Post reply

Name:
Email:
Subject:
Message icon:

Verification:
Type the letters shown in the picture
Listen to the letters / Request another image

Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

shortcuts: hit alt+s to submit/post or alt+p to preview


Topic Summary

Posted by: StevenMiller
« on: 25. March 2016., 13:34:26 »

I am very grateful for your advices. Thank you very much! The issue has been resolved.)
Posted by: GergoLakatos
« on: 22. March 2016., 19:15:58 »

Posted by: GergoLakatos
« on: 22. March 2016., 19:05:50 »

I had a similar problem and was help with PDF Recovery Toolbox http://www.pdf.recoverytoolbox.com/
I have tried to restore and open a corrupted file with PDF Recovery Toolbox and it was opened.
Maybe this is not the best solution for your problem but I hope it helps.
Posted by: DMShuman
« on: 14. March 2016., 22:31:17 »

I believe that tool is discussed in the 47 pages of info on this and does not work.   It states that later version of this malware deletes the key.dat file you need.  Maybe someone else who gets the .mp3 version can test this.
Posted by: Samker
« on: 14. March 2016., 22:15:11 »

---

Right now the only fix would be to wipe clean the drive and reinstall.

---

@DMShuman

FYI, before that, point your friend to test this solution - "The Talos TeslaCrypt Decryption Tool": http://scforum.info/index.php/topic,10085.0.html


@StevenMiller

Please, use some of recommended "Online Anti-Malware Scanners": http://scforum.info/index.php/topic,734.0.html & provide us results.

cya later,

S.
 
Posted by: DMShuman
« on: 14. March 2016., 21:59:09 »

A friend of mine just got hit with a newer version of TeslaCrypt.  Delivered by an email with attached .zip file where once open  it rename all her text, doc and pdf files to end with .mp3 extension.  you are held ransom for decryption of encrypted files.  But paying does not mean they unlocked all your files.
  Ie
*.pdf.mp3.
if you rename your files back to .pdf you will find the files are encrypted.  It will also attach itself to network drives and rename these also.  Right now the only fix would be to wipe clean the drive and reinstall.

There are 47 pages of  info at bleeping computers forum.  (see link below)

 http://www.bleepingcomputer.com/forums/t/605185/teslacrypt-30-xxx-ttt-micro-mp3-support-topic/?hl=%20teslacrypt
Posted by: jheysen
« on: 14. March 2016., 19:37:35 »

Sadly, My bet is that the trojan dropped some kind of worm and that affected your PDF files. I would try with an "Standard" AV to see if it can recover the header, other option would be to get your hand into a tool that can let you set the PDF Version and experiment with that
Posted by: StevenMiller
« on: 14. March 2016., 17:56:25 »

Hello experts,
I had to clean a trojan from my laptop this morning. After a few hours of work and Malware scanning, I got rid of the issue and everything seemed to be fine.
...then I realized I was wrong. I realized 'some' of my adobe files in my hard disk cannot be opened with 'File corrupt' error. I know these files are valid and usable (at least before the issue)
I realized the files that cannot be read has a PDF version 0.0 in the attributes.
The interesting thing is this issue is seen in some adobe files and not in others. I copied the supposely corrupted files into my PC, the issue is still the same on the PC - files cannot be opened.
For some files I have backups but for some I don't. So need to find a way to recover them.
Please help!
Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising