You have encryptor malware as well, do you have a backup of your data ?
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer Open
notepad and copy/paste the text in the quotebox below into it:
HKLM Group Policy restriction on software: C:\Program Files (x86)\Malwarebytes' Anti-Malware <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Malwarebytes <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\AVAST Software <====== ATTENTION
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [11c08d] => C:\11c08dd\11c08dd.exe [258432 2014-11-06] (Company name goes here)
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [JozcUqawo] => regsvr32.exe "C:\ProgramData\JozcUqawo\JozcUqawo.dat"
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [ForpEzuze] => regsvr32.exe "C:\ProgramData\ForpEzuze\ForpEzuze.dat"
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [Evdtion] => C:\Users\Barbie\AppData\Local\Evdtion\msiexec.exe [163232 2014-11-06] ()
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [Esxgtion] => regsvr32.exe C:\Users\Barbie\AppData\Local\Esxgtion\wxMaindll32.dll <===== ATTENTION
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [Evzftion] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Barbie\AppData\Local\Evdtion\DRMGLWeb16.dll
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [BayoRyomi] => regsvr32.exe "C:\ProgramData\BayoRyomi\BayoRyomi.dat"
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\Run: [PakuPutpi] => regsvr32.exe "C:\ProgramData\PakuPutpi\PakuPutpi.dat"
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...\RunOnce: [*1c08dd] => C:\Users\Barbie\AppData\Roaming\11c08dd.exe
HKU\S-1-5-21-124788536-2644335351-2029234871-1000\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 239 more characters). <==== Poweliks!
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
2014-11-06 18:52 - 2014-11-06 18:52 - 00008536 _____ () C:\Users\Barbie\Downloads\DECRYPT_INSTRUCTION.HTML
2014-11-06 18:52 - 2014-11-06 18:52 - 00008536 _____ () C:\Users\Barbie\Documents\DECRYPT_INSTRUCTION.HTML
2014-11-06 18:52 - 2014-11-06 18:52 - 00004208 _____ () C:\Users\Barbie\Downloads\DECRYPT_INSTRUCTION.TXT
2014-11-06 18:52 - 2014-11-06 18:52 - 00004208 _____ () C:\Users\Barbie\Documents\DECRYPT_INSTRUCTION.TXT
2014-11-06 18:52 - 2014-11-06 18:52 - 00000272 _____ () C:\Users\Barbie\Downloads\INSTALL_TOR.URL
2014-11-06 18:52 - 2014-11-06 18:52 - 00000272 _____ () C:\Users\Barbie\Documents\INSTALL_TOR.URL
2014-11-06 18:48 - 2014-11-06 18:48 - 00008536 _____ () C:\Users\Barbie\AppData\Roaming\DECRYPT_INSTRUCTION.HTML
2014-11-06 18:48 - 2014-11-06 18:48 - 00008536 _____ () C:\Users\Barbie\AppData\DECRYPT_INSTRUCTION.HTML
2014-11-06 18:48 - 2014-11-06 18:48 - 00004208 _____ () C:\Users\Barbie\AppData\Roaming\DECRYPT_INSTRUCTION.TXT
2014-11-06 18:48 - 2014-11-06 18:48 - 00004208 _____ () C:\Users\Barbie\AppData\DECRYPT_INSTRUCTION.TXT
2014-11-06 18:48 - 2014-11-06 18:48 - 00000272 _____ () C:\Users\Barbie\AppData\Roaming\INSTALL_TOR.URL
2014-11-06 18:48 - 2014-11-06 18:48 - 00000272 _____ () C:\Users\Barbie\AppData\INSTALL_TOR.URL
2014-11-06 18:47 - 2014-11-06 18:47 - 00008536 _____ () C:\Users\Barbie\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-11-06 18:47 - 2014-11-06 18:47 - 00004208 _____ () C:\Users\Barbie\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-11-06 18:47 - 2014-11-06 18:47 - 00000272 _____ () C:\Users\Barbie\AppData\Local\INSTALL_TOR.URL
2014-11-06 18:10 - 2014-11-06 18:10 - 00008536 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-11-06 18:10 - 2014-11-06 18:10 - 00004208 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-11-06 18:10 - 2014-11-06 18:10 - 00000272 _____ () C:\ProgramData\INSTALL_TOR.URL
2014-11-06 17:58 - 2014-11-06 17:58 - 00000000 ____D () C:\ProgramData\PakuPutpi
2014-11-06 17:58 - 2014-11-06 17:58 - 00000000 ____D () C:\ProgramData\BayoRyomi
2014-11-06 17:45 - 2014-11-06 17:45 - 00000000 ____D () C:\Users\Barbie\AppData\Local\Evdtion
2014-11-06 17:45 - 2014-11-06 17:45 - 00000000 ____D () C:\Users\Barbie\AppData\Local\Esxgtion
2014-11-06 17:44 - 2014-11-06 17:44 - 00000000 ____D () C:\ProgramData\JozcUqawo
2014-11-06 17:44 - 2014-11-06 17:44 - 00000000 ____D () C:\ProgramData\ForpEzuze
2014-11-06 17:41 - 2014-11-06 17:41 - 00000000 ___HD () C:\11c08dd
2014-11-06 17:41 - 2014-11-06 17:41 - 00000000 ____D () C:\Users\Barbie\AppData\Roaming\FrameworkUpdate7
CustomCLSID: HKU\S-1-5-21-124788536-2644335351-2029234871-1000_Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 -> rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";eval("epdvnfou/xsjuf)(=tdsjqu!mbohvbhf>ktds (the data entry has 247 more characters). <==== Poweliks?
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as
fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THENDownload
Anti-CryptorBit.zip to your desktop
Extract Anti-CryptorBitV2 to the desktop and run
Select the file type you wish to decrypt and then follow the instructions
FINALLYDownload and run
farbar service scannerTick "
All" options.
Press "
Scan".
It will create a log (
FSS.txt) in the same directory the tool is run.
Please copy and paste the log to your reply.