Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trojan download #215

Closed
jerebord opened this issue Aug 5, 2023 · 6 comments
Closed

Trojan download #215

jerebord opened this issue Aug 5, 2023 · 6 comments
Labels

Comments

@jerebord
Copy link

jerebord commented Aug 5, 2023

Someone downloaded an apparently malicious file, and the computer got infected with viruses. Word files were encrypted and their file extension changed to ".gatz" now.
I used different antivirus and antimalware but I think it is still infected.

1.log
CollectionLog-2023.08.05-10.30.zip

@dragokas
Copy link
Owner

dragokas commented Aug 5, 2023

Hi,
thank you for the log.
We'll return to you as soon as possible.


Please, note that only members of VIRUSNET-Association are allowed to respond to PC cure topics.
Ignore any recommendations given by other users, including PM !!!

Assistance is provided free of charge in our free time. If you found our help useful, you can thank us with any amount using this form or you can leave feedback in Guestbook.

@Sandor-Helper
Copy link

Hi,
Please zip a couple of encrypted files (with .gatz extention) along with the ransome note (if you have one) and attach it to your next post.
In addition:
Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click to run as administrator. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce logs called FRST.txt and Addition.txt in the same directory the tool is run from.
  • Please attach the logs back here.

@jerebord
Copy link
Author

jerebord commented Aug 7, 2023

Encrypted files (with .gatz extention).
Desktop.zip

Farbar Recovery Scan Tool files.
FRST.txt
Shortcut.txt
Addition.txt

@Sandor-Helper
Copy link

Thanks for the logs.
Can you please also attach this file?

C:_readme.txt

@jerebord
Copy link
Author

jerebord commented Aug 7, 2023

_readme.txt

@Sandor-Helper
Copy link

Sandor-Helper commented Aug 7, 2023

Type of ransome is STOP (Djvu). Decryption for this encryptor was available only for early versions.

I see that you've already try to use it with no luck.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants