Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Crypotlocker or copycat infected computer


  • This topic is locked This topic is locked
9 replies to this topic

#1 Jimmybub

Jimmybub

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:30 AM

Posted 11 November 2014 - 12:56 PM

  We have a client with a crypto locker virus on her computer.  We ran combofix and other antivirus programs, and eventually did a system restore.  I tried to supply an encrypted file to https://www.decryptcryptolocker.com/ but it gave me the following message "invalid file:  this file does not appear to be encrypted by cryptolocker, please submit a cryptolocker encrypted file."  I looked this error up on google, and it seems that the encrypter on this computer is either an updated version of cryptolocker or a copycat.  Superantispyware found the executable for the virus, and deleted it.  The name of the executable and other viruses removed can be viewed in the log from the spoiler below:

Spoiler

 

EDIT: miss spelled Cryptolocker..


Edited by Jimmybub, 11 November 2014 - 03:11 PM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,660 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:30 AM

Posted 16 November 2014 - 01:00 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/555718 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 Jimmybub

Jimmybub
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:30 AM

Posted 19 November 2014 - 11:25 AM

1.  A clients files were locked with an encrypter virus, already tried the decryptcryptolocker.com website.  The website said that the files were not encrypted by cryptolocker.  we had to do a wipe of the computer as we could not fix the problem, and backed up what we could.

 

2.  I'm not sure what a dds log would do, as the computer has been wiped.  It has also been returned to the client with necessary programs re-installed.

 

3.  we do not have the original, but we do have the same OS disk



#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:30 PM

Posted 20 November 2014 - 03:12 PM

Greetings,

Sorry about the delay. Are you still requesting help?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 Jimmybub

Jimmybub
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:30 AM

Posted 21 November 2014 - 12:56 PM

Yes, I'd really like to figure out if the files are savable.  The computer was already returned to the customer, but It it seems we have been getting a lot of encryter viruses recently. We had another case like this a couple of weeks ago at a doctor's office..  It'd be good to figure this one out so I don't have to pester you guys in the future :P    Is there a way to get a log that includes the backed up files? I got one after I wiped the computer, but I'm not sure what good that would do.
EDIT: the spoiler is a log from the wiped computer


