About this question
Is there a way to decrypt Cryptowall3? What is the best way to prevent these kinds of viruses from infecting our computers? Are there any ways to prevent the execution of unknown files?
A blog I recently read had the following information on cryptowall3 that Cryptowall 3 ransomware employs multiple dropper files and contains a number of different exploits. Once initiated, code is injected into a new explorer.exe process which installs the malware while disabling system protections. Malicious code is then hidden in a new SVChost.exe process.
The malware collects a considerable amount of data from the host computer, obtains an external IP address, establishes a connection, and registers the machine with the hacker’s command and control center. A POST request is made and the main Cryptowall 3 thread is initiated.