Ransomware com.apple.axsvcpd

I launched Chrome yesterday, downloaded from the official site a long time ago, and as I did, it downloaded without asking my permission some file, that I couldn't place and soon forgot about it. The nane of the file is "com.apple.axsvcpd" and it is a ransomware, it created a .txt file in my home and other big folders, that described the situation: you mihgt be looking for your photos or files and come up with nothing because they're missing? Don't bother because we've encrypted your files with [I don't remember what] and now you have 72 hours to pay us only once, email provided. No payment within 72 hours — my files are gonna be deleted.

Before that, something was eating halp of my RAM and CPU, I managed to find this file in the Library/osxmobiledata/com.apple.axsvcpd . Deleting, stopping the process in the Activity Monitor, moving, any manipulations with this file were abviousely futile. BUT: none of my files are missing for now. And the text file started with: "As soon as you get this message" — don't really know what they're talking about, there was no message, I only quick looked it because it wasn't there before. Right after Chrome sent me this surprise, I started receiving questions: allow the process track all your buttons pushed on your keyboard? and stupid crap like that. At first, I might have given it a green light for the external drive access, one partition of which is TimeMachine - also the process prevents rolling back in time. How do I know what permissions this file has? Is it curable? Somebody had a similar experience with ransom ware before?

Thanks,

Anna

MacBook Pro 15″, macOS 10.15

Posted on Aug 7, 2020 5:27 PM

Reply

Similar questions

1 reply

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Ransomware com.apple.axsvcpd

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.