We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Cryptowall Virus

glicky
glicky Posts: 318 Forumite
edited 15 May 2014 at 12:34PM in Techie Stuff
I wonder if any of you kind folks can help me please?

My friend has this Cryptowall virus on her computer which has completely ruined it. Slow as hell and cannot do hardly anything on it. Can't even get into Malwarebytes or MSE. Says it has to be gotten into by an administrator, but when I go in as an administrator, it still won't let me do anything. Has messed up the e-mail too. It won't even allow me to go into Safe Mode.

Anyone know how to get rid of it or do I need to take it into an engineer?

Your help would be appreciated. Thanks in advance.

Comments

  • GunJack
    GunJack Posts: 11,884 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    basically, you can't get their files decrypted without paying the ransom, it's a new variant of Cryptolocker. Clean install of OS and replace pics/docs/music from their backup, or full disk image restore from their last backup image....

    what do you mean, what backups?
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • glicky
    glicky Posts: 318 Forumite
    GunJack wrote: »
    basically, you can't get their files decrypted without paying the ransom, it's a new variant of Cryptolocker. Clean install of OS and replace pics/docs/music from their backup, or full disk image restore from their last backup image....

    what do you mean, what backups?

    Sorry.. I'm not tech minded. Could you please explain.
  • bod1467
    bod1467 Posts: 15,214 Forumite
    Basically your mate if funked. The PC needs to be completely rebuilt from scratch. (i.e. using the reinstall partition that came on the PC, or using a reinstall disk that came with the PC or which was created when the PC was first run*).

    And then reload all the necessary apps from the installation disks** and then reinstate the files/photos etc. from the backups that were made***

    * This WAS done, wasn't it?
    ** The installation disks ARE available, aren't they?
    *** Your mate DOES have backups, doesn't he?
  • glicky
    glicky Posts: 318 Forumite
    bod1467 wrote: »
    Basically your mate if funked. The PC needs to be completely rebuilt from scratch. (i.e. using the reinstall partition that came on the PC, or using a reinstall disk that came with the PC or which was created when the PC was first run*).

    And then reload all the necessary apps from the installation disks** and then reinstate the files/photos etc. from the backups that were made***

    * This WAS done, wasn't it?
    ** The installation disks ARE available, aren't they?
    *** Your mate DOES have backups, doesn't he?
    Thanks.

    No she doesn't have back ups :(

    Are all her documents "funked" too?

    So basically....... "bin it"?
  • GunJack
    GunJack Posts: 11,884 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    glicky wrote: »
    Thanks.

    No she doesn't have back ups :(

    Are all her documents "funked" too?

    So basically....... "bin it"?

    no, not bin it, the pc will work again AFTER a complete re-install of the operating system (whichever version of windows was on it)...

    ....but all her pics/music/docs stored on it are funked....
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • GunJack
    GunJack Posts: 11,884 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    IF there's a recovery partition on the hdd, you could reinstall from that, then use CCleaner's free space wiper to wipe the rest of the drive to ensure no trace is left of the actual virus...
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • glicky
    glicky Posts: 318 Forumite
    GunJack wrote: »
    IF there's a recovery partition on the hdd, you could reinstall from that, then use CCleaner's free space wiper to wipe the rest of the drive to ensure no trace is left of the actual virus...
    There is a recovery drive on the computer but it looks like it's infected that because on there it says Decrypt Instructions :(
  • GunJack
    GunJack Posts: 11,884 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    oh well, shame - sometimes they escape the initial infection :( If you supply the full make & model of the laptop a certain niftydigits may be able to find a machine-specific windows installation disk for it :) ... you may need to PM him :)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.8K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.