Ransomware cleanup question

I have Norton 360 on my laptop - can I scan an external system ( from a close friend’s system ) by connecting the bad system SSD via usb..

The SSD to be scanned is the SSD I placed into a HUB as it has Ransomware - and I do not believe scanning it from my laptop can also get the that Ransomware - as long as I only Scan with my 360 Norton and do not pull in any files from it ??

It might depend on what ransomware is on that drive? Do you know? Does not matter how close a friend had this happen to them.

Fixing ransomware is not just a matter of an anti virus scan. There will be files on that drive that got encrypted.

1 Like

@TheChazz I have some AI generated information for you that you may consider.

AI Overview

To scan a removed SSD for ransomware, connect it to a clean computer via a USB-to-SATA/NVMe enclosure, ensure it is treated as a non-bootable external drive, and scan it with updated antimalware tools like Malwarebytes or Windows Defender. Do not attempt to open any files on the drive during this process.

Steps to Scan a Removed SSD

  1. Isolate the SSD: Physically remove the SSD from the infected machine.
  2. Connect Securely: Use an external USB enclosure or drive dock to connect the drive to a different, known-clean computer.
  3. Prevent Auto-run: Ensure the clean computer is configured not to automatically open or execute files from external drives (turn off AutoPlay).
  4. Scan with Antivirus: Use Malwarebytes, Kaspersky Virus Removal Tool, or Windows Defender. Perform a “Custom Scan” or “Deep Scan” explicitly targeting the external drive letter.
  5. Remove Threats: If ransomware executables are found, allow the software to remove or quarantine them to prevent re-infection.

Post-Scan Data Recovery

  • Decryption Check: If files are encrypted, removing the ransomware does not unlock them. Check the ransomware note (if you found one) or search on the No More Ransom Project to see if a free decryptor exists.
  • Recovery Software: Use tools like Wondershare Recoverit to scan for unencrypted versions of files that may have been copied, deleted, and partially overwritten.

Key Considerations

  • System Files: Do not run, open, or transfer any .exe, .bat, or .vbs files from the infected drive, as these likely contain the ransomware.
  • SSD Nature: Because of TRIM functionality, data recovery on SSDs is time-sensitive; files might be permanently removed by the drive controller if not rescued promptly.

SA

1 Like

I really appreciate both of you Guru’s responding to my posting !!

Regards,

Chuck

You’re welcome!! Please let us know how things go.

SA