Ciao, apri un file di testo, al suo interno cOpia e incolla il seguente script:
Startup: C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\help_recover_instructions+kav.html [2016-02-03] ()
Startup: C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\help_recover_instructions+kav.png [2016-02-03] ()
Startup: C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\help_recover_instructions+kav.txt [2016-02-03] ()
2016-02-03 10:31 - 2016-02-03 10:31 - 00007856 _____ C:\Users\Public\help_recover_instructions+kav.html
2016-02-03 10:31 - 2016-02-03 10:31 - 00007856 _____ C:\Users\Public\Downloads\help_recover_instructions+kav.html
2016-02-03 10:31 - 2016-02-03 10:31 - 00007856 _____ C:\Users\Filippo\Downloads\help_recover_instructions+kav.html
2016-02-03 10:31 - 2016-02-03 10:31 - 00002097 _____ C:\Users\Public\help_recover_instructions+kav.txt
2016-02-03 10:31 - 2016-02-03 10:31 - 00002097 _____ C:\Users\Public\Downloads\help_recover_instructions+kav.txt
2016-02-03 10:31 - 2016-02-03 10:31 - 00002097 _____ C:\Users\Filippo\Downloads\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:31 - 00007856 _____ C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:31 - 00002097 _____ C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:28 - 00007856 _____ C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:28 - 00007856 _____ C:\Users\Filippo\AppData\Roaming\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:28 - 00007856 _____ C:\Users\Filippo\AppData\LocalLow\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:28 - 00007856 _____ C:\Users\Filippo\AppData\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:28 - 00002097 _____ C:\Users\Filippo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:28 - 00002097 _____ C:\Users\Filippo\AppData\Roaming\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:28 - 00002097 _____ C:\Users\Filippo\AppData\LocalLow\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:28 - 00002097 _____ C:\Users\Filippo\AppData\help_recover_instructions+kav.txt
2016-02-03 10:27 - 2016-02-03 10:31 - 00007856 _____ C:\Users\Filippo\AppData\Local\help_recover_instructions+kav.html
2016-02-03 10:27 - 2016-02-03 10:31 - 00002097 _____ C:\Users\Filippo\AppData\Local\help_recover_instructions+kav.txt
2016-02-03 10:26 - 2016-02-03 10:31 - 00007856 _____ C:\Users\Public\Documents\help_recover_instructions+kav.html
2016-02-03 10:26 - 2016-02-03 10:31 - 00002097 _____ C:\Users\Public\Documents\help_recover_instructions+kav.txt
2016-02-03 10:26 - 2016-02-03 10:27 - 00007856 _____ C:\ProgramData\help_recover_instructions+kav.html
2016-02-03 10:26 - 2016-02-03 10:27 - 00002097 _____ C:\ProgramData\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:28 - 0007856 _____ () C:\Users\Filippo\AppData\Roaming\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:28 - 0067607 _____ () C:\Users\Filippo\AppData\Roaming\help_recover_instructions+kav.png
2016-02-03 10:28 - 2016-02-03 10:28 - 0002097 _____ () C:\Users\Filippo\AppData\Roaming\help_recover_instructions+kav.txt
2016-02-03 10:28 - 2016-02-03 10:28 - 0007856 _____ () C:\Users\Filippo\AppData\Roaming\Microsoft\help_recover_instructions+kav.html
2016-02-03 10:28 - 2016-02-03 10:28 - 0067607 _____ () C:\Users\Filippo\AppData\Roaming\Microsoft\help_recover_instructions+kav.png
2016-02-03 10:28 - 2016-02-03 10:28 - 0002097 _____ () C:\Users\Filippo\AppData\Roaming\Microsoft\help_recover_instructions+kav.txt
2016-02-03 10:27 - 2016-02-03 10:31 - 0007856 _____ () C:\Users\Filippo\AppData\Local\help_recover_instructions+kav.html
2016-02-03 10:27 - 2016-02-03 10:31 - 0067607 _____ () C:\Users\Filippo\AppData\Local\help_recover_instructions+kav.png
2016-02-03 10:27 - 2016-02-03 10:31 - 0002097 _____ () C:\Users\Filippo\AppData\Local\help_recover_instructions+kav.txt
2016-02-03 10:26 - 2016-02-03 10:27 - 0007856 _____ () C:\ProgramData\help_recover_instructions+kav.html
2016-02-03 10:26 - 2016-02-03 10:27 - 0067607 _____ () C:\ProgramData\help_recover_instructions+kav.png
2016-02-03 10:26 - 2016-02-03 10:27 - 0002097 _____ () C:\ProgramData\help_recover_instructions+kav.txt
EmptyTemp:salva il file di testo nella stessa cartella dove hai messo FRST, nominandolo fixlist.txt, Esegui il programma frst64.exe come amministratore e clicca sull'opzione "Fix", terminata la scansione riavvia il pc.
All'interno della cartella dovresti trovare il file Fixlog.txt , postalo per vedere le eliminazioni.
Per quanto riguarda il recupero dei files è un bel problema, di seguito alcuni link utili:
http://aiuto-pc.forumfree.it/?t=70654641http://www.ransomware.it/ransomware-teslacrypt-3-0/https://turbolab.it/windows-10/come-rip ... locker-833