

Thank you very much for all replies. All help is much appreciated.
 
  • Like
Reactions: upnorth

nasdaq

Super Moderator
Verified
Staff Member
Nov 5, 2019
1,597
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Sorry for this delay.

You first option is to check on this site what you re dealing with.
Submit a file sample as suggested.

The will inform you if there is a way at this time to restore your files.

Do not expect much hope of this being possible.

You can save all the compromised files on a CD or Flash drive in case a solution is found in the future.

If you have difficulties with this compute run this program and post the logs for my review.


[/b][/b]Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Attach Files.
Navigate to the location of the File.
Click the file. It will appear in the reply section.
Click the Post Reply button.

Please post the logs for my review.

Let me know what problems persists.

Wait for further instructions
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top