Skip to main content

Hypothetical: When restoring after ransomware encrytion wipe drive(s) first?

Thread needs solution

Acronis True Image 2016 Windows 7 Professional 64-bit.

The instances of computers being infected with ransomware are increasing. If this should happen should one wipe or format the infected drives and then use the rescue disk to reboot and then recover the computer? The alternative seems to be just recover all files by overwriting the encrypted files.

Minor problem: When I want to recover only one file and use the GUI it does not show individual files of the selected drive. I can use Windows Explorer to select and recover a file.

Thanks,

Charles

0 Users found this helpful

Charles,

https://forum.acronis.com/forum/109233

The link above may be of interest to you...it contains some opinions regarding Cryptowall.

Charles Elias wrote:
The instances of computers being infected with ransomware are increasing. If this should happen should one wipe or format the infected drives and then use the rescue disk to reboot and then recover the computer? The alternative seems to be just recover all files by overwriting the encrypted files.

A wipe or format is probably not required.  However, my recovery plan for any malware is to format the drive and then do a restore of an image that was made several days prior to the infection.  My personal recommendation is to do a minimum of 1 backup (incremental) per day.

Charles Elias wrote:
Minor problem: When I want to recover only one file and use the GUI it does not show individual files of the selected drive. I can use Windows Explorer to select and recover a file.

When you want to recover only one file or several files, you should "Mount" the image.  Mounting an image assigns drive letter(s) to each partition in the image. You can then use Windows explorer to extract the file. 

Mounting is covered in paragraph 11.7 of the user manual, starting on page 149.

Regards,
FtrPilot

Hello,

I would perform a regular (not quick) format of the infected drive. Make sure that you have a backup of uninfected system.

Best regards.

AlexanderK,

Thanks for the advice.

FtrPilot,

I found that I can use the GUI to view the files--no mounting required.

Charles