Solved

File names changed to .ENCODED

Posted on 2010-11-29
4
1,077 Views
Last Modified: 2012-05-10
Last Friday (11/26) many files on my network suddenly appear with .ENCODED as the file extension.  It's hit and miss around the network.  It's effected PDFs, XLS and DBF file type.  There's no rhyme nor reason I can figure out.  I noticed one folder on Saturday and restored it from backups, but it's all over the place.  

I've got Trend Micro running on all workstations and servers, so I should be protected.  I can't find anything online on this.  Any ideas?

If I remove the .ENCODED from the file name and open it, it's gibberish.
0
Comment
Question by:BigRBTrout
  • 3
4 Comments
 
LVL 27

Accepted Solution

by:
Tolomir earned 500 total points
ID: 34232454
this seems to fit here:

Malicious hackers are spreading the ransomware, which encrypts media and Office files on victim's computers, in an attempt to extort $120. In a nutshell - you can't access your files because the malicious code has encrypted them (in our observations, the whole file isn't encrypted - just the first 10% or so), and the hackers want you to pay the ransom if you want your valuable data back.

http://nakedsecurity.sophos.com/2010/11/26/drive-by-ransomware-attack-demands-120/
0
 
LVL 27

Assisted Solution

by:Tolomir
Tolomir earned 500 total points
ID: 34232478
you can check if there are these system modifications.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojransomu.html

0
 
LVL 27

Assisted Solution

by:Tolomir
Tolomir earned 500 total points
ID: 34232499
in short, remove the trojan.

You could use the sophos beta for it.

http://www.sophos.com/products/beta/
--
then  apply all windows updates. Also try to prevent to work with Administrator permissions. Especially when surfing the Internet.
0
 
LVL 1

Author Comment

by:BigRBTrout
ID: 34233329
Thanks, this helped out, quite a bit.  I've got Trend Micro working on removal and I'm restoring files.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Bitlocker on SQL Server question 14 58
for ssh without password, are both ways correct 16 58
Bit Locker 2 52
mysql Encryption with PHP 8 47
Today, security is a big concern in an organization to prevent sensitive data leakage. In Outlook you can secure your Outlook items (emails, calendars, contacts and other stuff) using various techniques like by marking item as private, or you can pu…
Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now