Who is this article for?
Incydr Professional, Enterprise, Gov F2, and Horizon, no.
Incydr Basic, Advanced, and Gov F1, no.
CrashPlan Cloud, no.
Retired product plans, yes.
CrashPlan for Small Business, no.
CryptoLocker and CryptoWall are a form of malware that encrypts files on your device and demands that you pay a ransom to decrypt these files. Instead of paying the criminals behind this attack, use Code42 CrashPlan to download your files from a date and time before the infection. This article describes how to use CrashPlan to recover your files from a CryptoLocker or CryptoWall attack.
- Known to affect Windows devices
- Attacks files on any storage connected to an infected devices, including flash drives, external drives, or mapped network drives
- Targets specific file types
This article assumes you are able to edit your file retention settings. Your administrator may prevent editing of this setting.
How CrashPlan can help you recover from CryptoLocker or Cryptowall
If your device becomes infected by CryptoLocker or CryptoWall, your frequency and version settings enable you to download your files from a date and time before the infection. The version settings must allow backups frequently enough to give you a range of dates from which to choose. If these settings are too restrictive, it's possible that even your oldest version could be encrypted by CryptoLocker or CryptoWall. To check how frequently versions of your files are backed up:
- Sign in to the Code42 console.
- Choose Devices.
- From Device Overview, click on the name of the device.
- Select the action menu.
- Choose Edit.
- Select Backup.
- Navigate to Frequency and Versions.
Before you begin
The recommended solution below instructs you to download files from a date before infection. If you do not know the date of infection, you can download several file versions to determine the date of infection.
To download an earlier version of the file:
- Sign in to the Code42 app.
- From the list of your devices, select Get Files for the infected device.
- If you are backing up to multiple destinations, you can select the arrow next to the destination shown to choose a destination.
- Click As Of Today.
The date and time selection window opens.
- Select a date and time that you believe is close to the time of infection.
- Hover over an infected file, and click the download icon.
Your download is added to the downloads manager.
- Open the file.
If you are able to open the file, then you know that your device was not yet infected on the date and time you selected. If the downloaded file is encrypted, repeat the steps above and select an earlier date and time.
CryptoLocker and CryptoWall informs you of infection only after they have finished encrypting your files. This encryption process can take several hours or days, depending on your device and your files. You may want to test several files to further isolate the date and time of infection.
If your device is infected by CryptoLocker or CryptoWall, follow the steps below to recover your files.
Step 1: Remove the CryptoLocker or Cryptowall infection
If you have not already done so, the first step is to remove the infection from the affected device. Many sites offer tutorials on removing CryptoLocker or CryptoWall. See External Resources for more information.
Note: Code42 Customer Champions cannot help you remove CryptoLocker or CryptoWall from your device. Consult a specialist if you have additional questions about removing the infection.
Some variants of CryptoLocker and CryptoWall may rename your files. Check for any renamed files and remove them before continuing.
Step 2: Download files from a time before the infection
If you replaced or reformatted the infected device, follow our Downloading All Files On A New Device guide.
You must download your files from a date and time before the infection.