Solved Windows 7 - Various Files Show As Corruputed After Virus Removal

Adplusone

New Member
Thread author
Verified
Aug 13, 2014
48
Need your help again!

Thanks!

Adplusone
 

Attachments

  • Addition.txt
    42 KB · Views: 1
  • AdwCleaner[S1].txt
    2.8 KB · Views: 1
  • FRST.txt
    76.8 KB · Views: 1

Adplusone

New Member
Thread author
Verified
Aug 13, 2014
48
See attached for the reports from Trend Micro on what was removed and the network log.
 

Attachments

  • Adplusone Network Log 9-17-2015.txt
    111.4 KB · Views: 0
  • Adplusone Virus Removed Log 9-17-2015.txt
    154.9 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello Jeffrey,

Unfortunately, you were infected with Cryptowall malware. Basically it encrypts your files and ask for ransom to decrypt them.

If you want more information, you can read about Cryptowall on this link:

CryptoWall and HELP_DECRYPT Ransomware Information Guide and FAQ

What I can say about this is that there is no way to restore encrypted files to working condition. Basically you can either save them somewhere safe if they are too important, because in future they will probably find a fix for this encryption so you can restore your files to working condition. But this is only my assumption.


Do you still have this fake email you received?


There are still some leftover I would like to clean. Also, you can run Adwcleaner again and clean all found items.


FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    2.3 KB · Views: 2

Adplusone

New Member
Thread author
Verified
Aug 13, 2014
48
1) Reran Adwarecleaner...log attached.
2) Reran Malwarebytes Anti-Malware and came up clean.
3) Ran across the attached "ransom" instructions buried in a file.
 

Attachments

  • AdwCleaner[S4].txt
    2.8 KB · Views: 2
  • HELP_DECRYPT.PNG
    HELP_DECRYPT.PNG
    45 KB · Views: 1

Adplusone

New Member
Thread author
Verified
Aug 13, 2014
48
I guess considering paying the "ransom" is really dumb....ran the List C Wall program...it found over 6,400 files.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Is your Carbonite backup cloud based?

Yes, I don't think paying to these bad guys is a good idea, I would never give them my money for such awful thing.
 

Adplusone

New Member
Thread author
Verified
Aug 13, 2014
48
Am in process of restoring files via Carbonite...could take two days.

My TrendMicro just ran a report and found the 8 attached files (see log).

Is this related to the current problem...does that mean we did get all the Crypto files out?
 

Attachments

  • Last Scan.csv.txt
    2.7 KB · Views: 2

Adplusone

New Member
Thread author
Verified
Aug 13, 2014
48
All is clear....

Thanks again....you have helped me in the past....what is your PayPal address...would like to buy you a few beers
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top