Hi for Tesla Crypt, the best you can do is ensure that it doesn't spread further to other computers on your network.

To clean it out, boot up in safemode then go to your startup config to check for the malware source files. Disable it from starting when your PC start.

After that You will have to run a search on your hard drive for all files with the offending extension (so far i've seen .CCC & .VVV) and delete them. The only way to recover your ms office based documents is if you had previously backed them.

Regards

On 30 Dec 2015 12:00, <skunkworks-request@lists.my.co.ke> wrote:
Send skunkworks mailing list submissions to
        skunkworks@lists.my.co.ke

To subscribe or unsubscribe via the World Wide Web, visit
        http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
or, via email, send a message with subject or body 'help' to
        skunkworks-request@lists.my.co.ke

You can reach the person managing the list at
        skunkworks-owner@lists.my.co.ke

When replying, please edit your Subject line so it is more specific
than "Re: Contents of skunkworks digest..."


Today's Topics:

   1. Re: Tesla Script Ransomware (Amarjit Labhuram)


----------------------------------------------------------------------

Message: 1
Date: Wed, 30 Dec 2015 11:50:53 +0300
From: Amarjit Labhuram <amarjit.labhuram@gmail.com>
To: Barrack Otieno <otieno.barrack@gmail.com>,  Skunkworks Mailing
        List <skunkworks@lists.my.co.ke>
Subject: Re: [Skunkworks] Tesla Script Ransomware
Message-ID:
        <CAJxpFmTFo0UDz55wR2bdm+GcmnVw_1FDX28aUp=uDtKXGzt28w@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"

Hi Otieno,

I have been hit with that malware on our network a number of times and
there is almost nothing you can do. Tried various ways of recovering data
that have been posted on the net but to no avail. Luckily cloud backups
were there from where I could restore as at up to a certain date. Good luck
and if you do get a work around please share.

Have a great day!

Warm regards,
Amarjit Singh Labhuram.


On Wed, Dec 30, 2015 at 10:50 AM, Barrack Otieno via skunkworks <
skunkworks@lists.my.co.ke> wrote:

> Hi all ,
>
> Has anyone dealt with the above mentioned Malware?, Please share your
> experience.
>
> Regards
>
> --
> Barrack O. Otieno
> +254721325277
> +254-20-2498789
> Skype: barrack.otieno
> http://www.otienobarrack.me.ke/
>
> _______________________________________________
> skunkworks mailing list
> skunkworks@lists.my.co.ke
> ------------
> List info, subscribe/unsubscribe
> http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
> ------------
>
> Skunkworks Rules
> http://my.co.ke/phpbb/viewtopic.php?f=24&t=94
> ------------
> Other services @ http://my.co.ke
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.my.co.ke/cgi-bin/mailman/private/skunkworks/attachments/20151230/9db91902/attachment-0001.html>

------------------------------

Subject: Digest Footer

_______________________________________________
skunkworks mailing list
skunkworks@lists.my.co.ke
http://lists.my.co.ke/cgi-bin/mailman/listinfo/skunkworks
------------
Skunkworks Server donations spreadsheet
http://spreadsheets.google.com/ccc?key=0AopdHkqSqKL-dHlQVTMxU1VBdU1BSWJxdy1fbjAwOUE&hl=en
------------
Skunkworks Rules
http://my.co.ke/phpbb/viewtopic.php?f=24&t=94
------------
Other services @ http://my.co.ke

------------------------------

End of skunkworks Digest, Vol 19, Issue 95
******************************************