Author Topic: a school network computer just got cryptowall 3. Why did Avast not prevent it?  (Read 4104 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Our school has over 300 desktop computers and one of our teachers just got hit with cryptowall 3.0.  She had her usb drive connected and it is infected as well.  We have Endpoint Protection Suite for Edu and nothing has been found on the infected pc by Avast after running scans.  Is this variant to new???

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
CryptoWall and its variants are sometimes difficult to detect. This is not just the case with Avast but other AV solutions as well.

The best protection from CryptoWall/CryptoLocker/etc is a valid backup with versioning.
"People who are really serious about software should make their own hardware." - Alan Kay

REDACTED

  • Guest
>>> The best protection from CryptoWall/CryptoLocker/etc is a valid backup with versioning.

What if it's too late ?   Too late to backup because CryptoWall is already dug in.

How do I get rid of it ?


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Please start your own thread in the correct forum and follow these instructions :
http://forum.avast.com/index.php?topic=53253.0

REDACTED

  • Guest
>>> The best protection from CryptoWall/CryptoLocker/etc is a valid backup with versioning.

What if it's too late ?   Too late to backup because CryptoWall is already dug in.

How do I get rid of it ?

Start a new Thread as Eddy described. If you make on in the viruses and worms section the guys can help you remove the malware.  You will need a backup to recover the data, otherwise you can try to pay the ransom but thats not recommended as there is no guarantee that the data will be decrypted if you pay