Solved

Virus / Malware that changes file extensions to .pdf.xdtorli or .*.xdtorli CryptoWall virus

Posted on 2014-12-11
7
4,264 Views
Last Modified: 2014-12-11
I have a work station that where the "internet stopped working". When I check the work station I found many issues. I ran mbam, TDSSKiller, and ComboFix. I believe this removed the issues, but I now need to repair the damage. Question: Is there some else I should check to make sure malware / virus has been removed. Question: How should repair all the files that have been changed from #####.pdf.xdtorli, #####.xls.xdtorli, ....?
 I have the log file for scan if need. The rootkit found was Rootkit.Boot.Cidox.b

I started in the wrong place... original Q&A string.
http://www.experts-exchange.com/Community_Support/CleanUp/Q_28578918.html#a40494304
0
Comment
Question by:BrianDHoyt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 34

Expert Comment

by:Michael-Best
ID: 40494345
Can you restore to a time before infection?
0
 

Author Comment

by:BrianDHoyt
ID: 40494354
yes I can now... I could not at first.
I'm running through this...
http://www.pcrisk.com/removal-guides/7844-cryptowall-virus#a2
0
 
LVL 28

Expert Comment

by:Thomas Zucker-Scharff
ID: 40494386
Be my guest and run through it, but to the best of my knowledge there is no "fix" for cryptowall and its' derivatives.  The only option is restoring from backup or a system restore.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:BrianDHoyt
ID: 40494410
well, that's pretty much what it says as well.
How about on networked drives? rename the fill is the issue I'm working on. Is that pretty much the same: Restore or Replace?
0
 
LVL 34

Accepted Solution

by:
Michael-Best earned 500 total points
ID: 40494418
Your only solution is to restore to a time before infection.
Use a restore point or a backup.
0
 

Author Comment

by:BrianDHoyt
ID: 40494442
but that will not Un-encrypt the files. Correct?
0
 

Author Comment

by:BrianDHoyt
ID: 40494485
Okay for people who have to deal with this in the future.
1 Clean workstation.
2 Restore from system restore point
3 Restore file from "Restore previous version"
4 Search for encrypted file extension and delete
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as high-speed processing of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
Article by: Justin
In light of the WannaCry ransomware attack that affected millions of Windows machines, you might wonder if your Mac needs protecting. Yes, it does and here is how to do it.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question