I finally was able to clean the computer and get online, my initial post was closed so, I am reopening it in the hopes that Adam will continue helping me in decrypting docs. I followed Adam's previous advise and here is my reply:
Do you recognise the items in the spoiler? YES
Fixlog.txt (attached)
VirusTotal results (those 2 files ChromeUpdate.exe and psaftshf.sys were not found, evidently they were deleted by Malwarebytes I ran when cleaning the computer)
I also attached new FRST.txt and Addition.txt (if needed, I re-ran Farbar after the fix).
VirusTotal results (those 2 files ChromeUpdate.exe and psaftshf.sys were not found, evidently they were deleted by Malwarebytes I ran when cleaning the computer)
Unlikely. The latter file is legitimate.
I would still like to double-check the first file at some point.
You've made a lot of changes since the last time you posted. What happened to Panda Internet Security 2014?
There are remnants of the programme. Please run the Removal Tool(scroll down to "Solution").
From here, please refrain from making changes to your computer other than those I instruct.
β
After this round of instructions, we should be ready to attempt file recovery.
Good news is that a new brute force decrypter has been released for your file encrypter. This significantly increases the chance of successfully decrypting your files.
Click File, Save As and type fixlist.txt as the File Name.
Important: The file must be saved in the same location as FRST64.exe.
NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.
Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
Click Fix.
A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
Search for the following programmes, right-click and click Uninstall.
CWA Reminder by We-Care.com v4.1.22.3
Follow the prompts.
Note: If you are offered the choice to install additional software, ensure you decline.
Reboot if necessary.
STEP 3 [external image: MgeHyNE.png]Batch File
Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
Copy the entire contents of the codebox below and paste into the Notepad document.
@echo off
cd\
(
del /f /s /q "HELP_RESTORE_FILES.*"
del /f /s /q "HELP_TO_DECRYPT_YOUR_FILES.*"
del /f /s /q "HELP_TO_SAVE_FILES.*"
) 1> "%userprofile%\desktop\delresults.txt" 2>&1
del %0
Click Format. Ensure Wordwrap is unchecked.
Click File, Save As and name the file batchfile.bat.
Select All Files as the Save as type.
Save the file to your Desktop.
Locate batchfile.bat[external image: lmRDSkT.png] (W8/7/Vista) on your Desktop. Right-Click the file and click [external image: AVOiBNU.jpg]Run as administrator.
When the black Command Prompt disappears, attachdelresults.txt (found on your Desktop) in your next post. Please be patient.
STEP 4 [external image: mlEX1wH.png]RogueKiller
Please download RogueKiller (x64) and save the file to your Desktop.
Close any running programmes.
Right-Click RogueKiller.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
Allow the Prescan to complete. Upon completion, a window will open. Click Accept.
A browser window may open. Close the browser window.
Click [external image: jpgUwzp.png]. Upon completion, click [external image: phPvmc6.png].
Close the programme. Do not fix anything!
A log (RKreport.txt) will be open. Copy the contents of the log and paste in your next reply.
STEP 5 [external image: GzlsbnV.png]ESET Online Scan Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.
Please download ESET Online Scan and save the file to your Desktop.
Temporarily disable your anti-virus software. For instructions, please refer to the following link.
Double-click esetsmartinstaller_enu.exe to run the programme.
Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
Agree to the Terms of Use once more and click Start. Allow components to download.
Place a checkmark next to Enable detection of potentially unwanted applications.
Click Advanced settings. Place a checkmark next to:
Scan archives
Scan for potentially unsafe applications
Enable Anti-Stealth technology
Ensure Remove found threats is unchecked.
Click Start.
Wait for the scan to finish. Please be patient as this can take some time.
Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points.
Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
Push the Back button.
Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
Re-enable your anti-virus software.
Copy the contents of the log and paste in your next reply.
