I have a single computer away from my network that has been infected with a virus. It looks like it is Bitcrypt.
Symptoms:
1. Multiple instances of explorer.exe running and using a lot of memory some up to 300MB
2. All personal files (word, excel, jpg) etc., now read like filename.doc.bitcrypt
For haha's I tried to rename the file and remove the .bitcrypt and then send to another PC to open, but it does not open. File is still encrypted.
I know that there is a legit software for doing this, but this is not the case. Seems as though it is ransomware, but no notification of sorts.
Removed several things with malwarebytes. Unable to run combofix. When running it, it gets to the part of scan times may take 10 minutes etc.... but never actually scans, and starts to eat a lot of memory.
I am not totally against formatting and reloading however my concern is decrypting the files.
Any Help??? Thanks....