DDS (Ver_2012-11-20.01) - NTFS_x86 
Internet Explorer: 11.0.9600.17420
Run by user1 at 15:00:42 on 2014-11-19
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.3570.2227 [GMT -5:00]
.
AV: Bitdefender Antivirus *Enabled/Updated* {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
SP: Bitdefender Antispyware *Enabled/Updated* {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_FATIFJA.EXE
C:\Program Files\Dentrix\DtxQuickLaunch.exe
C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Dentrix\Apptbook.exe
C:\Program Files\Bitdefender\Bitdefender\odscanui.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
BHO: Bitdefender Wallet: {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - c:\program files\bitdefender\bitdefender\pmbxie.dll
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office 15\root\office15\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [EPSON WorkForce 610 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifja.exe /fu "c:\windows\temp\E_S450B.tmp" /EF "HKCU"
uRun: [DtxQuickLaunch.exe] c:\program files\dentrix\DtxQuickLaunch.exe
uRun: [Bitdefender Wallet Agent] "c:\program files\bitdefender\bitdefender\pmbxag.exe"
uRun: [Bitdefender Wallet] "c:\program files\bitdefender\bitdefender\pwdmanui.exe" --hidden --nowizard
uRun: [Bitdefender Wallet Application Agent] "c:\program files\bitdefender\bitdefender\bdapppassmgr.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe
mRun: [FUFAXSTM] "c:\program files\epson software\fax utility\FUFAXSTM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Bdagent] "c:\program files\bitdefender\bitdefender\bdagent.exe"
mRun: [ScreenPrint32] c:\program files\screenprint32 v3\ScreenPrint32.exe -startup
dRun: [Bitdefender Wallet Agent] "c:\program files\bitdefender\bitdefender\pmbxag.exe"
dRun: [Bitdefender Wallet] "c:\program files\bitdefender\bitdefender\pwdmanui.exe" --hidden --nowizard
dRun: [Bitdefender Wallet Application Agent] "c:\program files\bitdefender\bitdefender\bdapppassmgr.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\websyn~1.lnk - c:\program files\dentrix\WebSyncReminder.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: NameServer = 192.168.1.4 192.168.1.3
TCP: Interfaces\{C36DA438-80E4-4662-AECE-8ECA45D0A862} : DHCPNameServer = 192.168.1.4 192.168.1.3
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - c:\program files\microsoft office 15\root\office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\38.0.2125.122\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2014-11-14 1060312]
R0 gzflt;gzflt;c:\windows\system32\drivers\gzflt.sys [2014-11-14 165744]
R1 bdfwfpf;bdfwfpf;c:\program files\common files\bitdefender\bitdefender firewall\bdfwfpf.sys [2014-11-14 90704]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-1-26 176128]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;c:\program files\microsoft office 15\clientx86\officeclicktorun.exe [2014-11-14 1674928]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IPROSetMonitor.exe [2014-11-13 109728]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2014-11-13 2656280]
R2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\bitdefender\bitdefender\updatesrv.exe [2014-11-14 54424]
R3 avchv;avchv Function Driver;c:\windows\system32\drivers\avchv.sys [2014-11-14 242504]
R3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2014-11-14 528248]
R3 MEI;Intel® Management Engine Interface;c:\windows\system32\drivers\HECI.sys [2014-11-13 41088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys [2014-11-14 66832]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\ieetwcollector.exe [2014-11-13 102912]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2014-11-14 14848]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2014-11-14 49152]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
.
=============== Created Last 30 ================
.
2014-11-17 20:12:53 -------- d-----w- C:\PreXion3DViewer
2014-11-17 20:12:14 -------- d-----w- c:\program files\ScreenPrint32 v3
2014-11-17 20:12:05 73216 ----a-w- c:\windows\ST6UNST.EXE
2014-11-17 20:12:05 249856 ------w- c:\windows\Setup1.exe
2014-11-17 20:11:41 280064 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzppw71.dll
2014-11-14 20:33:40 1060312 ----a-w- c:\windows\system32\drivers\avc3.sys
2014-11-14 20:33:39 72704 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2014-11-14 20:33:36 27168 ----a-w- c:\windows\system32\bdsandboxuh.dll
2014-11-14 20:33:11 74512 ----a-w- c:\windows\system32\bdsandboxuiskin.dll
2014-11-14 19:55:34 -------- d-----w- c:\users\user1.katz\appdata\local\Danaher_Dental
2014-11-14 19:55:34 -------- d-----w- c:\programdata\Danaher_Dental
2014-11-14 19:50:07 691933 ----a-w- c:\programdata\1415994217.bdinstall.bin
2014-11-14 19:48:04 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2014-11-14 19:48:00 -------- d-----w- c:\programdata\BDLogging
2014-11-14 19:47:51 66832 ----a-w- c:\windows\system32\drivers\bdsandbox.sys
2014-11-14 19:47:51 511328 ----a-w- c:\windows\capicom.dll
2014-11-14 19:47:48 528248 ----a-w- c:\windows\system32\drivers\avckf.sys
2014-11-14 19:47:48 242504 ----a-w- c:\windows\system32\drivers\avchv.sys
