Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I Need Help Removing Cryptolocker


  • This topic is locked This topic is locked
77 replies to this topic

#1 he's dead jim

he's dead jim

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 22 April 2015 - 05:46 AM

Hi everyone.

 

I have my friends computer which was infected with the cryptolocker virus.

 

If I start it in normal mode, I get the big popup that locks me out of the PC.

 

If I start it in safe mode, I can access most of the files with no problem, but none of the malware / spyware / virus detection software sees anything wrong.

 

It also seems as though the program is only partway through the encryption as most of the files are not yet encrypted.

 

I sent a few of the encryption files to FireEye, but they come back as not being encrypted.

 

Thanks.

 

 



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,733 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:54 AM

Posted 27 April 2015 - 05:50 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/574032 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 28 April 2015 - 03:52 PM

hello everyone.

 

by using standard programs like rkill, tdsskill, junk removal tool, adw cleaner, hitman pro, eset online scanner, super anti spy, malwarebytes, and combofix, I managed to get most of the virus eliminated.

 

all of a sudden, it popped up out of nowhere and is once again fully entrenched in my system, as if I did nothing.

 

tough little bugger, lol.

 

my main concern right now, before cleaning it out again, is the status of the encrypted files.

 

there are many files with an ecc extension, and I downloaded the emsisoft decryption tool, but the list of decrypted files must have already been removed.

 

I had set all of my removal tools to quarantine the infection, not to delete it, so the file should still be there, I just need to know which one it is.

 

unless there is another way to use that decryption tool, such as putting all the encrypted files in one directory and pointing it to that directory somehow.

 

I will also be posting the FRST log in about an hour, as soon as I hook the system up again.

 

thanks.


Edited by he's dead jim, 28 April 2015 - 03:53 PM.


#4 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 28 April 2015 - 07:17 PM

ok, here is my FRST log file.

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2015 01
Ran by sal (administrator) on SAL-484AC017D99 on 28-04-2015 19:56:04
Running from C:\Documents and Settings\sal\Desktop
Loaded Profiles: sal (Available profiles: sal & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
() C:\Documents and Settings\sal\Application Data\jrqgftk.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [msdedf] => C:\Documents and Settings\sal\Application Data\jrqgftk.exe [262144 2015-04-24] ()
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-790525478-776561741-839522115-1003\...\Run: [msdedf] => C:\Documents and Settings\sal\Application Data\jrqgftk.exe [262144 2015-04-24] ()
Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\sal\Application Data\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-790525478-776561741-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-790525478-776561741-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
ShellExecuteHooks: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Documents and Settings\sal\Application Data\Mozilla\Firefox\Profiles\eqjyzb3i.default
FF Homepage: https://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-20] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1209149.dll [2014-01-28] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-03-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-03-08] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll [2007-10-01] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll [2007-10-01] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2010-12-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2010-12-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2010-12-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2010-12-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2010-12-15] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2010-12-15] (Apple Inc.)
FF Extension: Status-4-Evar - C:\Documents and Settings\sal\Application Data\Mozilla\Firefox\Profiles\eqjyzb3i.default\Extensions\status4evar@caligonstudios.com.xpi [2012-06-22]
FF Extension: Video DownloadHelper - C:\Documents and Settings\sal\Application Data\Mozilla\Firefox\Profiles\eqjyzb3i.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-14]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-06-17]
FF HKU\S-1-5-21-790525478-776561741-839522115-1003\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\Documents and Settings\All Users\Application Data\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java™ Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave for Director) - C:\WINDOWS\system32\Adobe\Director\np32dsw_1202122.dll No File
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_169.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\sal\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Documents and Settings\sal\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09]
CHR Extension: (Google Wallet) - C:\Documents and Settings\sal\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path Or update_url value

