Results 1 to 6 of 6

Thread: got infected with cryptowall ransomware - help_decrypt

  1. #1
    Member
    Join Date
    Jul 2013
    Posts
    34

    got infected with cryptowall ransomware - help_decrypt

    Has anyone dealt with the Cryptowall ransomware? This system got infected, and now we can't open any files at all. They are all encrypted. Almost every folder has 4 additional files in them named HELP_DECRYPT (different types of files, html, etc.).

    And every time the computer is restarted, an HTML page comes up with "instructions on how to fix it" and the links are different each time. (the fix, as you probably know, is to pay a ransom fee)

    I scanned it with MalwareBytes and removed 688 threats.

    Here is the log file:
    Malwarebytes Scan 6.19.15 5pm.txt

    AVAST only found three, which I also removed.

    Any ideas on how to decrypt the files or is there no hope? What else should I do to clean the system?

    What is the best anti-virus to protect against this from happening again?

    Thanks.

  2. #2
    Lifetime Friend of Staff
    Join Date
    May 2007
    Location
    Sheboygan, WI
    Posts
    3,921
    Pay or forget it and wipe the drive and start from scratch.
    I would DBAN, http://www.dban.org/download , the drive infact.

    http://www.bleepingcomputer.com/foru...cryptowall-30/
    http://www.bleepingcomputer.com/viru...re-information

  3. #3
    Member
    Join Date
    Jul 2013
    Posts
    34
    OK. Thanks.

  4. #4
    Lifetime Friend of Staff
    Join Date
    May 2007
    Location
    Sheboygan, WI
    Posts
    3,921
    I know I hate to have to give you So few options,

  5. #5
    Member
    Join Date
    Jul 2013
    Posts
    34
    No worries. I did some research and your advice is spot on.

    What do you recommend installing to prevent this from happening again?

  6. #6
    Lifetime Friend of Staff
    Join Date
    May 2007
    Location
    Sheboygan, WI
    Posts
    3,921
    What I do.

    AV - MSE
    Malwarebytes anti malware
    That is in Windows and of coarse I check my email online and watch what I do.

    I do run Linux as a alternate OS. A beta version AntiX 15 for when i am not so creful and the big thing is to backup what I would hat to lose and keep my USB harddrives disconnected, except when I am updating the. 1 onsite and 2 offsite at all times.
    Yes, I do have a image on each USB hdd. Thatway it does not take to long to rewrite to the C:\\ drive.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •