Other Everything else not covered in the main topics goes here. Please avoid brand and flame wars. Don't try and up your post count. It won't work in here.

CryptoWall Virus

Thread Tools
 
Search this Thread
 
Old Jul 6, 2015 | 11:14 PM
  #1  
capt.Ron's Avatar
Thread Starter
I think I can... I think...
 
Joined: Aug 2004
Posts: 2,264
Likes: 0
From: Texas (DFW area)
CryptoWall Virus

As the title obviously indicates I have a virus issue. Well the wife does. She got one of those funky emails on her laptop with a link planted in it with no explanation, curiosity drew her in and even though I've warned her and everyone else not to she clicked on it anyway!!!

So I believe I have expelled the CryptoWall but I can't seem to remove the HELP_Decrypt items from the startup menu. I also have yet to find a way that I trust to decrypt the files that this nasty bugger encrypted!

Has anyone here dealt with this??
Reply
Old Jul 7, 2015 | 07:28 AM
  #2  
j_martin's Avatar
Registered User
 
Joined: Nov 2011
Posts: 4,479
Likes: 211
From: Isanti, MN
Originally Posted by capt.Ron
As the title obviously indicates I have a virus issue. Well the wife does. She got one of those funky emails on her laptop with a link planted in it with no explanation, curiosity drew her in and even though I've warned her and everyone else not to she clicked on it anyway!!!

So I believe I have expelled the CryptoWall but I can't seem to remove the HELP_Decrypt items from the startup menu. I also have yet to find a way that I trust to decrypt the files that this nasty bugger encrypted!

Has anyone here dealt with this??
Hit our network. Machine that launched the virus had to be wiped and reloaded. Encrypted files are lost. We suffered naught because we use a dynamic backup system that replaced the several thousand damaged files.

I have never heard of anyone successfully decrypting the files even if they paid the ransome.


The same user that launched this one launched another one a few months ago. He uses the slowest machine in the office.......by design.
Reply
Old Jul 7, 2015 | 09:31 AM
  #3  
capt.Ron's Avatar
Thread Starter
I think I can... I think...
 
Joined: Aug 2004
Posts: 2,264
Likes: 0
From: Texas (DFW area)
Originally Posted by j_martin
Hit our network. Machine that launched the virus had to be wiped and reloaded. Encrypted files are lost. We suffered naught because we use a dynamic backup system that replaced the several thousand damaged files.

I have never heard of anyone successfully decrypting the files even if they paid the ransome.


The same user that launched this one launched another one a few months ago. He uses the slowest machine in the office.......by design.
The good thing is there wasn't many files so I'm not so worried about that. Under system configuration these Help_Decrypt files are in the "startup" menu. I've unchecked them but I want to delete them from the machine. I did a search on the C drive and found them as well as many others. I considered just deleting them all but I'm worried that I might crash the machine. What are your thoughts on that?
Reply
Old Jul 9, 2015 | 06:41 AM
  #4  
j_martin's Avatar
Registered User
 
Joined: Nov 2011
Posts: 4,479
Likes: 211
From: Isanti, MN
Originally Posted by capt.Ron
The good thing is there wasn't many files so I'm not so worried about that. Under system configuration these Help_Decrypt files are in the "startup" menu. I've unchecked them but I want to delete them from the machine. I did a search on the C drive and found them as well as many others. I considered just deleting them all but I'm worried that I might crash the machine. What are your thoughts on that?
The virus probably has a hidden backup and registry entries to fire them off later. The only solution I know of is to wipe and reload. Any temp fix is only to buy time to copy files before they're infected.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mexstan
Other
2
Aug 3, 2003 08:33 PM
Hoss
Other
8
Jun 26, 2003 06:24 PM
Hoss
Other
11
May 14, 2003 07:30 AM
ramlovingvet
Other
10
Jan 14, 2003 11:47 AM




All times are GMT -5. The time now is 02:04 PM.