2014-11-14 19:46:52 -------- d-----w- c:\users\user1.katz\appdata\roaming\Bitdefender
2014-11-14 19:43:57 165744 ----a-w- c:\windows\system32\drivers\gzflt.sys
2014-11-14 19:43:57 -------- d-----w- c:\programdata\Bitdefender
2014-11-14 19:43:56 385096 ----a-w- c:\windows\system32\drivers\trufos.sys
2014-11-14 19:43:56 -------- d-----w- c:\program files\Bitdefender
2014-11-14 19:43:37 -------- d-----w- c:\users\user1.katz\appdata\roaming\QuickScan
2014-11-14 19:39:19 -------- d-----w- c:\program files\common files\Bitdefender
2014-11-14 19:38:20 -------- d-----w- c:\windows\system32\Fusion
2014-11-14 19:37:03 -------- d-----w- C:\DEXIS
2014-11-14 19:21:35 -------- d-----w- c:\program files\Microsoft OneDrive
2014-11-14 19:21:35 -------- d-----r- c:\users\user1.katz\OneDrive
2014-11-14 19:21:27 -------- d-----w- c:\programdata\Microsoft OneDrive
2014-11-14 19:18:37 590536 ----a-w- c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\integrator.exe
2014-11-14 19:18:01 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2014-11-14 19:14:40 -------- d-----w- c:\program files\Microsoft Office 15
2014-11-14 18:53:58 -------- d-sh--w- c:\users\user1.katz\appdata\local\EmieUserList
2014-11-14 18:53:58 -------- d-sh--w- c:\users\user1.katz\appdata\local\EmieSiteList
2014-11-14 18:53:58 -------- d-sh--w- c:\users\user1.katz\appdata\local\EmieBrowserModeList
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2014-11-14 18:53:46 143360 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2014-11-14 18:51:31 -------- d-----w- c:\program files\Windows Journal Viewer
2014-11-14 18:51:08 499712 ----a-w- c:\windows\system32\MSVCP71.DLL
2014-11-14 18:51:08 348160 ----a-w- c:\windows\system32\MSVCR71.DLL
2014-11-14 18:51:08 1060864 ----a-w- c:\windows\system32\MFC71.DLL
2014-11-14 18:51:02 -------- d-----w- c:\users\user1.katz\appdata\roaming\Softland
2014-11-14 18:50:59 27472 ----a-w- c:\windows\system32\novamnv7.dll
2014-11-14 18:50:59 21840 ----a-w- c:\windows\system32\novamiv7.dll
2014-11-14 18:50:59 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2014-11-14 18:50:54 -------- d-----w- c:\program files\Softland
2014-11-14 18:50:53 -------- d-----w- c:\programdata\DtxDocCenter
2014-11-14 18:50:40 -------- d-----w- c:\program files\common files\Borland Shared
2014-11-14 18:50:22 -------- d-----w- c:\program files\Dentrix
2014-11-14 18:41:22 -------- d-----w- C:\inetpub
2014-11-14 18:41:20 -------- d-----w- c:\program files\SAP BusinessObjects
2014-11-14 18:40:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
2014-11-14 18:39:17 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2014-11-14 18:31:56 -------- d-----w- c:\users\user1.katz\appdata\local\Adobe
2014-11-14 18:31:06 282624 ----a-w- c:\program files\common files\installshield\updateservice\agent.exe
2014-11-14 18:26:34 90624 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HPZPPWN7.DLL
2014-11-14 18:24:11 -------- d-----w- c:\users\user1.katz\appdata\local\Google
2014-11-14 15:53:15 2744320 ----a-w- c:\windows\system32\rdpcorets.dll
2014-11-14 15:53:05 5703168 ----a-w- c:\windows\system32\mstscax.dll
2014-11-14 15:46:31 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-11-14 15:37:19 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-11-14 15:37:19 701104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-11-14 14:46:03 2285056 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2014-11-14 14:41:00 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2014-11-14 08:33:10 1247744 ----a-w- c:\windows\system32\DWrite.dll
2014-11-14 08:27:18 0 ----a-w- c:\windows\ativpsrm.bin
2014-11-14 08:26:01 -------- d-s---w- c:\windows\system32\CompatTel
2014-11-13 22:28:28 229000 ------w- c:\windows\system32\MpSigStub.exe
2014-11-13 22:12:06 -------- d-----w- c:\windows\Migration
2014-11-13 21:56:04 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-11-13 21:56:04 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-11-13 21:56:04 613888 ----a-w- c:\windows\system32\WUDFx.dll
2014-11-13 21:56:04 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-11-13 21:56:04 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2014-11-13 21:56:04 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-11-13 21:56:04 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-11-13 21:55:29 99480 ----a-w- c:\windows\system32\infocardapi.dll
2014-11-13 21:55:28 8856 ----a-w- c:\windows\system32\icardres.dll
2014-11-13 21:55:27 619672 ----a-w- c:\windows\system32\icardagt.exe
2014-11-13 21:55:26 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-11-13 21:55:00 5120 ----a-w- c:\windows\system32\wmi.dll
2014-11-13 21:55:00 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-11-13 21:47:19 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2014-11-13 21:47:18 164864 ----a-w- c:\program files\windows media player\wmplayer.exe
2014-11-13 21:41:52 49152 ----a-w- c:\windows\system32\taskhost.exe
2014-11-13 21:39:57 1505280 ----a-w- c:\windows\system32\d3d11.dll
2014-11-13 21:36:53 -------- d-----w- c:\windows\system32\MRT
