Jump to content

pcqq on my files


Recommended Posts

On 5/10/2021 at 7:20 PM, ahmed alshatub said:

My files have been encrypted by pcqq, and the files are a graduation project, and I need to get them back.

This is a newer variant of STOP/Djvu. If you have an offline ID, then once we can find the decryption key for this variant and add it to our database you should be able to recover your files. However, if you have an online ID (which is more likely) then it will not be possible to recover your files. There is more information at the following link:
https://support.emsisoft.com/topic/32045-about-the-stopdjvu-decrypter/

Link to comment
Share on other sites

Hi,

I computer also infected this pcqq ransomware.

The systemID is offline (t1) so think I can recover my file with Emsisoft tool.

Now I am waiting till emsisoft got the new dercrytion key of this pcqq file.

Thank you

Link to comment
Share on other sites

This is good, the files need to be kept in a safe place. The computer must be securely protected. Without protection, encryption can be repeated or a new one can attack.

Link to comment
Share on other sites

2 minutes ago, Amigo-A said:

This is good, the files need to be kept in a safe place. The computer must be securely protected. Without protection, encryption can be repeated or a new one can attack.

👌👍

Link to comment
Share on other sites

Decryption capability depends on the case. Someone from the victims who paid the ransom and bought the key, if can share with this key, if will they are so generous and kind. Then the key will be entered into the Emsisoft decryptor.

Link to comment
Share on other sites

Just now, Amigo-A said:

Decryption capability depends on the case. Someone from the victims who paid the ransom and bought the key, if can share with this key, if will they are so generous and kind. Then the key will be entered into the Emsisoft decryptor.

There is one wonder i would like to ask you that: i used KIS and Malwarebyte to remove this virus but the “sskipper.exe” still install to the folder “temp” and this app detected by KIS and KIS blocked and deleted it at the moment. Every 2 minutes this app install to my PC. What can i do to remover this app permanently?

Thanks 

Link to comment
Share on other sites

6 hours ago, Viet Thinh said:

What can i do to remover this app permanently?

Let's try getting a log from FRST, and see if it shows any sign of infection. You can find instructions for downloading and running FRST at the following link:
https://help.emsisoft.com/en/1738/how-do-i-run-a-scan-with-frst/

Note: When FRST checks the Windows Firewall settings, Emsisoft Anti-Malware's Behavior Blocker will quarantine it automatically. This can be avoided by clicking "Wait, I think this is safe" in the notification that is displayed while FRST is scanning.

Link to comment
Share on other sites

19 hours ago, Viet Thinh said:

What can i do to remover this app permanently?

If the virus is active on your system, then needs to be done as GT500 said as soon as possible.
They will help you remove the active virus, otherwise, encryption or other malicious action may be repeated.

Link to comment
Share on other sites

On 5/13/2021 at 4:43 AM, GT500 said:

Let's try getting a log from FRST, and see if it shows any sign of infection. You can find instructions for downloading and running FRST at the following link:
https://help.emsisoft.com/en/1738/how-do-i-run-a-scan-with-frst/

Note: When FRST checks the Windows Firewall settings, Emsisoft Anti-Malware's Behavior Blocker will quarantine it automatically. This can be avoided by clicking "Wait, I think this is safe" in the notification that is displayed while FRST is scanning.

Wonderful !

I used FRST of Emsisoft for scan and removed "Sskiper.exe" out of my PC.

But there is new issue coming: The trojan with name: "Win32.Luckymouse.gen" infected to my PC.

I used Emergency Kit of Emsisoft to scan and remove this trojan, but this tool is not detect it. Please see the picture file

Then I used KIS for scan PC, and KIS detected this Trojan, unfortunately KIS can not delete this Trojan. Please see the picture file.

I would like to remove this Trojan. What can I do?

Please advise

Thank you.

Oh I can not upload the picture on forum, the error message: "Sorry, an unknown server error occurred when uploading this file (error code: -200)"

 

Link to comment
Share on other sites

If the Kaspersky antivirus cannot remove the trojan, then you need to choose Reboot is required to complete the disinfection or restart the PC in Safe Mode and there allow the antivirus to remove the trojan.

Link to comment
Share on other sites

1 hour ago, Amigo-A said:

If the Kaspersky antivirus cannot remove the trojan, then you need to choose Reboot is required to complete the disinfection or restart the PC in Safe Mode and there allow the antivirus to remove the trojan.

Great !

I followed your instruction, I reboot the PC after KIS scan completed then the Trojan already removed.

Thanks for your support.

Now I just wait to Emsisoft update the tool for recover my data pcqq file. I hope someone send the key to Emsisoft soon 😘

 

Link to comment
Share on other sites

It is important that no new encryption occurs.
To do this, you can install any antivirus product of the Internet Security class, which provides a trial period of up to 1 month, with a full set of protection. For example, Emsisoft Anti-Malware 
After a month, you can install another AV and also for 1 month for free. After a while, you can choose the best one, in your opinion. 

  • Upvote 1
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...