To begin with, please understand that we can remove the malware from your system but we can not decrypt your files. Most experts say that the best way to start on this is to make an image of your system so that IF a way to decrypt the files is ever discovered, you can load the image and get you file back from the image.
You may also want to consider that, if you have a back up of your personal data files (documents, pictures, etc.), it may be better to format your hard drive and re-install Windows. There is considerable malware on this system and while we always strive to clean as best we can, there is no guarantee that all the malware can be removed and / or the damage undone.
With those two points in hand we can begin …
Did you know that System Restore is disabled?
If you did not do this intentionally, please check the following:
Go to Start and type System in the search box.
Click on System (under Control Panel or Settings) and then on System Protection.
Click on Configure and then select Turn on system protection.
Click Apply and then OK.
In the System Protection screen, is Protection now On for the drive?
FIRST >>>>
Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):
Define Ext
File Extractor
File Extractor Packages
TidyNetwork.com
Wondershare Helper Compact 2.5.0
Wondershare Video Converter Ultimate(Build 7.3.0.3)
To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window.
Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.
SECOND >>>>
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]
Download attached fixlist.txt file and save it to the Desktop:
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!
- Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
- Press the Fix button just once and wait.
- If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
- When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.