Recover encrypted files by virus

Page 2 of 2 FirstFirst 12

  1. Posts : 16,325
    W10Prox64
       #11

    Update:
    The CryptoWall v4 is sneaky now, in that, after deleting the original file, it puts the new, encrypted file in the exact sector where the original was deleted. This makes it very difficult to recover the original deleted file.

    Interestingly, there appear to be certain regions where it does not wish to attack, and if it detects these languages, it will not infect the computer: Russian, Kazakh, Ukrainian, Uzbek, Belarusian, Azeri, Armenian, Kyrgyz, Georgian.

    It is also using drive-by-download techniques and the Angler Exploit Kit, which means that you can be infected simply by visiting an infected website; malicious code is executed via hidden iFrame(s) after identifying unpatched programs/browsers/add-ons, and injected into svchost.exe, bypassing the UAC when deleting all Shadow Copies if you are using an account with administrative privileges, and thus tricking many AVs in the process.

    ref: Security Alert: Angler Exploit Kit Spreads CryptoWall 4.0 via New Drive-By Campaign - Heimdal Security Blog

    ref: Cisco Talos Blog: Threat Spotlight: CryptoWall 4 - The Evolution Continues
      My Computer


  2. Posts : 2,935
    Windows 10 Home x64
    Thread Starter
       #12

    Thanks for the info simrick.
      My Computer


  3. Posts : 16,325
    W10Prox64
       #13

    eLPuSHeR said:
    Thanks for the info simrick.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:04.
Find Us




Windows 10 Forums