Recommended Posts

Your files were probably encrypted twice, with two different encryptors.

In such cases, there is almost no hope of decrypt.

This is indicated by two different extensions:
.gusau - is STOP Ransomware (in some cases, can decrypt files); 
.WWIZ - is unknown Ransomware, we don't know him.

To find out something about the second Ransomware, you need search for a note from the ransomware. It can be txt, hta, html files.

Attach files to your post. It is better to collect them in the archive. This is more important than the first extension.


Malicious files can still reside on your system and encrypt all new files.

You may need the help of our specialists.

It's best to check and make sure that no such components have been left behind, so following the instructions at the link below to get us logs from FRST and one of our experts can look of the logs (attach the log files FRST  to your new message):



Share this post

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    No registered users viewing this page.