STEP 6 [external image: pfNZP4A.png]Logs In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
Did the Panda Removal Tool run successfully? YES, most likely I will reinstall it once we are done
Fixlog.txt (attached)
Did the programme uninstall OK? NO, it could not find the uninstaller *.msi file to complete, maybe I have to remove it manually?
delresults.txt (attached)
***Looks like the provided link to Roguekiller is broken, I found it here: http://www.fosshub.com/RogueKiller.htmland then picked up the 64x version. Yet was not able to run - it would throw an error: RogueKillerX64.exe is not a valid win32 application no matter how many times I re-downloaded the app.
Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
Copy the entire contents of the codebox below and paste into the Notepad document.
start
CreateRestorePoint:
C:\Program Files\WinZip\Utils\WzSysScan
C:\SWSETUP\APP\Applications\Corel\WinZipTrial\16.0\src\winzip160.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ApnStub.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASK3B8A.tmp
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASKA208.tmp
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASKCB25.tmp
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASKF056.tmp
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW3AED.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW6617.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW8A3B.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW97D.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW9891.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEWBF59.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEWCFCE.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\nsbB0FA.tmp.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\setup.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\miaBD48.tmp
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\{B59C74C2-754B-4C7E-9EAA-686B6372CB8D}
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\LocalLow\AskToolbar
C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_en-us.cab
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\jZipV1c.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\MyWebFace.exe
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Prudential Rock your Career_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Quicken\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Quicken\BACKUP\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\robert hotel 3 19 07_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Sample Basic Will (Annotated) - Findlaw for the Public -_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\ShopToWin\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Special Report The 23-Cent LIFE-SAVER_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Springfield Mo. Hotel receipt Weis depo trip hotel, priceline_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Texas Driver Education Schools_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\The Age Discrimination in Employment Act of 1967_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Timeliness Information for the Dallas District Office_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\TurboTax\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\TXU app stuff_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\unemployment_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\US-TX-Dallas-Legal & Regulatory Counsel_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\U_S_ Equal Employment Opportunity Commission (EEOC)_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\waffle man and the pancakes from the ukraine - CHAMPION!_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\will form_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\witnesses and depos_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Yahoo! Mail - cubsguv22@yahoo_com_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Yahoo! Mail - cubsguv22@yahoo_com_files\_;ord=1165894885439909_files\HELP_RESTORE_FILES.txt
C:\Users\Robert Buss\Desktop\Documents\MyWebFace.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ApnStub.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASK3B8A.tmp
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASKA208.tmp
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASKCB25.tmp
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASKF056.tmp
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW3AED.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW6617.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW8A3B.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW97D.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW9891.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEWBF59.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEWCFCE.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\nsbB0FA.tmp.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\setup.exe
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\miaBD48.tmp
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\{B59C74C2-754B-4C7E-9EAA-686B6372CB8D}
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\LocalLow\AskToolbar
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_en-us.cab
C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\Downloads\jZipV1c.exe
C:\Users\Robert Buss\Downloads\ccsetup410.exe
C:\Users\Robert Buss\Downloads\winzip175.exe
C:\Windows\Installer\c175a7a.msi
D:\Recovery\Logs\HELP_RESTORE_FILES.txt
D:\Recovery\system32\HELP_RESTORE_FILES.txt
D:\Recovery\system32\Recovery\HELP_RESTORE_FILES.txt
D:\Recovery\WindowsRE\HELP_RESTORE_FILES.txt
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChromeUpdate" /f
end
Click File, Save As and type fixlist.txt as the File Name.
Important: The file must be saved in the same location as FRST64.exe.
NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.
Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
Click Fix.
A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
Let me know how you get on with this one.
If this fails to recover your files, we can try restoring from Shadow Volume copies or recovery software - however, these recovery methods have a relatively low success rate unfortunately.
[external image: y3MMIrs.png]Previous Versions
Right-click the file/folder and click Properties.
Click Previous Versions.
This tab will list all copies of the file and the date they were backed up.
To restore a particular version of the file, click Copy and select the directory you wish to restore the file to.
If you wish to restore the selected file and replace the existing one, click Restore.
If you wish to view the contents of the file before restoring, click Open.
