Solved

Ransom Ware

Posted on 2014-03-12
8
438 Views
Last Modified: 2014-03-14
Hi I have a real-estate company  that has just had a ransom ware attack
this file on shared folders on the server

"All files including videos, photos and documents on your computer are encrypted.

In order to decrypt the files, open site 4sfxctgp53imlvzk.onion"

I can access files using previous versions without issue (lucky) sbs2011
question there running AVG Business on the server & workstation
is this program likely running on a PC that's doing this (how to locate?)

I'm hoping not to have to reload the server , but may have reload all workstations
or could I get away with a system restore?
0
Comment
Question by:Logical_Step
  • 5
  • 3
8 Comments
 
LVL 10

Expert Comment

by:cpmcomputers
Comment Utility
0
 
LVL 1

Author Comment

by:Logical_Step
Comment Utility
Thanks
It look similar
will check all PC's tomorrow morning
0
 
LVL 10

Expert Comment

by:cpmcomputers
Comment Utility
Beware that the later versions can disable your shadow copies
This will leave you no way but to restore from backup or pay the ransom ( not guarantee or recommended)

Depending on your file sizes it may be useful to "restore from previous versions" using you shadowcopies  all critical data now to an alternative location Then take it offline
this should give you a safety backup if all else fails

I dealt with a case of this on two occasions
The entry point was a user opening an innocent looking .zip file  in an email attachment
So the infection will probably be on a workstation not the server itself

Good luck
keep us posted
0
 
LVL 1

Author Comment

by:Logical_Step
Comment Utility
After disconnecting all PC from the Network
managed to recover all files from a few days earlier with previous versions off the server
I couldn't find any with Cryptolocker files on any PC's
in apps local or registry run
I did a system restore on all in case due to time issues (unplugged didn't loose trust)
All running fine for last couple of days

PS Couldn't find any email attachments either in the time period
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 10

Expert Comment

by:cpmcomputers
Comment Utility
I would now scan all the pc ' s and servers with malwarebytes as a check and prevent reinfection (you can get the free version from the bleeping computers site)

Is it possible a pc or perhaps a laptop user (not presently on the network) has been missed?
0
 
LVL 10

Accepted Solution

by:
cpmcomputers earned 500 total points
Comment Utility
I was just looking at the encryption message
Check out
http://botcrawl.com/remove-cryptorbit-virus/with malwarebytes
 
Looks like you might be lucky and have this rather than cyryptolocker itself

Is it possible a pc or perhaps a laptop user (not presently on the network) has been missed?
0
 
LVL 10

Expert Comment

by:cpmcomputers
Comment Utility
0
 
LVL 1

Author Comment

by:Logical_Step
Comment Utility
That link didn't work but this does

http://www.bleepingcomputer.com/virus-removal/cryptorbit-ransomware-information
& yes this look like it , all PC's were scanned with Malware Bytes  All Clean

Will keep checking
Thanks for your help
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now