Sign in to follow this  
oposer

Keyholder

Recommended Posts

I am being held at ransom. as I updated to total security on the 23 of Dec I also got infected with Keyhoder it is a nasty peace of work it has encrypted my personal files and want $500 for key, but from what I believe even after you pay they don't play the game . have had contact with Adawara support and they suggested the forum so here I am , any help would be fantastic. thank you. Addition.txtFRST.txt

Share this post


Link to post
Share on other sites

Hi oposer,

 

I'm sorry but your files can't be decrypted without the key, and I don't recommend you to pay criminals. I haven't read all pages of http://www.bleepingcomputer.com/forums/t/559463/keyholder-support-and-discussion-topic/but it's a website that you can trust and I recommend you to read through all the pages since there might be a chance that you at least can get back some files.

 

These folders and files were created during the infection, it might be useful information for the helpers in the linked topic:

2014-12-23 21:20 - 2014-12-23 21:36 - 00000000 ____D () C:\Users\Michael\AppData\Local\Ishhsoft

2014-12-23 20:19 - 2014-12-26 04:51 - 00000000 ____D () C:\Users\Michael\AppData\Local\Ecdction

2014-12-23 20:18 - 2014-12-29 14:10 - 00000000 ____D () C:\ProgramData\tiskmhj

2014-12-23 19:51 - 2014-12-23 19:51 - 00000000 ____D () C:\ProgramData\dha

2014-12-23 19:50 - 2014-12-23 19:50 - 00004651 _____ () C:\Users\Michael\Downloads\how_decrypt.html

2014-12-23 19:00 - 2014-12-23 19:00 - 00004651 _____ () C:\Users\Michael\AppData\Local\how_decrypt.html

2014-12-23 19:00 - 2014-12-23 19:00 - 00004651 _____ () C:\Users\Administrator\how_decrypt.html

2014-12-23 18:58 - 2014-12-23 19:00 - 00000000 ____D () C:\ProgramData\udlhrrc

2014-12-23 18:41 - 2014-12-31 12:00 - 00000824 _____ () C:\Windows\Tasks\Security Center Update - 1727467613.job

2014-12-23 18:41 - 2014-12-23 22:56 - 00000000 ____D () C:\Users\Michael\AppData\Roaming\Uqewfum

 

 

You should reinstall Windows to be sure that all malicious files are gone. It's possible to remove the listed files and folders, but since it's very important that nothing is hiding in the computer and starts to encrypt files again, I recommend you to install Windows.

Share this post


Link to post
Share on other sites

Due to lack of feedback, this topic has been closed.

 

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

 

Everyone else please begin a New Topic.

 

Thank You !

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this