Cryptowall is ransomware that is mostly distributed through spam emails. However, malicious Ads, infected websites and other malware are also used to distribute it. A typical email contains a malicious attachment that contains the ransomware and a message that attempts to socially engineer the user in downloading the file. The subject of the email mostly uses the excuses of invoices, undelivered packaged goods, fax reports etc. Once the user clicks on the attachment, the ransomware is executed and all files are encrypted. Another striking feature about Cryptowall is the use of Rig exploit kit and Nuclear exploit kit to spread it.
In this article, we will discuss how to remove Cryptowall ransomware from your computer and get your files back from the encrypted forms.
The steps mentioned in this articles are however meant only for the Windows XP, Windows 7 and Windows 8.
Windows 7 and Windows XP users need to start their computers in Safe Mode. The procedure for starting PC in safe mode for these two operating systems are:
Windows 8 users also need to begin with Safe Mode. Following are the steps to start your Windows 8 based system in Safe Mode:
Now you need to login to the account that is infected by Cryptowall ransomware. Now you need to download an antivirus software and perform a complete system scan. Whatever entries are highlighted by the antivirus, act by removing all of them.
If you are unable to start your system in Safe Mode with Networking, you should try to perform a system restore. Some of the variants of this ransomware disable all means to start the system in Safe Mode.
Steps for performing System Restore:
Once all the virus files have been eliminated from the computer, you can now proceed to decrypt the files. Try using Windows Previous Versions feature. However, this feature will work only if System Restore was enabled on the infected system. Also infections by some of the variants of Cryptowall disable this feature and hence it may now work.
To restore a file using Windows Previous Versions:
You can also use the tool Shadow Explorer to decrypt the files encrypted by CryptoWall.
Publisher