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
S4 Creative Service for CDROM Access; C:\WINDOWS\system32\CTSvcCDA.EXE [44032 1999-12-12] (Creative Technology Ltd) [File not signed]
S4 Crypkey License; C:\WINDOWS\system32\crypserv.exe [122880 2007-03-14] (CrypKey (Canada) Ltd.) [File not signed]
S4 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [598016 2007-12-25] () [File not signed]
S4 IDriverT; C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S4 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-03-08] (Oracle Corporation)
S4 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [159744 2007-12-25] () [File not signed]
S4 spupdsvc; C:\WINDOWS\system32\spupdsvc.exe [26144 2009-05-12] (Microsoft Corporation)
S4 stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [73728 2006-09-14] (MicroVision Development, Inc.) [File not signed]
S4 WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [53520 2000-06-26] (Microsoft Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 Ai2sXP; C:\WINDOWS\System32\drivers\Ai2sXP.sys [7296 2007-11-21] (Ai Squared ) [File not signed]
S0 cercsr6; C:\WINDOWS\system32\Drivers\cercsr6.sys [39904 2004-12-13] (Adaptec, Inc.) [File not signed]
S3 Jukebox3; C:\WINDOWS\System32\DRIVERS\ctpdusb.sys [17280 2006-01-19] (Creative Technology Ltd.)
R1 NetworkX; C:\WINDOWS\system32\ckldrv.sys [31846 2006-01-09] () [File not signed]
R0 nvatabus; C:\WINDOWS\System32\DRIVERS\nvatabus.sys [105472 2006-10-18] (NVIDIA Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [54784 2008-08-01] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [22016 2008-08-01] (NVIDIA Corporation)
R2 PfModNT; C:\WINDOWS\system32\drivers\PfModNT.sys [15840 2003-03-05] (Creative Technology Ltd.) [File not signed]
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [36528 2006-07-24] (Sonic Solutions) [File not signed]
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [320120 2014-07-11] (Duplex Secure Ltd.)
R1 StarPortLite; C:\WINDOWS\System32\DRIVERS\StarPortLite.sys [97920 2013-02-04] (StarWind Software)
S3 SWDUMon; C:\WINDOWS\System32\DRIVERS\SWDUMon.sys [13464 2014-03-02] ()
S3 catchme; \??\C:\DOCUME~1\sal\LOCALS~1\Temp\catchme.sys [X]
S4 IntelIde; No ImagePath
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-28 19:56 - 2015-04-28 19:56 - 00014778 _____ () C:\Documents and Settings\sal\Desktop\FRST.txt
2015-04-28 19:55 - 2015-04-28 19:56 - 00000000 ____D () C:\FRST
2015-04-28 19:42 - 2015-04-28 19:42 - 01140736 _____ (Farbar) C:\Documents and Settings\sal\Desktop\FRST.exe
2015-04-28 19:38 - 2015-04-28 19:54 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-28 19:38 - 2015-04-28 19:54 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-04-28 19:38 - 2015-04-28 19:39 - 00015749 _____ () C:\WINDOWS\setupapi.log
2015-04-28 19:38 - 2015-04-28 19:38 - 00000116 _____ () C:\WINDOWS\setupact.log
2015-04-28 19:38 - 2015-04-28 19:38 - 00000000 _____ () C:\WINDOWS\Sti_Trace.log
2015-04-28 19:38 - 2015-04-28 19:38 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-04-28 19:37 - 2015-04-28 19:54 - 00000057 _____ () C:\WINDOWS\errord.log
2015-04-25 14:47 - 2015-04-28 19:55 - 00010872 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-25 14:47 - 2015-04-25 14:47 - 00000000 ___SD () C:\ComboFix
2015-04-24 21:19 - 2015-04-28 19:55 - 02291910 _____ () C:\Documents and Settings\sal\Desktop\HeLP_ReSTORe_FILeS.bmp
2015-04-24 21:19 - 2015-04-28 19:55 - 00001630 _____ () C:\Documents and Settings\sal\Desktop\CryptoLocker.lnk
2015-04-24 21:19 - 2015-04-28 19:55 - 00001364 _____ () C:\Documents and Settings\sal\Desktop\HELP_RESTORE_FILES.txt
2015-04-24 21:19 - 2015-04-28 19:55 - 00000752 _____ () C:\Documents and Settings\sal\Application Data\key.dat
2015-04-24 21:19 - 2015-04-24 21:19 - 00262144 _____ () C:\Documents and Settings\sal\Application Data\jrqgftk.exe
2015-04-24 21:19 - 2015-04-24 21:19 - 00262144 _____ () C:\Documents and Settings\sal\Application Data\eoplfac.exe
2015-04-24 21:14 - 2015-04-24 21:14 - 00000000 ____D () C:\Program Files\ESET
2015-04-24 21:11 - 2015-04-24 21:12 - 02347384 _____ (ESET) C:\Documents and Settings\sal\Desktop\esetsmartinstaller_enu.exe
2015-04-24 21:08 - 2015-04-24 21:08 - 00000751 _____ () C:\Documents and Settings\sal\Desktop\JRT.txt
2015-04-24 21:03 - 2015-04-24 21:03 - 00000000 ____D () C:\RegBackup
2015-04-24 18:02 - 2015-04-25 14:46 - 00003090 _____ () C:\Documents and Settings\sal\Desktop\Rkill.txt
2015-04-24 17:44 - 2015-04-24 17:44 - 00001688 _____ () C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-04-24 17:42 - 2015-04-24 20:14 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-04-24 17:30 - 2015-04-24 17:30 - 00000943 _____ () C:\Documents and Settings\sal\Desktop\Spybot - Search & Destroy.lnk
2015-04-24 17:27 - 2015-04-25 09:39 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2015-04-24 17:27 - 2015-04-24 18:16 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy
2015-04-24 17:27 - 2015-04-24 17:30 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
2015-04-24 14:18 - 2015-04-24 14:18 - 01295016 _____ (Emsisoft Ltd) C:\Documents and Settings\sal\Desktop\decrypt_pclock2.exe
2015-04-24 14:16 - 2015-04-24 00:51 - 02685461 _____ (Thisisu) C:\Documents and Settings\sal\Desktop\JRT.exe
2015-04-24 07:20 - 2015-04-24 07:20 - 00000787 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-24 07:05 - 2015-04-24 07:08 - 00000000 ____D () C:\AdwCleaner
2015-04-24 06:42 - 2015-04-24 06:42 - 00012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2015-04-24 00:57 - 2015-04-28 19:56 - 00000000 ____D () C:\Documents and Settings\sal\Local Settings\temp
2015-04-24 00:57 - 2015-04-25 09:17 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\temp
2015-04-24 00:57 - 2015-04-24 00:57 - 00000000 ____D () C:\Documents and Settings\NetworkService\Local Settings\temp
2015-04-24 00:57 - 2015-04-24 00:57 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\temp
2015-04-24 00:57 - 2015-04-24 00:57 - 00000000 ____D () C:\Documents and Settings\Default User\Local Settings\temp
2015-04-19 13:23 - 2015-04-19 13:23 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla
2015-04-19 13:23 - 2015-04-19 13:23 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Mozilla
2015-04-19 09:32 - 2015-04-24 01:07 - 10109856 _____ (SurfRight B.V.) C:\Documents and Settings\sal\Desktop\HitmanPro.exe
2015-04-19 09:31 - 2015-04-19 09:33 - 150062624 _____ (Avast Software s.r.o.) C:\Documents and Settings\sal\Desktop\avast_free_antivirus_setup.exe
2015-04-19 09:26 - 2015-04-19 09:26 - 00050688 _____ (Atribune.org) C:\Documents and Settings\sal\Desktop\ATF-Cleaner.exe
2015-04-19 09:24 - 2015-04-19 09:25 - 04197016 _____ (Kaspersky Lab ZAO) C:\Documents and Settings\sal\Desktop\tdsskiller.exe
2015-04-19 09:24 - 2015-04-19 09:24 - 02217984 _____ () C:\Documents and Settings\sal\Desktop\adwcleaner_4.201.exe
2015-04-19 09:24 - 2015-04-19 09:24 - 01943800 _____ (Bleeping Computer, LLC) C:\Documents and Settings\sal\Desktop\rkill.exe
2015-04-19 09:23 - 2015-04-24 00:48 - 05619466 ____R (Swearware) C:\Documents and Settings\sal\Desktop\ComboFix.exe
2015-04-18 23:44 - 2015-03-27 22:41 - 27806772 _____ () C:\Documents and Settings\sal\Desktop\Detekt V1.9.exe
2015-04-18 19:07 - 2015-04-18 19:07 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Windows Search
2015-04-18 17:17 - 2015-04-18 17:17 - 00000000 __SHD () C:\Documents and Settings\Administrator\PrivacIE
2015-04-18 16:04 - 2015-04-25 09:27 - 00000000 ____D () C:\Qoobox
2015-04-18 16:04 - 2011-06-26 02:45 - 00256000 _____ () C:\WINDOWS\PEV.exe
2015-04-18 16:04 - 2010-11-07 13:20 - 00208896 _____ () C:\WINDOWS\MBR.exe
2015-04-18 16:04 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2015-04-18 16:04 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2015-04-18 16:04 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2015-04-18 16:04 - 2000-08-30 20:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2015-04-18 16:04 - 2000-08-30 20:00 - 00098816 _____ () C:\WINDOWS\sed.exe
2015-04-18 16:04 - 2000-08-30 20:00 - 00080412 _____ () C:\WINDOWS\grep.exe
2015-04-18 16:04 - 2000-08-30 20:00 - 00068096 _____ () C:\WINDOWS\zip.exe
2015-04-18 16:01 - 2015-04-18 16:02 - 00005276 _____ () C:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-04-18 15:46 - 2015-04-18 15:46 - 05618696 ____R (Swearware) C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
2015-04-18 15:46 - 2015-04-18 15:46 - 04197016 _____ (Kaspersky Lab ZAO) C:\Documents and Settings\Administrator\Desktop\tdsskiller.exe
2015-04-18 15:46 - 2015-04-18 15:46 - 01943800 _____ (Bleeping Computer, LLC) C:\Documents and Settings\Administrator\Desktop\rkill.exe
2015-04-18 15:34 - 2015-04-23 23:16 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\AVAST Software
2015-04-18 15:34 - 2015-04-18 15:34 - 00036736 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-04-18 15:22 - 2015-04-28 19:55 - 00000232 _____ () C:\Documents and Settings\sal\My Documents\RECOVERY_KEY.TXT
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 ____N () C:\Documents and Settings\sal\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\HELP_RESTORE_FILES.txt
2015-04-18 12:52 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 07:28 - 2015-04-18 07:28 - 00000227 _____ () C:\Documents and Settings\sal\Application Data\hbkai01iajah1
2015-04-18 00:09 - 2015-04-28 19:54 - 00000000 ___HD () C:\Documents and Settings\All Users\Application Data\{34A65AB3-CD68-4CBC-9F93-174FF3C5325F}
2015-04-04 23:59 - 2015-04-05 00:00 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-04 19:12 - 2015-04-04 23:08 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-28 19:54 - 2004-08-04 06:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-28 19:53 - 2012-06-17 13:52 - 00000178 ___SH () C:\Documents and Settings\sal\ntuser.ini
2015-04-28 19:41 - 2015-03-26 20:07 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2015-04-25 13:43 - 2013-06-15 11:58 - 00000000 __SHD () C:\Documents and Settings\Administrator\IETldCache
2015-04-25 13:43 - 2013-06-15 11:58 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2015-04-25 10:06 - 2013-06-15 12:09 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2015-04-25 10:06 - 2013-06-15 12:05 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2015-04-25 09:40 - 2012-06-17 13:52 - 00000000 ____D () C:\Documents and Settings\sal
2015-04-25 09:32 - 2012-10-26 09:31 - 00000000 ____D () C:\Documents and Settings\sal\Desktop\EXTRA STUFF
2015-04-25 09:31 - 2012-06-17 09:43 - 00000100 ___SH () C:\boot.ini
2015-04-25 09:27 - 2012-06-17 13:48 - 00000000 ____D () C:\WINDOWS\system32\Restore
2015-04-25 09:19 - 2013-06-15 11:58 - 00000178 ___SH () C:\Documents and Settings\Administrator\ntuser.ini
2015-04-25 09:19 - 2012-06-17 15:16 - 00065536 _____ () C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-04-25 09:18 - 2013-06-15 11:58 - 00000000 ____D () C:\Documents and Settings\Administrator
2015-04-25 08:56 - 2012-06-17 13:51 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-24 21:09 - 2012-06-17 15:56 - 00002443 _____ () C:\Documents and Settings\sal\Desktop\HiJackThis.lnk
2015-04-24 19:37 - 2012-06-17 13:51 - 00000178 ___SH () C:\Documents and Settings\NetworkService\ntuser.ini
2015-04-24 17:43 - 2012-06-17 15:52 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
2015-04-24 14:11 - 2012-06-17 09:40 - 00000000 ____D () C:\WINDOWS\addins
2015-04-24 13:26 - 2014-06-21 10:32 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-24 07:21 - 2014-06-21 10:32 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-24 07:20 - 2014-06-21 10:32 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-24 07:09 - 2012-06-17 13:51 - 00000178 ___SH () C:\Documents and Settings\LocalService\ntuser.ini
2015-04-24 06:44 - 2012-06-17 14:21 - 00000692 _____ () C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
2015-04-24 06:44 - 2012-06-17 14:21 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2015-04-24 06:43 - 2012-06-17 14:21 - 00000000 ____D () C:\Program Files\CCleaner
2015-04-24 06:42 - 2013-06-15 11:59 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\HitmanPro
2015-04-24 00:56 - 2004-08-04 06:00 - 00000227 ____N () C:\WINDOWS\system.ini
2015-04-24 00:44 - 2012-06-17 16:10 - 00000000 __SHD () C:\WINDOWS\CSC
2015-04-24 00:05 - 2014-07-12 12:31 - 00000000 ___RD () C:\Documents and Settings\sal\My Documents\Dropbox
2015-04-18 19:16 - 2012-06-17 13:51 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-18 19:15 - 2012-06-17 14:57 - 00000000 ____D () C:\Program Files\Windows Desktop Search
2015-04-18 16:03 - 2013-10-26 14:22 - 00000000 ____D () C:\WINDOWS\erdnt
2015-04-18 13:30 - 2012-06-17 16:18 - 00055296 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-18 13:27 - 2014-08-24 10:21 - 00000000 ____D () C:\SUPERDelete
2015-04-18 13:27 - 2014-07-12 12:31 - 00000000 ____D () C:\Documents and Settings\sal\Start Menu\Programs\Dropbox
2015-04-18 13:27 - 2014-04-27 16:11 - 00000000 ____D () C:\Freedom-Scientific-Product-Guide
2015-04-18 13:27 - 2014-04-25 13:37 - 00000000 ____D () C:\MDT
2015-04-18 13:27 - 2013-02-17 14:27 - 00000000 ____D () C:\VirtualDub-1.9.11
2015-04-18 13:27 - 2012-12-24 17:00 - 00000000 ____D () C:\Documents and Settings\sal\Start Menu\Programs\SanDisk
2015-04-18 13:27 - 2012-09-28 16:32 - 00000000 ____D () C:\UnrealTournament
2015-04-18 13:27 - 2012-06-22 16:40 - 00000000 ____D () C:\Documents and Settings\sal\My Documents\My Received Files
2015-04-18 13:27 - 2012-06-17 18:22 - 00000000 ___RD () C:\MSOCache
2015-04-18 13:27 - 2012-06-17 15:56 - 00000000 ____D () C:\Documents and Settings\sal\Start Menu\Programs\HiJackThis
2015-04-18 13:27 - 2012-06-17 15:46 - 00000000 ____D () C:\Documents and Settings\sal\Start Menu\Programs\FormatFactory
2015-04-18 13:27 - 2012-06-17 14:50 - 00000000 __SHD () C:\Documents and Settings\sal\PrivacIE
2015-04-18 13:27 - 2012-06-17 13:52 - 00000000 ___RD () C:\Documents and Settings\sal\Start Menu\Programs\Accessories
2015-04-18 12:56 - 2012-06-17 15:46 - 00000000 ____D () C:\Documents and Settings\sal\My Documents\FFOutput
2015-04-18 12:52 - 2013-09-08 15:27 - 00000000 ____D () C:\Documents and Settings\sal\My Documents\eRightSoft
2015-04-18 12:44 - 2015-01-09 11:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2015-04-18 12:44 - 2014-08-30 17:16 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Nero
2015-04-18 12:44 - 2014-08-23 09:41 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\DVDVideoSoft
2015-04-18 12:44 - 2014-07-11 08:47 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\StarBurn Software
2015-04-18 12:44 - 2014-03-08 14:45 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Java
2015-04-18 12:44 - 2014-03-08 10:44 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Roxio Creator DE
2015-04-18 12:44 - 2013-11-10 13:54 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Fotosizer
2015-04-18 12:44 - 2013-10-26 14:28 - 00011988 _____ () C:\ComboFix.txt.ecc
2015-04-18 12:44 - 2013-09-08 15:23 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\SUPER © - by eRightSoft
2015-04-18 12:44 - 2013-06-29 09:14 - 00000000 ____D () C:\Documents and Settings\NetworkService\Application Data\Softland
2015-04-18 12:44 - 2013-06-28 16:26 - 00000000 __SHD () C:\Documents and Settings\LocalService\IETldCache
2015-04-18 12:44 - 2013-06-15 12:05 - 00000000 ____D () C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe
2015-04-18 12:44 - 2013-06-15 12:05 - 00000000 ____D () C:\Documents and Settings\Administrator\Application Data\Adobe
2015-04-18 12:44 - 2013-06-15 11:58 - 00000000 ___RD () C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories
2015-04-18 12:44 - 2013-03-16 10:29 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\Application Data\HP
2015-04-18 12:44 - 2013-02-03 16:29 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Creative
2015-04-18 12:44 - 2012-11-11 20:13 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\McAfee
2015-04-18 12:44 - 2012-10-14 12:35 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ZoomText 9.1
2015-04-18 12:44 - 2012-10-13 09:28 - 00000000 ____D () C:\Documents and Settings\Default User\Application Data\TuneUp Software
2015-04-18 12:44 - 2012-09-15 11:17 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Tools
2015-04-18 12:44 - 2012-09-15 11:15 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works
2015-04-18 12:44 - 2012-06-29 14:58 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Musicmatch
2015-04-18 12:44 - 2012-06-25 12:48 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\Softland
2015-04-18 12:44 - 2012-06-25 12:48 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\doPDF 7
2015-04-18 12:44 - 2012-06-22 17:36 - 00000000 ____D () C:\Documents and Settings\sal\dwhelper
2015-04-18 12:44 - 2012-06-17 18:36 - 00000000 ____D () C:\Documents and Settings\LocalService\Application Data\Roxio
2015-04-18 12:44 - 2012-06-17 18:27 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
2015-04-18 12:44 - 2012-06-17 16:45 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\ArcSoft PhotoStudio 2000
2015-04-18 12:44 - 2012-06-17 16:35 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\HP
2015-04-18 12:44 - 2012-06-17 15:49 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\MPC-HC
2015-04-18 12:44 - 2012-06-17 15:47 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
2015-04-18 12:44 - 2012-06-17 15:42 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\QT Lite
2015-04-18 12:44 - 2012-06-17 15:41 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Real Alternative
2015-04-18 12:44 - 2012-06-17 14:59 - 00000000 ____D () C:\af61272a8fc71bc0ee798c8db415d0d3
2015-04-18 12:44 - 2012-06-17 14:58 - 00000000 __SHD () C:\Documents and Settings\NetworkService\IETldCache
2015-04-18 12:44 - 2012-06-17 14:50 - 00000000 __SHD () C:\Documents and Settings\sal\IETldCache
2015-04-18 12:44 - 2012-06-17 14:16 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\NVIDIA Corporation
2015-04-18 12:44 - 2012-06-17 13:49 - 00000000 __SHD () C:\Documents and Settings\All Users\DRM
2015-04-18 12:44 - 2012-06-17 13:49 - 00000000 ___RD () C:\Documents and Settings\Default User\Start Menu\Programs\Accessories
2015-04-18 12:44 - 2012-06-17 13:49 - 00000000 ____D () C:\DELL
2015-04-18 12:44 - 2012-06-17 13:48 - 00000000 ___RD () C:\Documents and Settings\All Users\Start Menu\Programs\Games
2015-04-18 12:44 - 2012-06-17 13:47 - 00000000 ___RD () C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
2015-04-18 06:44 - 2014-07-12 12:30 - 00000000 ____D () C:\Documents and Settings\sal\Application Data\Dropbox
2015-04-17 08:40 - 2012-06-21 09:18 - 00000000 ____D () C:\Documents and Settings\sal\Application Data\Media Player Classic
2015-04-12 15:43 - 2012-11-17 09:32 - 00000000 ____D () C:\Documents and Settings\sal\Application Data\Audacity
2015-04-12 15:42 - 2012-06-22 09:29 - 03480400 ___SH () C:\Documents and Settings\sal\My Documents\Thumbs.db
2015-04-10 07:54 - 2014-07-12 12:31 - 00001006 _____ () C:\Documents and Settings\sal\Desktop\Dropbox.lnk
2015-04-07 18:11 - 2014-05-10 11:20 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-03 10:37 - 2014-08-30 17:53 - 00000214 _____ () C:\Documents and Settings\sal\Application Data\default.rss
2015-04-03 10:36 - 2014-08-30 17:46 - 00000069 _____ () C:\WINDOWS\NeroDigital.ini

==================== Files in the root of some directories =======

2015-04-18 07:28 - 2015-04-18 07:28 - 0023040 _____ () C:\Documents and Settings\sal\Application Data\06 - Stevie Nicks - Stand Back.mp3
2014-08-30 17:53 - 2015-04-03 10:37 - 0000214 _____ () C:\Documents and Settings\sal\Application Data\default.rss
2015-04-24 21:19 - 2015-04-24 21:19 - 0262144 _____ () C:\Documents and Settings\sal\Application Data\eoplfac.exe
2015-04-18 07:28 - 2015-04-18 07:28 - 0000227 _____ () C:\Documents and Settings\sal\Application Data\hbkai01iajah1
2015-04-24 21:19 - 2015-04-24 21:19 - 0262144 _____ () C:\Documents and Settings\sal\Application Data\jrqgftk.exe
2015-04-24 21:19 - 2015-04-28 19:55 - 0000752 _____ () C:\Documents and Settings\sal\Application Data\key.dat
2012-06-17 16:18 - 2015-04-18 13:30 - 0055296 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-12 11:06 - 2012-08-12 11:06 - 0027520 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\dt.dat
2015-04-24 00:07 - 2015-04-24 00:07 - 0000032 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\mfzeranuzw.png
2015-04-18 12:44 - 2015-04-18 15:22 - 0002674 _____ () C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt

Files to move or delete:
====================
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job
C:\Windows\Tasks\At3.job
C:\Windows\Tasks\At4.job


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================



#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,495 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:54 AM

Posted 30 April 2015 - 07:32 PM

Greetings he's dead jim and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please allow me a bit of time to review our situation. I will post back as soon as I can.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,495 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:54 AM

Posted 30 April 2015 - 08:25 PM

Thank you for your patience. Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
HKLM\...\Run: [msdedf] => C:\Documents and Settings\sal\Application Data\jrqgftk.exe [262144 2015-04-24] ()
HKU\S-1-5-21-790525478-776561741-839522115-1003\...\Run: [msdedf] => C:\Documents and Settings\sal\Application Data\jrqgftk.exe [262144 2015-04-24] ()
Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
HKU\S-1-5-21-790525478-776561741-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S3 catchme; \??\C:\DOCUME~1\sal\LOCALS~1\Temp\catchme.sys [X]
S4 IntelIde; No ImagePath
2015-04-24 21:19 - 2015-04-28 19:55 - 02291910 _____ () C:\Documents and Settings\sal\Desktop\HeLP_ReSTORe_FILeS.bmp
2015-04-24 21:19 - 2015-04-28 19:55 - 00001630 _____ () C:\Documents and Settings\sal\Desktop\CryptoLocker.lnk
2015-04-24 21:19 - 2015-04-28 19:55 - 00001364 _____ () C:\Documents and Settings\sal\Desktop\HELP_RESTORE_FILES.txt
2015-04-24 21:19 - 2015-04-28 19:55 - 00000752 _____ () C:\Documents and Settings\sal\Application Data\key.dat
2015-04-24 21:19 - 2015-04-24 21:19 - 00262144 _____ () C:\Documents and Settings\sal\Application Data\jrqgftk.exe
2015-04-24 21:19 - 2015-04-24 21:19 - 00262144 _____ () C:\Documents and Settings\sal\Application Data\eoplfac.exe
2015-04-18 15:22 - 2015-04-28 19:55 - 00000232 _____ () C:\Documents and Settings\sal\My Documents\RECOVERY_KEY.TXT
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 ____N () C:\Documents and Settings\sal\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\HELP_RESTORE_FILES.txt
2015-04-18 12:52 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 07:28 - 2015-04-18 07:28 - 00000227 _____ () C:\Documents and Settings\sal\Application Data\hbkai01iajah1
2015-04-18 00:09 - 2015-04-28 19:54 - 00000000 ___HD () C:\Documents and Settings\All Users\Application Data\{34A65AB3-CD68-4CBC-9F93-174FF3C5325F}
2015-04-24 21:19 - 2015-04-24 21:19 - 0262144 _____ () C:\Documents and Settings\sal\Application Data\eoplfac.exe
2015-04-18 07:28 - 2015-04-18 07:28 - 0000227 _____ () C:\Documents and Settings\sal\Application Data\hbkai01iajah1
2015-04-24 21:19 - 2015-04-24 21:19 - 0262144 _____ () C:\Documents and Settings\sal\Application Data\jrqgftk.exe
2012-06-17 16:18 - 2015-04-18 13:30 - 0055296 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-24 00:07 - 2015-04-24 00:07 - 0000032 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\mfzeranuzw.png
2015-04-18 12:44 - 2015-04-18 15:22 - 0002674 _____ () C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job
C:\Windows\Tasks\At3.job
C:\Windows\Tasks\At4.job
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Please visit this page, review the information and run Cisco's TeslaDecrypt.

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Results of decrypt efforts

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#7 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 01 May 2015 - 12:14 AM

hello and thanks for everything so far.

 

I ran the frst and I have posted the log below.

 

the decryption program could not find the key.dat file, but when I searched using windows explorer, it found two files.

 

one had been quarantined by combofix a few days ago, (key.dat.vir), and one was quarantined by frst, (key.dat.bad)

 

I did not want to remove any files from quarantine until I spoke to you first.

 

thanks again and here's the log.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-04-2015 01
Ran by sal at 2015-05-01 00:59:55 Run:1
Running from C:\Documents and Settings\sal\Desktop
Loaded Profiles: sal (Available profiles: sal & Administrator)
Boot Mode: Safe Mode (minimal)

