Philadelphia ransomware (.locked) demonstration attack and removal tips

PCFixHelp 2017-02-16

Views 18

The video is a removal guide of Philadelphia ransomware (Russian Roulette virus) and includes demonstration of virus, removing and decryption tips. It adds to txt, jpg, bmp and other files .locked extension and changes files names.
More information about Philadelphia virus: http://pcfixhelp.net/viruses/3627-how-to-remove-philadelphia-ransomware-and-restore-the-encrypted-files
Philadelphia ransomware removal instruction
Step 1. Boot the system into safe mode
Step 2. Show all hidden files and folders
Step 3. Remove virus files
Check next folders to find suspicious files:
%TEMP%
%APPDATA%
%ProgramData%
Step 4 (optional). Clean registry
Click Start
Type Regedit.exe and press Enter
Check next registry keys:
HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
Step 5. Check hosts file
Step 6. Scan computer by antivirus
Step 7. Disable Safe mode

Emsisoft decryptor: https://decrypter.emsisoft.com/philadelphia

Share This Video


Download

  
Report form