My computer got infected with some malware that disabled the antivirus and added a .ecc extension to office, pdf, text and image files.
There was no ransom message, just some pornographic images at startup. There was a "syshost.exe" service installed and a program with a random name was running. I cleaned the malware and the antivirus works now, but these files no longer open.
For some files I have the unmodified original. I tried using Panda Ransomware Decrypt to extract the key and restore the files, but it failed.
Is it possible to use files that have the original and encrypted versions to extract information that can decrypt the rest of the files?
Edited by hamluis, 26 March 2015 - 02:47 PM.