Need help! a virus attack

seoscrachiers

Power Member
Joined
Sep 22, 2015
Messages
572
Reaction score
196
Hi, I am rohit. Today when i opened a email (which was a spam ) all pictures,text files, sql files and many more files are automatically got encrypted.
And now when i try to open them i got a message to buy their software named crptowall. Have any body heard or faced it.
please help me i am frustrated and can't use any of images or files.

I am attaching the image that i am getting all the time. All the files are named " HELP_YOUR_FILES.extension ".



HELP_YOUR_FILES.PNG
 
If you truly need help I can probably help you. DAMMIT I hate bug catching, but if you haven't got a fix let me know.
 
In my opinion you have lost your data unless you have a backup - I have not heard anyone that can decrypt those files.
 
You attacked with CryptoWall Ransomware

now they will ask you money to fix that

Its adware

scan with malwarebytes or any good spyware/adware removal sotware.

ps : You data gone if you are infected with Cryptowall. Now you can only remove that but no option to take data back
 
Last edited by a moderator:
Crypto locker attacker, you can do a system restore, there are plenty of tutorials n it, if that fails you can't recover those files, they are gone.
 
Hi, I am rohit. Today when i opened a email (which was a spam ) all pictures,text files, sql files and many more files are automatically got encrypted.

Let me correct OP

Hi, I am rohit. Today I saw a offer and i opened email and click on Attachment (which was a spyware ) all pictures,text files, sql files and many more files are automatically got encrypted.

op : that spyware encrypted all your data in background with secret key. That key they will suppose to send once you will pay. This is technology ransom (Phirautee).
 
There might be some decriptors,i saw them work in some cases,in some not
read this

techspot.com/downloads/6229-kaspersky-rakhnidecryptor.html
support.kaspersky.com/viruses/utility#rakhnidecryptor
noransom.kaspersky.com/
activationcodes-database.com/helpmeatfreespeechmail/
sensorstechforum.com/restore-files-encrypted-via-rsa-encryption-remove-cryptowall-and-other-ransomware-manually/
talosintel.com/teslacrypt_tool/
and this
wintips.org/how-to-decrypt-or-get-back-encrypted-files-by-known-encrypting-ransomware-crypt-viruses/#cryptodefense

You need to see what .extension is on your files,and try to use right tool from above ^^
it takes some processing time,it depends on core strength of your CPU
and try to google some more

On one IT forum in my country,some guys successfully decrypted all files using this methods ^^
 
There might be some decriptors,i saw them work in some cases,in some not
read this

techspot.com/downloads/6229-kaspersky-rakhnidecryptor.html
support.kaspersky.com/viruses/utility#rakhnidecryptor
noransom.kaspersky.com/
activationcodes-database.com/helpmeatfreespeechmail/
sensorstechforum.com/restore-files-encrypted-via-rsa-encryption-remove-cryptowall-and-other-ransomware-manually/
talosintel.com/teslacrypt_tool/
and this
wintips.org/how-to-decrypt-or-get-back-encrypted-files-by-known-encrypting-ransomware-crypt-viruses/#cryptodefense

You need to see what .extension is on your files,and try to use right tool from above ^^
it takes some processing time,it depends on core strength of your CPU
and try to google some more

On one IT forum in my country,some guys successfully decrypted all files using this methods ^^

Tool to decrypt RSA-2048 encryption ?

Its not possible. We are still on near 2016

Op you have two option

1. Boot on safe mode, restore system and run malwarebytes

2. Boot on safe mode and run malwarebytes and delete encrypted files (you can't decrypt that)
 
Tool to decrypt RSA-2048 encryption ?

Its not possible. We are still on near 2016

Op you have two option

1. Boot on safe mode, restore system and run malwarebytes

2. Boot on safe mode and run malwarebytes and delete encrypted files (you can't decrypt that)
Maybe it is just pretender
He can try,i personally would try, nothing costs me

"Files affected by this particular malicious threat typically have the .exx, .xyz, .zzz, .aaa, .abcor appended to the end of the file. Users may think they've been targeted by Cryptowall, because some TeslaCrypt versions may pretend to be Cryptowall 3.0.
As we have already pointed out in the comments section of the Restore Files Encrypted via RSA Encryption sensorstechforum.com/restore-...ware-manually/, the Tesla decryptor tool can be tried. You can download it from here:
talosintel.com/teslacrypt_tool/ "

and by the way @OP ,always make backup of your important data on external HDD, it is safest point
 
I tried with malware byte. Is detected and deleted and again when i restarted my system it appears again.
 
Thanks webstartm,
I will surely try this.
 
Back
Top