• ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
Are you having HotKey issues? Click here for tips and tricks.
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended
HP pavilion x360 cd0087tu
Microsoft Windows 10 (64-bit)

My PC was recently infected with a Phobos ransomware where all my files were encrypted by the virus and every file had an extension

This also occurred to many system files and RECOVERY partition. I have copied the absolute necessary files to a USB pen drive hoping for a decryptor in future but until then, I want my PC to go back to normal. I have removed all the threats by a full scan using MalwareBytes.

1. If you know any way to recover the encrypted files, please help but I do realise that is not possible yet

2. What software should I use to scan my PC furthur or is just MalwareBytes enough?

2. How do I reset my PC to factory condition? I want to retain my original copy of Windows and MS Office Home and Student.

 

I can enter Recovery by pressing the F11 key at startup but online articles advice that the ransomware might have tampered with the recovery which s evident from the change in extensions of all files in the recovery partition. 

 

Please help ASAP, all my work is on PC!

Thanks in advance

1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

@Harnoor 

There is no guaranteed way to retain usage of a PC but eliminate all the traces of malware.  AV products can only do so much. If malware is encoded and hidden away inside archive files, the AV products simply may be unable to see it.  The only SAFE option is to erase the drive and restart from scratch with a fresh copy of Windows.

 

Unless a "crack" for the specific ransomware has been published, there is no way to get those files back.  They change these constantly, so there is no general-purpose decrypter out there.

 

You basically can't "retain" what you have and while you might be able to restore the PC to working condition using HP Recovery Media, that will NOT contain any MS Office products, so you will lose those. This is one of the key reasons for regularly doing System Image backups.

 

To find out if it's even possible to get MS Office back, you will have to contact HP Customer Support directly...

 

HP International Support: http://welcome.hp.com/country/w1/en/support.html

HP Phone Support: https://www8.hp.com/us/en/contact-hp/ww-phone-assist.html

 

If your PC is a 2016 model or newer, you should see if you can make a bootable USB recovery drive using the HP cloud recovery tool on a working PC.

The recovery drive can then be used to install Win10 and the HP drivers and utilities that originally came with your PC.

Here is the link: https://support.hp.com/us-en/document/c06162205



I am a volunteer and I do not work for, nor represent, HP

View solution in original post

1 REPLY 1
HP Recommended

@Harnoor 

There is no guaranteed way to retain usage of a PC but eliminate all the traces of malware.  AV products can only do so much. If malware is encoded and hidden away inside archive files, the AV products simply may be unable to see it.  The only SAFE option is to erase the drive and restart from scratch with a fresh copy of Windows.

 

Unless a "crack" for the specific ransomware has been published, there is no way to get those files back.  They change these constantly, so there is no general-purpose decrypter out there.

 

You basically can't "retain" what you have and while you might be able to restore the PC to working condition using HP Recovery Media, that will NOT contain any MS Office products, so you will lose those. This is one of the key reasons for regularly doing System Image backups.

 

To find out if it's even possible to get MS Office back, you will have to contact HP Customer Support directly...

 

HP International Support: http://welcome.hp.com/country/w1/en/support.html

HP Phone Support: https://www8.hp.com/us/en/contact-hp/ww-phone-assist.html

 

If your PC is a 2016 model or newer, you should see if you can make a bootable USB recovery drive using the HP cloud recovery tool on a working PC.

The recovery drive can then be used to install Win10 and the HP drivers and utilities that originally came with your PC.

Here is the link: https://support.hp.com/us-en/document/c06162205



I am a volunteer and I do not work for, nor represent, HP
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.