[external image: MzmiIl9.gif]ShadowExplorer
Please download ShadowExplorer and save the file to your Desktop.
Right-Click ShadowExplorer-0.9-portable.zip and click Extract All. Select your Desktop and click Extract.
Right-ClickShadowExplorer.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
You will see a drop-down menu with the shadow copies of all partitions and disks present.
Click C:\ from the drop-down menu.
To the right, pick a date prior to the infection from the drop-down menu.
To restore a whole folder, right-click on your desired folder and click Export. You will then be prompted as to where you would like to restore the contents of the folder to.
[external image: J8xQM97.png] File Recovery Software
File Recovery Software may be able to recover the original file deleted by the file encrypter.
[external image: fSA1TL4.png] R-Studio
[external image: C08PZmH.png] Photorec
[external image: uc6sByo.png] Recuva
If the above fails, I'm afraid we're out of luck at this current moment in time. However, a solution may present itself in the future. I'm going to have you backup the relevant TeslaCrypt data files in case one does present itself.
Negative on Cisco decryptor (for the same reason as the first one - decryption key was destroyed by teslacrypt), negative on previous versions and shadow explorer (as they go back only for the last 2 days). Will try Recovery, I have R-Studio and Photorec.
1. I am not sure on the date of infection - key.dat's date is 4/21/15 - is that the date?
2. Besides looking for deleted versions of all docs (doc, xls, pdf, zip, etc.) - would it make sense to search for older key.dat too?
3. Also I found interesting file on my desktop, it's called RECOVERY_KEY.TXT and contains a long HEX number - can it be used for decrypting process? I know that friend of mine (that's his computer) has attempted to correct this issue and spoke with some geeks couple of weeks ago.
1. I am not sure on the date of infection - key.dat's date is 4/21/15 - is that the date?
Difficult to say. Timestamps aren't a reliable source, and may have been altered.
2. Besides looking for deleted versions of all docs (doc, xls, pdf, zip, etc.) - would it make sense to search for older key.dat too?
Yes, this is worth an attempt.
3. Also I found interesting file on my desktop, it's called RECOVERY_KEY.TXT and contains a long HEX number - can it be used for decrypting process?
With TeslaDecoder and Cisco's decrypter failing, I don't think you're going to have any luck with decryption I'm afraid.
Once TeslaCrypt finished encrypting your files, it destroyed the decryption key in your key.dat file.
My advice is to backup your encrypted files and those listed below to a USB drive.
C:\Users\Robert Buss\Desktop\RECOVERY_KEY.TXT
C:\Users\Robert Buss\AppData\Roaming\key.dat
C:\Users\Robert Buss\AppData\Roaming\log.html
A solution may present itself in the future. I suggest you keep tabs on the following topics:
We still have a little work to do on your computer - including checking for adware/PUPs, updating vulnerable software and correctly removing the tools we've used.
If you're happy to continue, I will post the next set of instructions later today.
Please download Junkware Removal Tool and save the file to your Desktop.
Create a System Restore Point. For instructions, please refer to the following link (W7).
Temporarily disable your anti-virus software. For instructions, please refer to the following link.
Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
Follow the prompts and allow the scan to run uninterrupted.
Upon completion, a log (JRT.txt) will open on your desktop.
Re-enable your anti-virus software.
Copy the contents of JRT.txt and paste in your next reply.
STEP 2 [external image: BY4dvz9.png]AdwCleaner
Please download AdwCleaner and save the file to your Desktop.
Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
Follow the prompts.
Click Scan.
Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate.
Ensure anything you know to be legitimate does not have a checkmark, and click Clean.
Follow the prompts and allow your computer to reboot.
After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.
β File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
Using the relevant instructions below, please reset your installed browsers.
As Internet Explorer is an integral part of Windows, please ensure you reset this browser.
[external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png]Internet Explorer: How to reset Internet Explorer settings
STEP 5 [external image: pfNZP4A.png]Logs In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.
JRT.txt
AdwCleaner[S0].txt
Did your browsers reset OK?
FRST.txt
Addition.txt
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI