Malwareaware

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 19 May 2013

Decrypt Protect Ransomware and how to fully remove it.

Posted on 17:59 by Unknown
WARNING: This post is meant for self-help only. This post is meant only to assist with removal of malware covered in the post. So for the safety and protection of yourself and others, do not download files or programs where links are given to in this post.

I am going to try to keep this a short post, because I do not want to be rambling on when you are infected with this thing.

There is a new piece of ransomware going around for Windows that encrypts your files. This is not good that ransomware actually encrypts files this time around, because that means that actual removal is only half the battle. Then you have to decrypt your files, otherwise you will be unable to use them. Lucky for us, the encryption has already been cracked and a decryption tool has been released. But before we get into decryption, we have to remove the ransomware from your computer.

First, you will want to boot your computer into safe mode with networking. This is done by pressing the power button on your computer and repeatedly pressing the F8 key until you come to a menu with boot options such as Safe Mode. You will want to use the arrow keys to go to Safe Mode With Networking. Then press enter.

Next you will want to download and install Malwarebytes Anti-Malware. This program can be downloaded here. Once it has been installed, or you have updated it if you already had it installed, do a quick scan. Once the scan is completed, it may prompt you to restart your computer, which you will not want to do, we will restart after we have decrypted the files.

Now for the decryption tool. The encryption that the ransomware used to encrypt your files is relatively simple, which is why it was so easy to crack. You can download the decryption tool here. Save it to your desktop and then open a command line window by typing cmd into the search bar of the start menu and pressing enter. Navigate to the desktop directory. Now, run the same exe (decrypt_mblblock.exe) with the drive letters of all the drives you have mounted. (in the case of the C drive: decrypt_mblblock.exe C:\)

If after decryption, you find that there are still html files that the ransomware used, you can delete those. After decryption and mop up, you can go ahead and restart your computer in normal mode. You will find that all of the files that the ransomware encrypted are back.

Thank You for reading, hopefully this post can help you with removal of this thing. If some of these instructions do not make sense, please ask a competent professional to assist you.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Removal Guides, Windows | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • How to remove System Doctor 2014
    There is a new rogue AV making the rounds on the web called System Doctor 2014. For those that have just started reading my blog or for thos...
  • What are Bitcoin Miners?
    For my first post about Bitcoins, and for what I wish to be my last about the subject, we are going to be talking about what Bitcoin miners ...
  • How to keep spies from monitoring you through your computer or your phone.
    Those of you in The United States of America have most likely heard about that whole IRS scandal and the accompanying scandals of wiretappin...
  • Spotlight on Malware: The Gruel Worm.
    It's been around since Windows 2000, but there still is not a way to remove this worm without formatting the hard drive. I speak of the ...
  • I am going to be a billionaire!
    For those of you that have been reading my blog for some time, you know I like to mess with scammers, fake tech support and the like. But th...
  • Use VBScript to pull a joke on your friends.
    Do you want to play a trick on your friends, family, or coworkers? Well this one's for you. You can make a fake piece of malware on your...
  • Spotlight on Malware: MyDoom
    The MyDoom Windows worm, also known as Novarg, and Shimgapi will be the subject of our focus for this post. The MyDoom worm was first discov...
  • CryptoLocker as of 11/3/2013
    If you have read my other posts on this, you know. But for those of you who do not, there is a piece of ransomware that has been making the ...
  • The Big Game: Who's on our side?
    I recently helped a friend of mine remove malware from their computer when she be one mused on how lonely my job must be. "It must be s...
  • Java: No more coffee for you.
    Odds are that every blogger that has a tight focus on computer security has authored a blog post about Java. So why am I wasting your time? ...

Categories

  • Android
  • History Of
  • iOS
  • Java
  • Macs
  • Passwords
  • Removal Guides
  • Spotlight On Malware
  • The CryptoLocker Saga
  • What Does It Mean?
  • What's in a name?
  • Windows

Blog Archive

  • ▼  2013 (151)
    • ►  November (10)
    • ►  October (5)
    • ►  September (15)
    • ►  August (22)
    • ►  July (26)
    • ►  June (17)
    • ▼  May (25)
      • Update on the new blog.
      • What's In a name: Rogue Antivirus
      • A break from blogging.
      • Apparently, my computer loves me. (Surprise ending)
      • How to keep spies from monitoring you through your...
      • Malware In Space: Not A Science Fiction Drama Gone...
      • Greyware and the Babylon Toolbar.
      • Decrypt Protect Ransomware and how to fully remove...
      • Plug In to Plugins.
      • How a fake tech support scam works.
      • Mac Malware is now getting past Gatekeeper.
      • Spotlight On Malware: Bring On The Flame!
      • Attack Of The Clones: What is a clone rogue?
      • The Big Game: Who's on our side?
      • KeyScrambler: A preventive measure against keylogg...
      • Spotlight on Malware: MyDoom
      • Spotlight on Malware: The Gruel Worm.
      • How (Not) to Make Your Computer Run Faster With th...
      • A brief look at Windows 8.
      • A few jokes about computers.
      • Malware: It could happen to iOS too.
      • Android Malware: The robot can be infected.
      • "Stupid Malware! You made me drop my sandwich!"
      • How to remove Internet Security (Rogue)
      • Glipho
    • ►  April (15)
    • ►  March (7)
    • ►  February (6)
    • ►  January (3)
Powered by Blogger.

About Me

Unknown
View my complete profile