This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CryptoLocker encrypted all my docs, need help - 2 (attn: Adam) [Solved

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I finally was able to clean the computer and get online, my initial post was closed so, I am reopening it in the hopes that Adam will continue helping me in decrypting docs. I followed Adam's previous advise and here is my reply:

 

 

  • Do you recognise the items in the spoiler? YES
  • Fixlog.txt (attached)
  • VirusTotal results (those 2 files ChromeUpdate.exe and psaftshf.sys were not found, evidently they were deleted by Malwarebytes I ran when cleaning the computer)

 

I also attached new FRST.txt and Addition.txt (if needed, I re-ran Farbar after the fix).

 

Edit by paws: original topic here:

http://forums.whatthetech.com/index.php?showtopic=129597#entry866497

Hello,
 

VirusTotal results (those 2 files ChromeUpdate.exe and psaftshf.sys were not found, evidently they were deleted by Malwarebytes I ran when cleaning the computer)

Unlikely. The latter file is legitimate.
I would still like to double-check the first file at some point. 
 
You've made a lot of changes since the last time you posted. What happened to Panda Internet Security 2014? 
There are remnants of the programme. Please run the Removal Tool (scroll down to "Solution").
 
From here, please refrain from making changes to your computer other than those I instruct.  
 
β€”
 
After this round of instructions, we should be ready to attempt file recovery. 
Good news is that a new brute force decrypter has been released for your file encrypter. This significantly increases the chance of successfully decrypting your files. 
 
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    HKLM\…\Policies\Explorer: [NoControlPanel] 0
    S1 SASDIFSV; \??\C:\Users\ROBERT~1\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [X]
    S1 SASKUTIL; \??\C:\Users\ROBERT~1\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [X]
    2015-05-13 12:13 - 2015-05-13 12:13 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\{234E4DF9-E803-4C43-A642-140DE08BECE4}
    2015-05-06 08:47 - 2015-05-06 08:47 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\{D3FAD453-A290-4C44-B353-147DF9EA8E51}
    2015-05-05 15:06 - 2015-05-05 15:06 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\{33EF1A96-CAAA-4AF3-8D94-23351D1C8978}
    2015-05-04 15:24 - 2015-05-04 15:25 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\{A29DF038-E3C3-4CB4-B459-A1ECAC41CD52}
    2015-05-03 09:23 - 2015-05-03 09:23 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\{81C58831-66FC-43E9-BBFA-0EF4DE905BE0}
    2015-05-02 16:34 - 2015-05-02 16:34 - 00000000 ____D () C:\Users\Robert Buss\AppData\Local\{25246F23-BFE0-4F22-A19D-4A33A03E36A5}
    2015-05-02 16:30 - 2014-10-22 15:37 - 00000000 ___HD () C:\c2e697b
    File: C:\Users\Robert Buss\AppData\Roaming\ChromeUpdate.exe
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name. 
  • Important: The file must be saved in the same location as FRST64.exe. 

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
     

STEP 2
[external image: EtQetiM.png] Uninstall Software

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the following programmes, right-click and click Uninstall.
    • CWA Reminder by We-Care.com v4.1.22.3
  • Follow the prompts.
  • Note: If you are offered the choice to install additional software, ensure you decline.
  • Reboot if necessary.
     

STEP 3
[external image: MgeHyNE.png] Batch File

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    @echo off
    cd\
    (
    del /f /s /q "HELP_RESTORE_FILES.*"
    del /f /s /q "HELP_TO_DECRYPT_YOUR_FILES.*"
    del /f /s /q "HELP_TO_SAVE_FILES.*"
    ) 1> "%userprofile%\desktop\delresults.txt" 2>&1
    del %0
  • Click Format. Ensure Wordwrap is unchecked. 
  • Click File, Save As and name the file batchfile.bat. 
  • Select All Files as the Save as type.
  • Save the file to your Desktop. 
  • Locate batchfile.bat [external image: lmRDSkT.png] (W8/7/Vista) on your Desktop. Right-Click the file and click [external image: AVOiBNU.jpg] Run as administrator.
  • When the black Command Prompt disappears, attach delresults.txt (found on your Desktop) in your next post. Please be patient.
     

STEP 4
[external image: mlEX1wH.png] RogueKiller

  • Please download RogueKiller (x64) and save the file to your Desktop.
  • Close any running programmes.
  • Right-Click RogueKiller.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Allow the Prescan to complete. Upon completion, a window will open. Click Accept.
  • A browser window may open. Close the browser window.
  • Click [external image: jpgUwzp.png]. Upon completion, click [external image: phPvmc6.png].
  • Close the programme. Do not fix anything!
  • A log (RKreport.txt) will be open. Copy the contents of the log and paste in your next reply.
     

STEP 5
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points. 
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
     

======================================================
 
STEP 6
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Did the Panda Removal Tool run successfully?
  • Fixlog.txt
  • Did the programme uninstall OK?
  • delresults.txt (attached!)
  • RKreport.txt
  • ESET Online Scan log
  • Did the Panda Removal Tool run successfully? YES, most likely I will reinstall it once we are done
  • Fixlog.txt (attached)
  • Did the programme uninstall OK? NO, it could not find the uninstaller *.msi file to complete, maybe I have to remove it manually?
  • delresults.txt (attached)

 

***Looks like the provided link to Roguekiller is broken, I found it here: http://www.fosshub.com/RogueKiller.htmland then picked up the 64x version. Yet was not able to run - it would throw an error: RogueKillerX64.exe is not a valid win32 application no matter how many times I re-downloaded the app.

 

  • RKreport.txt (unable to install Roguekiller)
  • ESET Online Scan log (attached)

Use this link to download RogueKiller: 

http://www.bleepingcomputer.com/download/roguekiller/dl/121/

 

We'll address the other items afterwards. 

Hello, 

 

STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    C:\Program Files\WinZip\Utils\WzSysScan
    C:\SWSETUP\APP\Applications\Corel\WinZipTrial\16.0\src\winzip160.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ApnStub.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASK3B8A.tmp
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASKA208.tmp
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASKCB25.tmp
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\ASKF056.tmp
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW3AED.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW6617.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW8A3B.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW97D.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEW9891.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEWBF59.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\NEWCFCE.tmp.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\nsbB0FA.tmp.exe 
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\setup.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\miaBD48.tmp
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Local\Temp\{B59C74C2-754B-4C7E-9EAA-686B6372CB8D}
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\LocalLow\AskToolbar
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_en-us.cab
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\jZipV1c.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\MyWebFace.exe
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Prudential Rock your Career_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Quicken\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Quicken\BACKUP\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\robert hotel 3 19 07_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Sample Basic Will (Annotated) - Findlaw for the Public -_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\ShopToWin\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Special Report The 23-Cent LIFE-SAVER_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Springfield Mo. Hotel receipt Weis depo trip hotel, priceline_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Texas Driver Education Schools_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\The Age Discrimination in Employment Act of 1967_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Timeliness Information for the Dallas District Office_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\TurboTax\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\TXU app stuff_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\unemployment_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\US-TX-Dallas-Legal & Regulatory Counsel_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\U_S_ Equal Employment Opportunity Commission (EEOC)_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\waffle man and the pancakes from the ukraine - CHAMPION!_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\will form_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\witnesses and depos_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Yahoo! Mail - cubsguv22@yahoo_com_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Backup\CompUSA\Downloads\Documents\Yahoo! Mail - cubsguv22@yahoo_com_files\_;ord=1165894885439909_files\HELP_RESTORE_FILES.txt
    C:\Users\Robert Buss\Desktop\Documents\MyWebFace.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ApnStub.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASK3B8A.tmp
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASKA208.tmp
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASKCB25.tmp
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\ASKF056.tmp
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW3AED.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW6617.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW8A3B.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW97D.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEW9891.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEWBF59.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\NEWCFCE.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\nsbB0FA.tmp.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\setup.exe
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\miaBD48.tmp
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Local\Temp\{B59C74C2-754B-4C7E-9EAA-686B6372CB8D}
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\LocalLow\AskToolbar
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.50\agent\stub_data\stubinst_pkg_en-us.cab
    C:\Users\Robert Buss\Desktop\Geek Squad Data Backup 11 Aug 2013\Users\CompUSA\Downloads\jZipV1c.exe
    C:\Users\Robert Buss\Downloads\ccsetup410.exe
    C:\Users\Robert Buss\Downloads\winzip175.exe
    C:\Windows\Installer\c175a7a.msi
    D:\Recovery\Logs\HELP_RESTORE_FILES.txt
    D:\Recovery\system32\HELP_RESTORE_FILES.txt
    D:\Recovery\system32\Recovery\HELP_RESTORE_FILES.txt
    D:\Recovery\WindowsRE\HELP_RESTORE_FILES.txt
    reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChromeUpdate" /f
    end
  • Click File, Save As and type fixlist.txt as the File Name. 
  • Important: The file must be saved in the same location as FRST64.exe. 

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.

 

STEP 2
[external image: mlEX1wH.png] RogueKiller Fix

  • Close any running programmes.
  • Right-Click RogueKiller.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Allow the Prescan to complete.
  • A browser window may open. Close the browser window.
  • Click [external image: jpgUwzp.png]. 
  • Upon completion, do the following:
     
  • Click [external image: 5UKuIKl.png] and place a checkmark next to the following items. Ensure any other items are unchecked.
    • [PUM.Orphan] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | WebCheck : {E6FB5E20-DE35-11CF-9C87-00AA005127ED}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub) | (default) : {99FD978C-D287-4F50-827F-B2C658EDA8E7}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 2 (GFS Stub) | (default) : {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) | (default) : {920E6DB1-9907-4370-B3A0-BAFC03D81399}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 3 (GFS Folder) | (default) : {16F3DD56-1AF5-4347-846D-7C10C4192619}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark) | (default) : {2916C86E-86A6-43FE-8112-43ABE6BF8DCC}  -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> Found
    • [PUM.Orphan] (X86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263} | CLSID : {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16}  -> Found
    • [PUM.Desktop] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore | DisableSR : 1  -> Found
  • Click [external image: QEIRkTE.png].
     
  • Click [external image: phPvmc6.png].
  • Copy the contents of the log and paste in your next reply.

 

 


 

After carrying out the steps above, we can begin file recovery. 

 

Please see the following: 

http://www.bleepingcomputer.com/forums/t/576600/tesladecoder-released-to-decrypt-exx-ezz-ecc-files-encrypted-by-teslacrypt/

 

Let me know how you get on with the decrypter. This is one of several options we can explore. 

 

β€”

 

Once file recovery is exhausted, we still have a little more work on non-malware related issues. 

When running the decryptor I am getting this log:

 

Data file found >> C:\Users\Robert Buss\AppData\Roaming\key.dat
Data file version 3 recognized.
ERROR - Decryption key is not present in data file.
Decryption key was destroyed by TeslaCrypt.
Unfortunately this tool can't recover decryption key. :-(
Trying to load data file from disk…
ERROR - Data file not found.
 
*** You can load data file manually by clicking on Load data file button. ***

Our next option is the decrypter released by Cisco:
http://www.bleepingcomputer.com/forums/t/574560/ciscos-talos-group-releases-decryptor-for-teslacrypt/
 
Let me know how you get on with this one.
If this fails to recover your files, we can try restoring from Shadow Volume copies or recovery software - however, these recovery methods have a relatively low success rate unfortunately. 

[external image: y3MMIrs.png] Previous Versions

  • Right-click the file/folder and click Properties.
  • Click Previous Versions.
  • This tab will list all copies of the file and the date they were backed up.
  • To restore a particular version of the file, click Copy and select the directory you wish to restore the file to.
  • If you wish to restore the selected file and replace the existing one, click Restore.
  • If you wish to view the contents of the file before restoring, click Open.
     

[external image: MzmiIl9.gif] ShadowExplorer

  • Please download ShadowExplorer and save the file to your Desktop.
  • Right-Click ShadowExplorer-0.9-portable.zip and click Extract All. Select your Desktop and click Extract.
  • Right-Click ShadowExplorer.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • You will see a drop-down menu with the shadow copies of all partitions and disks present.
  • Click C:\ from the drop-down menu.
  • To the right, pick a date prior to the infection from the drop-down menu.
  • To restore a whole folder, right-click on your desired folder and click Export. You will then be prompted as to where you would like to restore the contents of the folder to.
     

[external image: J8xQM97.png] File Recovery Software
File Recovery Software may be able to recover the original file deleted by the file encrypter.

  • [external image: fSA1TL4.png] R-Studio
  • [external image: C08PZmH.png] Photorec
  • [external image: uc6sByo.png] Recuva
     

If the above fails, I'm afraid we're out of luck at this current moment in time. However, a solution may present itself in the future. I'm going to have you backup the relevant TeslaCrypt data files in case one does present itself.

Negative on Cisco decryptor (for the same reason as the first one - decryption key was destroyed by teslacrypt), negative on previous versions and shadow explorer (as they go back only for the last 2 days). Will try Recovery, I have R-Studio and Photorec.

1. I am not sure on the date of  infection - key.dat's date is 4/21/15 - is that the date?

2. Besides looking for deleted versions of all docs (doc, xls, pdf, zip, etc.) - would it make sense to search for older key.dat too?

3. Also I found interesting file on my desktop, it's called RECOVERY_KEY.TXT and contains a long HEX number - can it be used for decrypting process? I know that friend of mine (that's his computer) has attempted to correct this issue and spoke with some geeks couple of weeks ago. 

 

Thank you!

1. I am not sure on the date of  infection - key.dat's date is 4/21/15 - is that the date?

Difficult to say. Timestamps aren't a reliable source, and may have been altered. 
 

2. Besides looking for deleted versions of all docs (doc, xls, pdf, zip, etc.) - would it make sense to search for older key.dat too?

Yes, this is worth an attempt.
 

3. Also I found interesting file on my desktop, it's called RECOVERY_KEY.TXT and contains a long HEX number - can it be used for decrypting process?

With TeslaDecoder and Cisco's decrypter failing, I don't think you're going to have any luck with decryption I'm afraid. 
Once TeslaCrypt finished encrypting your files, it destroyed the decryption key in your key.dat file. 
 
My advice is to backup your encrypted files and those listed below to a USB drive.

  • C:\Users\Robert Buss\Desktop\RECOVERY_KEY.TXT
  • C:\Users\Robert Buss\AppData\Roaming\key.dat
  • C:\Users\Robert Buss\AppData\Roaming\log.html
     

A solution may present itself in the future. I suggest you keep tabs on the following topics:

We still have a little work to do on your computer - including checking for adware/PUPs, updating vulnerable software and correctly removing the tools we've used.

If you're happy to continue, I will post the next set of instructions later today.

Hello, 

 

Please work your way through the following, and let me know how you get on. 

 

STEP 1
[external image: E3feWj5.png] Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Create a System Restore Point. For instructions, please refer to the following link (W7).
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts and allow the scan to run uninterrupted. 
  • Upon completion, a log (JRT.txt) will open on your desktop.
  • Re-enable your anti-virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 2
[external image: BY4dvz9.png] AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts. 
  • Click Scan. 
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate. 
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean. 
  • Follow the prompts and allow your computer to reboot. 
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
 
 
STEP 3
[external image: b8zkrsY.png] Browser Reset
 
Before proceeding, please refer to the following instructions on how you can backup your Favourites/Bookmarks.

  • [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png] Internet Explorer: Backup Internet Explorer Favourites
  • [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg] Firefox: Backup Firefox Bookmarks
  • [external image: U5NwUGc.png] Chrome: Backup Chrome Bookmarks
     

Using the relevant instructions below, please reset your installed browsers.
As Internet Explorer is an integral part of Windows, please ensure you reset this browser.

  • [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png] Internet Explorer: How to reset Internet Explorer settings
  • [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg] Firefox: Reset Firefox
  • [external image: U5NwUGc.png] Chrome: Chrome - Reset browser settings
     

STEP 4
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Right-Click FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply. 
     

======================================================

STEP 5
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • JRT.txt
  • AdwCleaner[S0].txt
  • Did your browsers reset OK?
  • FRST.txt
  • Addition.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI