GandCrab Ransomware
My Macbook infected Ransomware name "GandCrab". I cannot open my files in local disk and iCloud as well.
What should i do?
My Macbook infected Ransomware name "GandCrab". I cannot open my files in local disk and iCloud as well.
What should i do?
I've been doing research on this, and haven't found any signs of a Mac version of GandCrab yet. There are a couple possibilities.
1) You could be affected by something brand new that nobody has seen yet. If so, it'll be critically important to get as much information from you about what happened as possible.
2) If the affected disks have been accessed from a Windows machine, it's possible that the Windows machine was infected, and that resulted in encryption of files on the affected disks. This is actually the more common case to-date, as Mac ransomware has yet to be very successful.
Let us know more details so that we can identify what's going on in your case.
I've been doing research on this, and haven't found any signs of a Mac version of GandCrab yet. There are a couple possibilities.
1) You could be affected by something brand new that nobody has seen yet. If so, it'll be critically important to get as much information from you about what happened as possible.
2) If the affected disks have been accessed from a Windows machine, it's possible that the Windows machine was infected, and that resulted in encryption of files on the affected disks. This is actually the more common case to-date, as Mac ransomware has yet to be very successful.
Let us know more details so that we can identify what's going on in your case.
GandCrab is not something currently known to infect Macs, only Windows machines. What are you seeing that indicates that you're infected with GandCrab?
Since I noted it occurred with Window system, I deleted Window VM and uninstall parallel desktop program. No spreading of the infected files anymore.
I agree with Thomas. I used parallel desktop to run window. It might infected from this. Then it encrypted my files in local hard disk and the files were upload to cloud drive automaticall. Finally, the files in cloud drive are affected. I note that it encrypted with I turn on window.
First of all, I thought it didn’t change the extension of file name. So the files should be safe. But actually, I could not open the files even with macbook, iPad, iphone or safari browse. All of files are modified in the same date and time.
Fortunately, the keynote can recovery the old version of files. However, I lost all of pdf files.
Try to download this program which was written by Thomas Reed, a long time poster. I don't know if the program has been updated to remove this or not.
Malwarebytes Anti-Malware for Mac 10.10 and later
Do you have a Windows machine set up with access to iCloud? Are you actually unable to open those various files? They don't look like they have had their extensions changed. Is the only change on iCloud the presence of the GDCB-DECRYPT file?
This is what happened in my iClound.
Does your Windows system in Parallels have access to the drives that were encrypted, including the iCloud drive? If so, that's likely what happened. Is that Windows system similarly infected?
Sounds good. If you need to run windows in something like Parallels in the future, be sure to run a good anti-virus program in the Windows system, and be cautious what folders you give that system access to on your Mac. Also, be sure you're keeping your data thoroughly backed up, if you're not already, so that if something like this happens again, you can recover easily.
GandCrab Ransomware