I have been somewhat successful in removing this malware whereby AVG and Malwarebytes both no longer see it as being a threat and can't find any trace on the system but all of the files still have the extension .ezz and no matter what I try I am unable to 'decrypt?' them.
I have run both AVG and malware bytes repeatedly in safe and normal mode until nothing is detected. AVG first picked it up as Trojan Horse Crypt4.YIW within AppData\Local\xizis.exe on the PC.
I have also found the key.dat file in AppData > Roaming which I believe is the encryption key used.
After some web trawling I have tried the website https://www.decryptcryptolocker.com/ and uploaded one of the .ezz files but it says the file is not encrypted.
I have also installed and run TeslaDecrypt which finds the key.dat file and runs a scan of my whole system and says it is okay and the scan has completed but still the files are the same name and when you try to open them, Word says that it is unable to open the file and for jpg it says the file may be corrupt or damaged.
The system does not have shadow copies running and also system restore was disabled.
I have been searching all over but I can't seem to find a way of recovering the files back to how they were.
May anybody know if these files are recoverable please?
Thank you in advance.
I have run both AVG and malware bytes repeatedly in safe and normal mode until nothing is detected. AVG first picked it up as Trojan Horse Crypt4.YIW within AppData\Local\xizis.exe on the PC.
I have also found the key.dat file in AppData > Roaming which I believe is the encryption key used.
After some web trawling I have tried the website https://www.decryptcryptolocker.com/ and uploaded one of the .ezz files but it says the file is not encrypted.
I have also installed and run TeslaDecrypt which finds the key.dat file and runs a scan of my whole system and says it is okay and the scan has completed but still the files are the same name and when you try to open them, Word says that it is unable to open the file and for jpg it says the file may be corrupt or damaged.
The system does not have shadow copies running and also system restore was disabled.
I have been searching all over but I can't seem to find a way of recovering the files back to how they were.
May anybody know if these files are recoverable please?
Thank you in advance.