Solved Malware removal help (possibly teslacrypt)

FairyL

New Member
Thread author
Verified
May 22, 2016
16
When I ran Maleware Bytes, it identified the virus and quarantined it, eventually removing it. Hitman Pro is showing "no threats" now. The threats diagnosed by SpyHunter 4 are "Bravenet, mediaples, xiti.com and gator" all either tracking cookies or spyware cookies. I thought I had gotten rid of the virus but now everytime I restart my computer the pop-up above keeps showing up. I don't know how to get rid of that. Please help.
As for my encrypted files, I actually had a backup on ropbox and even though it did get nfected as well, I asked dropbox to do a rollback before the date my files were deleted and I'm fairly certain I can retrieve most of my files. I'm just concerned about the pop-ups. Does it mean that my computer still has the virus ? If not, how do I get rid of the pop ups?
Also I looked it up online, and I'm not sure whether the virus is teslacrypt or cryptowall.
 

FairyL

New Member
Thread author
Verified
May 22, 2016
16
Sorry, I just scanned with Farbar and I'm attaching the FRST report
 

Attachments

  • Addition.txt
    29.2 KB · Views: 8
  • FRST.txt
    39.9 KB · Views: 14

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,


Looks like TeslaCrypt, but let's do some procedure to be completely sure about it. If this is TeslaCrypt indeed, we can restore your files.


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.



You will also find Upload.zip archive on your Desktop. Please upload it Free large file hosting. Send big files the easy way! and give me download link.
 

Attachments

  • fixlist.txt
    875 bytes · Views: 8
  • Like
Reactions: Andytay70

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Please run one more fix with this fixlist.txt attached and upload again Upload.zip archive.
 

Attachments

  • fixlist.txt
    32 bytes · Views: 7

FairyL

New Member
Thread author
Verified
May 22, 2016
16
I'm attaching the fixlog.txt but this time there was no Upload.zip archive generated.
 

Attachments

  • Fixlog.txt
    458 bytes · Views: 5

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Sorry, it was my mistake. Go to C:\FRST, right click on Quarantine, select Send to >> Compressed (zipped) folder and upload this archive.
 

FairyL

New Member
Thread author
Verified
May 22, 2016
16
That's alright. I tried that and it's saying: Compressed (zipped) folders error- file not found or no read permission
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
It seems you can use Kaspersky RannohDecryptor to save your files.

Let's first clean your PC from the remnants of infection.


FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

FairyL

New Member
Thread author
Verified
May 22, 2016
16
Is the Kaspersky RannohDecryptor found online to download free?
 

Attachments

  • FRST.txt
    41.1 KB · Views: 2
  • Addition.txt
    28.3 KB · Views: 3

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Yes, but there is a trick how to use it.

In your case, you must find the largest file that has been infected, because this infection works in that way. Only files the same size and smaller will be disinfected. Meaning if you find the largest infected file all files will be disinfected.

Let's perform FRST fix first:

FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finishes FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.



To disinfect the system:

  1. Download RannohDecryptor.zip. The following pages contain information on how to download the file.
  2. Run RannohDecryptor.exe on the infected computer.
  3. In the main window, click Start scan.
8547_RannohDecryptor_0113-313105.png


  1. Indicate path to one encrypted file and one not encrypted file.
    If the file is encrypted by Trojan-Ransom.Win32.CryptXXX, indicate the largest files. Only the files of this size or smaller ones will be decrypted.
  2. Wait until the files are found and decrypted.
  3. Reboot the computer, if needed.
 

Attachments

  • fixlist.txt
    899 bytes · Views: 2

FairyL

New Member
Thread author
Verified
May 22, 2016
16
I'm attaching the fixlog.txt
As for the RannohDecryptor, I'm downloading it now but how do I identify which of the infected files is the largest? Sorry, I'm not really techy at all.
 

Attachments

  • Fixlog.txt
    2.2 KB · Views: 1

FairyL

New Member
Thread author
Verified
May 22, 2016
16
so I think I found out how to identify the largest file. But it's showing up a 'system file' that reads 'pagefile.sys C:/' and a message pops up saying modifying the file can damage the system. It's size is 8.0GB. Should I proceed or choose another file?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
  • Please download and unpack Search Everything
  • Start Everything.exe
  • In the search field, please type exactly this:
    Code:
    *.crypt
  • It will list all the files with .crypt extension.
  • Click on Size column so it can sort them for you, putting the biggest one on the top.
  • Make a picture of this window and attach the picture in your next reply.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top