Author Topic: Infection by ransomware Zepto extension on Windows 10  (Read 8619 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Infection by ransomware Zepto extension on Windows 10
« on: August 16, 2016, 06:09:07 PM »
Hi,

End of the day yesterday, my Outlook stopped working then I found out most of the data on my Hard Drive got renamed with zepto extension; I posted some enquiry/ feedback on my Avast! account, as this is how I got help in the past, but this time no reaction from Avast!, nobody else seems to be able to help so far.
I managed to partially retrive my e-mail data, but I don't know what to do next.
Is there anybody who could help further?
This is quite urgent as most of my work is done via e-mail.

thanks,

PhD

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #1 on: August 16, 2016, 06:12:31 PM »

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #2 on: August 16, 2016, 07:27:53 PM »
Hi Eddy,

thanks for replying.
I'm not familiar with this forum.
I assume you suggest I follow the steps at the link you posted? Right?
We already ran Malwarebytes and Spybot S&D so I'll continue on with the next steps.
Should I reboot my computer in Safe Mode or it doesn't matter at this stage?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #3 on: August 16, 2016, 07:31:22 PM »
Yes, follow the steps described there and attach the requested log files to your next post.
Do not boot into safe mode to run the tools.

REDACTED

  • Guest
Infection by ransomware Zepto extension on Windows 10
« Reply #4 on: August 17, 2016, 06:00:23 PM »
Ok I'm running in bit more difficulties than expected: so far I managed to recreate my Outlook account and can now send and receive; for the rest, I found out that I can't start: Task Manager. i must have tried at least 9 different ways to do so and still no luck.
I managed to run Spybot which removed about 1500 file anfd reported the following a minute ago:

   16-08-15 20:07:21   TFileScanHTTPDaemon   Listening on port 21323
   16-08-15 20:07:21   TFileScanHTTPDaemon   Successfully started listening on port 21323.
SDFileScanLibrary.dll [2016-08-15 20:07:27] Loaded databases.
   16-08-17 12:26:54   TFileScanHTTPDaemon   Listening on port 21323
   16-08-17 12:26:54   TFileScanHTTPDaemon   Successfully started listening on port 21323.
SDFileScanLibrary.dll [2016-08-17 12:26:54] Loaded databases.
SDFileScanLibrary.dll [2016-08-17 12:28:41] Started scanning C:\Windows\System32\Taskmgr.exe.
SDFileScanLibrary.dll [2016-08-17 12:28:47] Scanned file C:\Windows\System32\Taskmgr.exe is clean.
   16-08-17 17:51:17   TFileScanHTTPDaemon   Listening on port 21323
   16-08-17 17:51:17   TFileScanHTTPDaemon   Successfully started listening on port 21323.
SDFileScanLibrary.dll [2016-08-17 17:51:17] Loaded databases.

Unfortunately, after several attempts I still can't run: Malwarebytes Anti-Malware. When I click the application nothing happens. I'm stuck at this point. Looked at a few suggestions on Internet but none worked.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #5 on: August 17, 2016, 06:01:46 PM »
Please only follow the instructions if you want help.

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #6 on: August 17, 2016, 06:58:08 PM »
Ok moving on to Farbar.
Thanks.

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #7 on: August 17, 2016, 07:48:27 PM »
See logs from  Farbar Recovery Scan Tool attached

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #8 on: August 17, 2016, 07:49:41 PM »
Adding FRST.txt as well, sorry.

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #9 on: August 17, 2016, 08:11:53 PM »
And attached the aswMBR.txt file

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #10 on: August 18, 2016, 07:14:05 AM »
To begin with, please understand that we can remove the malware from your system but we can not decrypt your files.  Most experts say that the best way to start on this is to make an image of your system so that IF a way to decrypt the files is ever discovered, you can load the image and get you file back from the image.

You may also want to consider that, if you have a back up of your personal data files (documents, pictures, etc.), it may be better to format your hard drive and re-install Windows.  There is considerable malware on this system and while we always strive to clean as best we can, there is no guarantee that all the malware can be removed and / or the damage undone.

 With those two points in hand we can begin .....


Did you know that System Restore is disabled?

If you did not do this intentionally, please check the following:

Go to Start and type System in the search box.

Click on System (under Control Panel or Settings) and then on System Protection.

Click on Configure and then select Turn on system protection.

Click Apply and then OK.

In the System Protection screen, is Protection now On for the drive?



FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

Define Ext
File Extractor
File Extractor Packages
TidyNetwork.com
Wondershare Helper Compact 2.5.0
Wondershare Video Converter Ultimate(Build 7.3.0.3)


To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. 

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.


SECOND >>>>


Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #11 on: August 18, 2016, 10:31:06 AM »
Yes I understand that unfortunately.
Yes I know that Syetem Restore is disabled as this is one of the first thing I tried to do.
This was not done on purpose as I used this feature on earlier versions and know it is useful.
I tried the steps you suggested, but when doing so, I see that my OS & Program (C:) drive has protection on, Data (F): and RECOVERY (D:) are off. Under System Protection all buttons are greyed except: OK and Cancel, so I cannot click on Configure.
I also tried to do this as Administrator since it says this had been desactivated by my Administrator, but the view is the same.

I'm proceeding with your other instructions. 

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #12 on: August 18, 2016, 11:12:41 AM »
You will find the requested file attached.

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #13 on: August 18, 2016, 11:29:09 AM »
Good news: after running Farbar, as you indicated, I could turn System Protection on for drive (F:); (C:) was already on.
I also, now, could launch the Task Manager which was not starting before.
Thanks.
I'll now try again to run: Malwarebytes Anti-Malware which was not launching before.
Let me know if other actions are required.

REDACTED

  • Guest
Re: Infection by ransomware Zepto extension on Windows 10
« Reply #14 on: August 18, 2016, 03:52:05 PM »
Ok, this time Malwarebytes started and completed succesfully. I don't think I'll need any of the quarantined files, but I did not remove them yet, in case you say else.
I have attached the 3 logs that were produced.
Everything seems to work properly, now, including the fact that I receive much less spams than in the past  :)
I placed all the encrypted files in a separate folder that I'll backup later on, but before connecting another drive, I'd like to be sure it won't get infected.
For the same reason I did not yet restore the files from my last backup.