Good Day

One of my pc has been infected by a Ransom:Win32/Crowti.gen!A virus and as a result all the files are are not accessible they appear as encrypted and the file extensions automatically default to .AAA whether be it a txt, ppt, xls, docx or pdf file.

Is there a way to detect and remove this virus, and does this also assist in decrypting the files so that they can be accessible again.

Please assist.

regards,

Dani AI

Generated

Brief expert summary and practical next steps tied to the thread

reported a Crowti/CryptoWall detection and asked about removal and file recovery. ’s comment (that paying is the only option) reflects a common belief, but official guidance stresses containment, evidence preservation, and recovery planning rather than reflexively paying a ransom. See the U.S. government #StopRansomware guidance for recommended incident steps. (cisa.gov)

Immediate containment and evidence preservation

  • Disconnect the infected machine from the network and unplug any external drives immediately.
  • If possible, capture volatile data and make a full disk image before attempting cleanup; if that isn’t possible, power the machine off to limit further damage and preserve the disk for a later image. These are standard first‑response actions for ransomware incidents. (cisa.gov)

Removal vs. recovery

  • Use a reputable anti‑malware product (Microsoft Defender, Malwarebytes, etc.) or boot from clean media to remove the active ransomware. Removal prevents further encryption but does not restore already‑encrypted files; the No More Ransom project explicitly recommends removing malware first, then checking for available decryptors. (nomoreransom.org)

File recovery options (in order of preference)

  • Restore from verified offline backups (best). (cisa.gov)
  • Check No More Ransom’s decryptor list for a matching tool (if one exists it’s the safe route). (nomoreransom.org)
  • If no decryptor is available, try Windows “Previous Versions” / ShadowCopies or file‑recovery tools (ShadowExplorer, PhotoRec) only after imaging; many Crowti/CryptoWall variants try to remove shadow copies so success varies. Preserve samples of encrypted files and the ransom note for researchers/law enforcement. (bleepingcomputer.com)

Report and next steps

  • Report the incident to law enforcement/IC3 and consider an incident response firm if the data are critical. Paying the ransom is risky and may not result in recovery; law enforcement and CISA advise caution and reporting. (cisa.gov)

References: CISA #StopRansomware guidance; No More Ransom decryption tools; Trend Micro Crowti threat page; Microsoft Defender definitions. (cisa.gov)

Recommended Answers

All 3 Replies

As far as I know the only way to get your encrypted adta back is to pay the ransom. Typically you are given a set number of days to pay the ransom. If you don't pay it before the deadline you are screwed. Removing the virus has the same effect as missing the deadline. It's sort of like in the movies when the hero cuts the wrong bomb wire and the timer fast-forwards to zero.

Ok thanks Reverend Jim.

THX FOR THE INFO

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.