Добрый день,

Пробился ко мне вирус, судя по всему через RDT 1vera.exe
Зашифровались все диски и даже сетевые. Срочно нужна помощь. Антивирус обнаружил шифровальщик уже после того как он зашифровал весь мой компьютер и множество сетевых.

Time;Scanner;Object type;Object;Threat;Action;User;Information;Hash;First seen here
12/22/2018 3:03:19 PM;Startup scanner;file;c:\programdata\microsoft\windows\start menu\programs\startup\1vera.exe;a variant of Win32/Filecoder.Crysis.P trojan;cleaned by deleting;;;3039663285BA1F7A5AF8F155726A0F6831F8DEDA;12/22/2018 3:01:18 PM
12/22/2018 3:03:24 PM;Startup scanner;file;c:\users\apetrov\appdata\roaming\microsoft\windows\start menu\programs\startup\1vera.exe;a variant of Win32/Filecoder.Crysis.P trojan;cleaned by deleting;;;3039663285BA1F7A5AF8F155726A0F6831F8DEDA;12/22/2018 3:01:18 PM
12/22/2018 3:03:37 PM;Startup scanner;file;c:\windows\system32\1vera.exe;a variant of Win32/Filecoder.Crysis.P trojan;cleaned by deleting;;;3039663285BA1F7A5AF8F155726A0F6831F8DEDA;12/22/2018 3:01:18 PM
12/22/2018 3:03:47 PM;Startup scanner;file;Operating memory » C:\Users\apetrov\Desktop\05\1Vera.exe;a variant of Win32/Filecoder.Crysis.P trojan;cleaned by deleting (after the next restart);;;3039663285BA1F7A5AF8F155726A0F6831F8DEDA;12/22/2018 3:01:06 PM
12/22/2018 8:32:54 PM;Real-time file system protection;file;C:\Windows\System32\1Vera.exe;a variant of Win32/Filecoder.Crysis.P trojan;cleaned by deleting;BUKA\timothy;Event occurred during an attempt to run the file by the application: C:\Windows\explorer.exe (408FE28868B5AC008B5DF98B9928A2FA6543D0D7).;3039663285BA1F7A5AF8F155726A0F6831F8DEDA;12/22/2018 3:03:59 PM
12/22/2018 8:32:55 PM;Real-time file system protection;file;C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\1Vera.exe;a variant of Win32/Filecoder.Crysis.P trojan;cleaned by deleting;BUKA\timothy;Event occurred during an attempt to run the file by the application: C:\Windows\explorer.exe (408FE28868B5AC008B5DF98B9928A2FA6543D0D7).;3039663285BA1F7A5AF8F155726A0F6831F8DEDA;12/22/2018 3:03:59 PM

Прикрепляю образ автозапуска
[URL=https://yadi.sk/d/mrqM40TP_Fj-aQ]https://yadi.sk/d/mrqM40TP_Fj-aQ[/URL]

и 2 файла -зашифрованый и нет
[URL=https://yadi.sk/d/jKx2VI-WuMRuAA]https://yadi.sk/d/jKx2VI-WuMRuAA[/URL]

Возможно ли будет расшифровать?