2014-11-13 21:34:59 87040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2014-11-13 21:33:59 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2014-11-13 21:22:27 826880 ----a-w- c:\windows\system32\rdpcore.dll
2014-11-13 21:22:27 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2014-11-13 20:08:23 109728 ----a-w- c:\windows\system32\IPROSetMonitor.exe
2014-11-13 20:08:13 2425856 ----a-w- c:\windows\system32\wucltux.dll
2014-11-13 20:08:06 92672 ----a-w- c:\windows\system32\wudriver.dll
2014-11-13 20:07:59 33792 ----a-w- c:\windows\system32\wuapp.exe
2014-11-13 20:07:59 179656 ----a-w- c:\windows\system32\wuwebv.dll
2014-11-13 20:07:33 266440 ----a-r- c:\windows\system32\PROUnstl.exe
2014-11-13 20:06:46 68264 ----a-w- c:\windows\system32\e1cmsg.dll
2014-11-13 20:06:46 28792 ----a-w- c:\windows\system32\NicCo36.dll
2014-11-13 20:06:46 238760 ----a-w- c:\windows\system32\drivers\e1c6232.sys
2014-11-13 20:06:45 75456 ----a-w- c:\windows\system32\NicInstC.dll
2014-11-13 20:06:28 8192 ----a-r- c:\windows\system32\drivers\IntelMEFWVer.dll
2014-11-13 20:06:24 -------- d-----w- c:\program files\common files\postureAgent
2014-11-13 20:06:22 41088 ----a-w- c:\windows\system32\drivers\HECI.sys
2014-11-13 20:02:46 53248 ----a-r- c:\windows\system32\CSVer.dll
2014-11-13 20:02:40 -------- d-----w- C:\Intel
2014-11-13 20:01:58 -------- d-----w- c:\program files\MSXML 4.0
2014-11-13 20:01:56 -------- d-sh--w- c:\windows\Installer
2014-11-13 20:01:52 -------- d-----w- C:\TempEI4
2014-11-13 19:59:42 -------- d-sh--w- C:\Recovery
2014-11-13 19:24:39 -------- d-----w- c:\windows\Panther
.
==================== Find3M  ====================
.
2014-11-13 21:40:47 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-11-06 02:51:33 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-11-05 17:50:47 254464 ----a-w- c:\windows\system32\generaltel.dll
2014-11-05 17:50:28 203776 ----a-w- c:\windows\system32\aepdu.dll
2014-11-05 17:47:40 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-10-25 01:32:37 67584 ----a-w- c:\windows\system32\packager.dll
2014-10-18 01:33:18 571904 ----a-w- c:\windows\system32\oleaut32.dll
2014-10-14 01:56:19 136632 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-10-14 01:50:50 523776 ----a-w- c:\windows\system32\termsrv.dll
2014-10-14 01:50:41 2363904 ----a-w- c:\windows\system32\msi.dll
2014-10-14 01:50:39 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-10-14 01:47:30 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-10-14 01:46:02 681984 ----a-w- c:\windows\system32\adtschema.dll
2014-10-10 00:45:54 2379264 ----a-w- c:\windows\system32\win32k.sys
2014-10-03 01:44:42 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2014-10-03 01:44:31 275968 ----a-w- c:\windows\system32\EncDump.dll
2014-10-03 01:44:26 475136 ----a-w- c:\windows\system32\audiosrv.dll
2014-10-03 01:44:26 374784 ----a-w- c:\windows\system32\AudioEng.dll
2014-10-03 01:44:26 195584 ----a-w- c:\windows\system32\AudioSes.dll
2014-09-25 01:40:50 519680 ----a-w- c:\windows\system32\qdvd.dll
2014-09-19 09:23:55 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-09-19 09:23:52 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-09-19 09:23:49 248832 ----a-w- c:\windows\system32\schannel.dll
2014-09-19 09:23:46 221184 ----a-w- c:\windows\system32\ncrypt.dll
2014-09-19 09:23:45 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-09-19 09:23:42 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-09-19 09:23:36 17408 ----a-w- c:\windows\system32\credssp.dll
2014-09-09 21:47:10 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-04 05:04:15 372736 ----a-w- c:\windows\system32\rastls.dll
2014-08-23 01:46:55 305152 ----a-w- c:\windows\system32\gdi32.dll
.
============= FINISH: 15:01:05.69 ===============

Edited by Oh My!, 21 November 2014 - 12:59 PM.


#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:30 PM

Posted 21 November 2014 - 01:09 PM

Greetings,

Unfortunately once the encryption has taken place there is really nothing to figure out. The files can't be decrypted using any tools. I am not aware of a way to scan for backed up files, although I have not addressed that very much.

The use of CryptoPrevent or other similar programs can help protect files.

 

Not sure what else I can offer.....
 


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:30 PM

Posted 24 November 2014 - 09:48 AM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 Jimmybub

Jimmybub
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:30 AM

Posted 24 November 2014 - 04:09 PM

If you can't help then thats fine.  I was kind of hoping that there was a program like the cryptolocker decrypter that would work.  Well, I guess it's alright to close the thread down, hopefully I can get some help from you guys in the future :)



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:30 PM

Posted 24 November 2014 - 04:15 PM

Unfortunately the latest versions of Crypto malware are designed to make it impossible for us to decrypt the files.

 

Sorry we couldn't help.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:30 PM

Posted 24 November 2014 - 06:46 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users