Solved

File names changed to .ENCODED

Posted on 2010-11-29
4
1,081 Views
Last Modified: 2012-05-10
Last Friday (11/26) many files on my network suddenly appear with .ENCODED as the file extension.  It's hit and miss around the network.  It's effected PDFs, XLS and DBF file type.  There's no rhyme nor reason I can figure out.  I noticed one folder on Saturday and restored it from backups, but it's all over the place.  

I've got Trend Micro running on all workstations and servers, so I should be protected.  I can't find anything online on this.  Any ideas?

If I remove the .ENCODED from the file name and open it, it's gibberish.
0
Comment
Question by:BigRBTrout
  • 3
4 Comments
 
LVL 27

Accepted Solution

by:
Tolomir earned 500 total points
ID: 34232454
this seems to fit here:

Malicious hackers are spreading the ransomware, which encrypts media and Office files on victim's computers, in an attempt to extort $120. In a nutshell - you can't access your files because the malicious code has encrypted them (in our observations, the whole file isn't encrypted - just the first 10% or so), and the hackers want you to pay the ransom if you want your valuable data back.

http://nakedsecurity.sophos.com/2010/11/26/drive-by-ransomware-attack-demands-120/
0
 
LVL 27

Assisted Solution

by:Tolomir
Tolomir earned 500 total points
ID: 34232478
you can check if there are these system modifications.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojransomu.html

0
 
LVL 27

Assisted Solution

by:Tolomir
Tolomir earned 500 total points
ID: 34232499
in short, remove the trojan.

You could use the sophos beta for it.

http://www.sophos.com/products/beta/
--
then  apply all windows updates. Also try to prevent to work with Administrator permissions. Especially when surfing the Internet.
0
 
LVL 1

Author Comment

by:BigRBTrout
ID: 34233329
Thanks, this helped out, quite a bit.  I've got Trend Micro working on removal and I'm restoring files.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

#SSL #TLS #Citrix #HTTPS #PKI #Compliance #Certificate #Encryption #StoreFront #Web Interface #Citrix XenApp
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now