Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Please Help __prosschiff@gmail.com_.crypt strikes again... (https://www.trojaner-board.de/170681-please-help-__prosschiff-gmail-com_-crypt-strikes-again.html)

sand0kan333 04.09.2015 16:17

Please Help __prosschiff@gmail.com_.crypt strikes again...
 
Hello

I hope it is ok to post in english.

This forum is the only place in the internet I found mentioning a similar attack.

Last Monday my computer was invaded with some kind of malware.

Almost all files renamed with added "__prosschiff@gmail.com_.crypt" and encrypted.

Malware detected:
PUP Ammy Admin
Win32/Skeey.B!plock
Win32/Skeey.C!plock

Suspect file found already encrypted: RootCrypt.exe

I really need to recover some mdf files and it will be almost impossible to recreate them.



Any information, clues or any help will be very much appreciated.

Thank You

Danke sehr!

schrauber 04.09.2015 16:44

Hello, sand0kan333
Welcome to the trojaner-board.de Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.



For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to the desktop.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to the desktop.

Please run it and click Scan, post back with the 2 logfiles.

sand0kan333 04.09.2015 17:51

Scan Results
 
Hello Tom,

Thank you for taking the time!

Here goes scan results in attachments.

schrauber 04.09.2015 18:37

Hi,

sorry to say, but there is no way to decrypt your files. The only thing we could try is to cleanup the system.

Do you want to clean it or do you want to reformat it?

sand0kan333 04.09.2015 18:50

Thanks Anyway!
 
Its ok my hopes were a bit low...

But thank you for taking the time to try anyway.

I think I'll format it or hold it for police to check it and maybe trace the guy who did this..

Anyway I think I can handle the formatting thing and will recover soon from backup trauma
:headbang:


Thanks again cheers!

Danke!

schrauber 05.09.2015 13:52

You're welcome :)

sand0kan333 01.10.2015 19:37

I have good news!!!
 
I've got my files back!!! :applaus:

This worked for me:
https://support.drweb.com/new/free_unlocker/?keyno=&for_decode=1&lng=en

I had to buy their av with support around 35 euro but after sending some encrypted doc files they helped me decrypt my files!

I still can't believe it, after 1 month!!!

Best Regards,

Pedro

schrauber 02.10.2015 19:51

Thanks for letting me know :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:25 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131