Any way to undo damage from KeyHolder Ransomware?

thebladeroden

Distinguished
Jun 13, 2004
1
0
18,510
I got a Trojan or something because Microsoft Security Essentials was sounding alarm bells and a scan with Anti-Malware was bringing up stuff too. After some guaranteeing and rebooting I thought I had gotten rid of the problem.

But later when I started Firefox all my addons were missing, which was weird but restoring its Appdata folder to an earlier date fixed it. Then a couple text files looked like they had part of the text corrupted. Restoring those worked too. Then I saw that there were a lot of files that were Last Modified around the same time.

So I went and did a System Restore, upon rebooting the PC, Windows said System Restore failed because one file didn't restore correctly. But now there are no other System Restore points to pick (I know there was at least one extra) none of the corrupted files have previous versions available anymore, and my C: drive suddenly has 20 more GB of space (gulp)

It was after that I saw every folder in My Documents had a how_decrypt.gif and how_decript.html



I haven't noticed any more weird behavior yet, but can you help me rid my comp of this thing if it isn't gone for good, and is there a way to get my files back?

Anti-Malware log
http://pastebin.com/CDL9Pd2m
 
Solution
If your machine was truly infected, and files were encrypted, and you didn't have a backup, then nothing short of paying the ransom (and even then they could simply take the money and run) will restore those files. The encryption keys are not breakable in several lifetimes. The utilities linked above will do nothing to recover files so encrypted.

ex_bubblehead

Distinguished
Moderator
If your machine was truly infected, and files were encrypted, and you didn't have a backup, then nothing short of paying the ransom (and even then they could simply take the money and run) will restore those files. The encryption keys are not breakable in several lifetimes. The utilities linked above will do nothing to recover files so encrypted.
 
Solution