==============================================

Content of fixlist:
*****************
HKLM\...\Run: [msdedf] => C:\Documents and Settings\sal\Application Data\jrqgftk.exe [262144 2015-04-24] ()
HKU\S-1-5-21-790525478-776561741-839522115-1003\...\Run: [msdedf] => C:\Documents and Settings\sal\Application Data\jrqgftk.exe [262144 2015-04-24] ()
Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt [2015-04-18] ()
HKU\S-1-5-21-790525478-776561741-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
S3 catchme; \??\C:\DOCUME~1\sal\LOCALS~1\Temp\catchme.sys [X]
S4 IntelIde; No ImagePath
2015-04-24 21:19 - 2015-04-28 19:55 - 02291910 _____ () C:\Documents and Settings\sal\Desktop\HeLP_ReSTORe_FILeS.bmp
2015-04-24 21:19 - 2015-04-28 19:55 - 00001630 _____ () C:\Documents and Settings\sal\Desktop\CryptoLocker.lnk
2015-04-24 21:19 - 2015-04-28 19:55 - 00001364 _____ () C:\Documents and Settings\sal\Desktop\HELP_RESTORE_FILES.txt
2015-04-24 21:19 - 2015-04-28 19:55 - 00000752 _____ () C:\Documents and Settings\sal\Application Data\key.dat
2015-04-24 21:19 - 2015-04-24 21:19 - 00262144 _____ () C:\Documents and Settings\sal\Application Data\jrqgftk.exe
2015-04-24 21:19 - 2015-04-24 21:19 - 00262144 _____ () C:\Documents and Settings\sal\Application Data\eoplfac.exe
2015-04-18 15:22 - 2015-04-28 19:55 - 00000232 _____ () C:\Documents and Settings\sal\My Documents\RECOVERY_KEY.TXT
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 ____N () C:\Documents and Settings\sal\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 13:27 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\HELP_RESTORE_FILES.txt
2015-04-18 12:52 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\sal\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\LocalService\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\Start Menu\Programs\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\Start Menu\HELP_RESTORE_FILES.txt
2015-04-18 12:44 - 2015-04-18 15:22 - 00002674 _____ () C:\Documents and Settings\Administrator\My Documents\HELP_RESTORE_FILES.txt
2015-04-18 07:28 - 2015-04-18 07:28 - 00000227 _____ () C:\Documents and Settings\sal\Application Data\hbkai01iajah1
2015-04-18 00:09 - 2015-04-28 19:54 - 00000000 ___HD () C:\Documents and Settings\All Users\Application Data\{34A65AB3-CD68-4CBC-9F93-174FF3C5325F}
2015-04-24 21:19 - 2015-04-24 21:19 - 0262144 _____ () C:\Documents and Settings\sal\Application Data\eoplfac.exe
2015-04-18 07:28 - 2015-04-18 07:28 - 0000227 _____ () C:\Documents and Settings\sal\Application Data\hbkai01iajah1
2015-04-24 21:19 - 2015-04-24 21:19 - 0262144 _____ () C:\Documents and Settings\sal\Application Data\jrqgftk.exe
2012-06-17 16:18 - 2015-04-18 13:30 - 0055296 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-24 00:07 - 2015-04-24 00:07 - 0000032 _____ () C:\Documents and Settings\sal\Local Settings\Application Data\mfzeranuzw.png
2015-04-18 12:44 - 2015-04-18 15:22 - 0002674 _____ () C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At2.job
C:\Windows\Tasks\At3.job
C:\Windows\Tasks\At4.job
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\msdedf => value deleted successfully.
HKU\S-1-5-21-790525478-776561741-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run\\msdedf => value deleted successfully.
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RESTORE_FILES.txt => Moved successfully.
"HKU\S-1-5-21-790525478-776561741-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
catchme => Service deleted successfully.
IntelIde => Service deleted successfully.
C:\Documents and Settings\sal\Desktop\HeLP_ReSTORe_FILeS.bmp => Moved successfully.
C:\Documents and Settings\sal\Desktop\CryptoLocker.lnk => Moved successfully.
C:\Documents and Settings\sal\Desktop\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\sal\Application Data\key.dat => Moved successfully.
C:\Documents and Settings\sal\Application Data\jrqgftk.exe => Moved successfully.
C:\Documents and Settings\sal\Application Data\eoplfac.exe => Moved successfully.
C:\Documents and Settings\sal\My Documents\RECOVERY_KEY.TXT => Moved successfully.
C:\Documents and Settings\sal\My Documents\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\sal\Start Menu\Programs\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\sal\Start Menu\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\sal\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\sal\Local Settings\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\NetworkService\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\NetworkService\Application Data\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Application Data\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\LocalService\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\LocalService\Application Data\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\Start Menu\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\My Documents\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\Desktop\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Default User\Application Data\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\All Users\Start Menu\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Administrator\Start Menu\Programs\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Administrator\Start Menu\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\Administrator\My Documents\HELP_RESTORE_FILES.txt => Moved successfully.
C:\Documents and Settings\sal\Application Data\hbkai01iajah1 => Moved successfully.

"C:\Documents and Settings\All Users\Application Data\{34A65AB3-CD68-4CBC-9F93-174FF3C5325F}" directory move:

Could not move "C:\Documents and Settings\All Users\Application Data\{34A65AB3-CD68-4CBC-9F93-174FF3C5325F}" directory. => Scheduled to move on reboot.

"C:\Documents and Settings\sal\Application Data\eoplfac.exe" => File/Directory not found.
"C:\Documents and Settings\sal\Application Data\hbkai01iajah1" => File/Directory not found.
"C:\Documents and Settings\sal\Application Data\jrqgftk.exe" => File/Directory not found.
C:\Documents and Settings\sal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => Moved successfully.
C:\Documents and Settings\sal\Local Settings\Application Data\mfzeranuzw.png => Moved successfully.
"C:\Documents and Settings\All Users\HELP_RESTORE_FILES.txt" => File/Directory not found.
C:\Windows\Tasks\At1.job => Moved successfully.
C:\Windows\Tasks\At2.job => Moved successfully.
C:\Windows\Tasks\At3.job => Moved successfully.
C:\Windows\Tasks\At4.job => Moved successfully.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-05-01 01:01:09)<=

C:\Documents and Settings\All Users\Application Data\{34A65AB3-CD68-4CBC-9F93-174FF3C5325F} => Is moved successfully.

==== End of Fixlog 01:01:09 ====



#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,495 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:54 AM

Posted 01 May 2015 - 08:56 AM

Thank you for the information. What we want to do now is see if we can decrypt your files by using the key.dat file. Since you seem so adept at this I will give you basic instructions rather than step by step. If you need step by step please let me know.

This is what we want to do. First, make sure the decryption program is on your desktop. Then we are going to copy and paste the key.dat files from quarantine onto your desktop. However, we need to do this one at a time and change the file extensions, removing the .vir and .bad respectively. I would like you to start with the Combofix quarantined file key.dat.vir.

Let me know if you need explicit instructions or, if not, the results of your efforts.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#9 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 01 May 2015 - 10:17 AM

hello again.

 

I tried both files and they came up empty.

 

the logs are posted below.

 

i am usually pretty good at getting rid of viruses and malware, so long as it's a windows xp system or earlier. lol.

 

I always come here for the real tough ones though.

 

You people are awesome.

 

 

Talos TeslaCrypt Decryptor 0.1
Execution time: 01/05/2015 - 11:08
11:08:36 - ReadKeyFile - Warning! The master key inside the "C:\Documents and Settings\sal\Desktop\key.dat" file is stripped down. Unable to import the master key. To recover the master key from the recovery key please use a newer version of this tool.
11:09:06 - Execution Ended!


Talos TeslaCrypt Decryptor 0.1
Execution time: 01/05/2015 - 11:09
11:09:25 - ReadKeyFile - Warning! The master key inside the "C:\Documents and Settings\sal\Desktop\key.dat" file is stripped down. Unable to import the master key. To recover the master key from the recovery key please use a newer version of this tool.
11:09:42 - Execution Ended!

 



#10 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 01 May 2015 - 10:20 AM

just one more thing.

 

I noticed from reading some of the removal guides, that this virus resembles the pclok version. is it possible that when I ran the other removal programs last week like junk removal tool and adw cleaner, that the files were erased?

 

if so, I may be able to recover them if nothing else works.

 

I await further instructions. lol.



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,495 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:54 AM

Posted 01 May 2015 - 10:27 AM

Greetings,

Unfortunately you used the latest version of the tool so we are stuck.

How is the computer running now? Any issues?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,495 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:54 AM

Posted 01 May 2015 - 10:30 AM

Sorry we cross posted. Which erased file are you looking for?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#13 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 01 May 2015 - 10:43 AM

i was thinking of possibly the original key.dat prior to me coming here.

 

I ran some of these programs multiple times, and I'n not sure if all of them have quarantine sections. some of them may just delete the files instead.

 

you would know better than me though, i'm sure.

 

over the past two weeks I ran:

 

rkill

 

tdsskiller - never turned up anything

 

malwarebytes - didn't see key.dat in the quarantine files but there were some .dat files

 

superantispy - just cookies in the quarantine file

 

adwcleaner - I don't know if deleted files can be recovered

 

junk removal tool - I don't know if deleted files can be recovered

 

hitmanpro - I don't know where the quarantine files are

 

combofix - already checked the quarantine file, but If I ran it multiple times, would the key.dat file be overwritten each time?

 

I also ran the eset scanner and I have no idea where the files for that are stored.

 

AVG had been installed, and my friend ran it before he gave me the computer to fix. he also uninstalled the program for some reason, so I don't know if those files are still available, or if I can recover them.

 

 

basically I am wondering, if I eliminated the virus, and then I came back, would it make a new encryption key or just reuse the old one prior to removal?



#14 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,495 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:54 AM

Posted 01 May 2015 - 11:18 AM

Thanks for the explanation. I just wanted to make sure we were talking about the same thing. I am not sure if the same or different key would be used. Depending on the variation of the infection the encryption key information is sometimes removed from the key.dat file.

Let's do this to see if we have any other key.dat files besides the 2 you identified.

===================================================

SystemLook by jpshortstuff

--------------------
  • Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Vista\Windows 7 users:: Right click on SystemLook.exe, click Run As Administrator
  • Copy the content of the following codebox into the main textfield:
:filefind
*key.dat*
*log.html*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply or, if necessary zip and attach the file.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • SystemLook log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#15 he's dead jim

he's dead jim
  • Topic Starter

  • Members
  • 112 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 01 May 2015 - 03:43 PM

here is the log file.

 

 

the system is running great so far.

 

 

 

SystemLook 30.07.11 by jpshortstuff
Log created at 16:40 on 01/05/2015 by sal
Administrator - Elevation successful

========== filefind ==========

Searching for "*key.dat*"
C:\Documents and Settings\sal\Desktop\key.dat.bad    --a---- 752 bytes    [15:08 01/05/2015]    [23:55 28/04/2015] 7000C8F75B3B0E71D8853F06A9A3E801
C:\Documents and Settings\sal\Desktop\key.dat.vir    --a---- 752 bytes    [15:08 01/05/2015]    [03:19 24/04/2015] 7000C8F75B3B0E71D8853F06A9A3E801
C:\FRST\Quarantine\C\Documents and Settings\sal\Application Data\key.dat.xBAD    --a---- 752 bytes    [01:19 25/04/2015]    [23:55 28/04/2015] 7000C8F75B3B0E71D8853F06A9A3E801
C:\Program Files\Microsoft Office\Office12\1033\PSRCHKEY.DAT    --a---- 325495 bytes    [21:51 05/10/2005]    [21:51 05/10/2005] 637F36F8C7AC336C5448B5FAADE33158
C:\Qoobox\Quarantine\C\Documents and Settings\sal\Application Data\key.dat.vir    --a---- 752 bytes    [03:19 24/04/2015]    [03:19 24/04/2015] 7000C8F75B3B0E71D8853F06A9A3E801

Searching for "*log.html*"
C:\Program Files\Audacity\help\manual\man\dependencies_dialog.html    --a---- 14905 bytes    [13:32 17/11/2012]    [02:11 09/08/2012] 07F6E39564E24427676D3BFD9898334A
C:\Program Files\Audacity\help\manual\man\file_export_dialog.html    --a---- 20929 bytes    [13:32 17/11/2012]    [02:10 09/08/2012] A0C9EDA02A376090065FE936F9DE64AB
C:\Qoobox\Quarantine\C\Documents and Settings\sal\Application Data\log.html.vir    --a---- 8501814 bytes    [16:44 18/04/2015]    [19:22 18/04/2015] 0F6386AB68595594A7564E19CE29B995

-= EOF =-






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users