Solved

Virus / Malware that changes file extensions to .pdf.xdtorli or .*.xdtorli CryptoWall virus

Posted on 2014-12-11
7
4,259 Views
Last Modified: 2014-12-11
I have a work station that where the "internet stopped working". When I check the work station I found many issues. I ran mbam, TDSSKiller, and ComboFix. I believe this removed the issues, but I now need to repair the damage. Question: Is there some else I should check to make sure malware / virus has been removed. Question: How should repair all the files that have been changed from #####.pdf.xdtorli, #####.xls.xdtorli, ....?
 I have the log file for scan if need. The rootkit found was Rootkit.Boot.Cidox.b

I started in the wrong place... original Q&A string.
http://www.experts-exchange.com/Community_Support/CleanUp/Q_28578918.html#a40494304
0
Comment
Question by:BrianDHoyt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 34

Expert Comment

by:Michael-Best
ID: 40494345
Can you restore to a time before infection?
0
 

Author Comment

by:BrianDHoyt
ID: 40494354
yes I can now... I could not at first.
I'm running through this...
http://www.pcrisk.com/removal-guides/7844-cryptowall-virus#a2
0
 
LVL 26

Expert Comment

by:Thomas Zucker-Scharff
ID: 40494386
Be my guest and run through it, but to the best of my knowledge there is no "fix" for cryptowall and its' derivatives.  The only option is restoring from backup or a system restore.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:BrianDHoyt
ID: 40494410
well, that's pretty much what it says as well.
How about on networked drives? rename the fill is the issue I'm working on. Is that pretty much the same: Restore or Replace?
0
 
LVL 34

Accepted Solution

by:
Michael-Best earned 500 total points
ID: 40494418
Your only solution is to restore to a time before infection.
Use a restore point or a backup.
0
 

Author Comment

by:BrianDHoyt
ID: 40494442
but that will not Un-encrypt the files. Correct?
0
 

Author Comment

by:BrianDHoyt
ID: 40494485
Okay for people who have to deal with this in the future.
1 Clean workstation.
2 Restore from system restore point
3 Restore file from "Restore previous version"
4 Search for encrypted file extension and delete
0

Featured Post

To Patch or not to Patch? That is the question!

Don't get caught out like thousands of others around the world in the recent Ransomware Fiasco!
Discuss..
- Why it's not a good idea to wait before Patching
- Sensible approaches to Patching discussed
- Add your feedback, comments and suggestions

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
Smart phones, smart watches, Bluetooth-connected devices—the IoT is all around us. In this article, we take a look at the security implications of our highly connected world.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question