.encrypt Virus

Kalani

Solid State Member
Messages
13
Location
Australia
Hey guys,

I've been working at a computer store and a lot of people have been coming in with .encrypt ransom ware. Anyone got any ideas on how to get rid of it? I've done the usual virus check/removal, boot time scan etc.
 
You need to find out specifically which variant of ransomware it is - there's different techniques for different versions. Some can be easily fixed, others...you're SOL unless you have a backup (usually a good idea to check Shadow Copies).
 
It's a thing called "CryptoVirus" we tried rolling back the PC and it didn't work. So I'm assuming just a reinstall.
 
Are you sure that's the name?

Variants include (but not limited to): VaultCrypt, TeslaCrypt, CTB-Locker, CryptoWall, KEYHolder, CryptoLocker, Petya, etc.

Rolling back won't work - the files are encrypted. You need to find out which variant it is so that you can try to decrypt the files if possible (as well as remove the malware in the first place).
 
I'm sure if you do some Googling, you can still find a copy of the database somewhere. Remember, once you put something on the internet, it'll never truly be able to be taken off ;).

Sent from my HTC One
 
How you find out what type of virus it is?
I got hit but one but only infected one driver on my server which i thought it was kind of weird. I deleted the whole drive and i just used a back up from a day before. But I have still haven't find out where it did originate from. anyone have any thought?
 
Back
Top Bottom