Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Otis Reddit
Nov 14, 2006
Have a machine that was hit with Crypto Wall two days ago. Did some cursory Googling and it looks like I really am at the mercy of hackers. Anyone here have any success with this thing?

Adbot
ADBOT LOVES YOU

Pyroclastic
Jan 4, 2010

According to bleepingcomputer, Cryptowall hasn't been compromised like CryptoLocker. If you don't have backups or shadow copies, your only resort is going to be to try a file recovery program:

Bleeping Computer posted:

Method 2: File Recovery Software

When CryptoWall encrypts a file it first makes a copy of it, encrypts the copy, and then deletes the original. Due to this you can use file recovery software such as R-Studio or Photorec to possibly recover some of your original files. It is important to note that the more you use your computer after the files are encrypted the more difficult it will be for file recovery programs to recover the deleted un-encrypted files.

Otherwise, you get to mourn the loss of the files or pay the ransom.

Otis Reddit
Nov 14, 2006
That's just lovely. Glad the machine was used for two days before it was brought to me.

Factory Factory
Mar 19, 2010

This is what
Arcane Velocity was like.
Two days and already it's got a ransomeware trojan? Maybe you should suggest the owner get a Mac or a Chromebook.

Pyroclastic
Jan 4, 2010

Factory Factory posted:

Two days and already it's got a ransomeware trojan? Maybe you should suggest the owner get a Mac or a Chromebook.

I think he means it got hit by Cryptowall and was used for two days while infected before the owner brought it in.

When it comes to file recovery, casual use probably isn't terrible, but if they downloaded a bunch of poo poo or reinstalled anything (or even visited a bunch of websites and got thousands of files in the cache), you might still get a lot of files back.

  • Locked thread