?
Solved

File names changed to .ENCODED

Posted on 2010-11-29
4
Medium Priority
?
1,103 Views
Last Modified: 2012-05-10
Last Friday (11/26) many files on my network suddenly appear with .ENCODED as the file extension.  It's hit and miss around the network.  It's effected PDFs, XLS and DBF file type.  There's no rhyme nor reason I can figure out.  I noticed one folder on Saturday and restored it from backups, but it's all over the place.  

I've got Trend Micro running on all workstations and servers, so I should be protected.  I can't find anything online on this.  Any ideas?

If I remove the .ENCODED from the file name and open it, it's gibberish.
0
Comment
Question by:BigRBTrout
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 27

Accepted Solution

by:
Tolomir earned 2000 total points
ID: 34232454
this seems to fit here:

Malicious hackers are spreading the ransomware, which encrypts media and Office files on victim's computers, in an attempt to extort $120. In a nutshell - you can't access your files because the malicious code has encrypted them (in our observations, the whole file isn't encrypted - just the first 10% or so), and the hackers want you to pay the ransom if you want your valuable data back.

http://nakedsecurity.sophos.com/2010/11/26/drive-by-ransomware-attack-demands-120/
0
 
LVL 27

Assisted Solution

by:Tolomir
Tolomir earned 2000 total points
ID: 34232478
you can check if there are these system modifications.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojransomu.html

0
 
LVL 27

Assisted Solution

by:Tolomir
Tolomir earned 2000 total points
ID: 34232499
in short, remove the trojan.

You could use the sophos beta for it.

http://www.sophos.com/products/beta/
--
then  apply all windows updates. Also try to prevent to work with Administrator permissions. Especially when surfing the Internet.
0
 
LVL 1

Author Comment

by:BigRBTrout
ID: 34233329
Thanks, this helped out, quite a bit.  I've got Trend Micro working on removal and I'm restoring files.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as high-speed processing of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
The conference as a whole was very interesting, although if one has to make a choice between this one and some others, you may want to check out the others.  This conference is aimed mainly at government agencies.  So it addresses the various compli…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question