Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Ransom Ware

Posted on 2014-03-12
Medium Priority
Last Modified: 2014-03-14
Hi I have a real-estate company  that has just had a ransom ware attack
this file on shared folders on the server

"All files including videos, photos and documents on your computer are encrypted.

In order to decrypt the files, open site 4sfxctgp53imlvzk.onion"

I can access files using previous versions without issue (lucky) sbs2011
question there running AVG Business on the server & workstation
is this program likely running on a PC that's doing this (how to locate?)

I'm hoping not to have to reload the server , but may have reload all workstations
or could I get away with a system restore?
Question by:Logical_Step
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
LVL 10

Expert Comment

ID: 39922975

Author Comment

ID: 39923096
It look similar
will check all PC's tomorrow morning
LVL 10

Expert Comment

ID: 39923129
Beware that the later versions can disable your shadow copies
This will leave you no way but to restore from backup or pay the ransom ( not guarantee or recommended)

Depending on your file sizes it may be useful to "restore from previous versions" using you shadowcopies  all critical data now to an alternative location Then take it offline
this should give you a safety backup if all else fails

I dealt with a case of this on two occasions
The entry point was a user opening an innocent looking .zip file  in an email attachment
So the infection will probably be on a workstation not the server itself

Good luck
keep us posted
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.


Author Comment

ID: 39928578
After disconnecting all PC from the Network
managed to recover all files from a few days earlier with previous versions off the server
I couldn't find any with Cryptolocker files on any PC's
in apps local or registry run
I did a system restore on all in case due to time issues (unplugged didn't loose trust)
All running fine for last couple of days

PS Couldn't find any email attachments either in the time period
LVL 10

Expert Comment

ID: 39928609
I would now scan all the pc ' s and servers with malwarebytes as a check and prevent reinfection (you can get the free version from the bleeping computers site)

Is it possible a pc or perhaps a laptop user (not presently on the network) has been missed?
LVL 10

Accepted Solution

cpmcomputers earned 1500 total points
ID: 39928620
I was just looking at the encryption message
Check out
http://botcrawl.com/remove-cryptorbit-virus/with malwarebytes
Looks like you might be lucky and have this rather than cyryptolocker itself

Is it possible a pc or perhaps a laptop user (not presently on the network) has been missed?
LVL 10

Expert Comment

ID: 39928641

Author Comment

ID: 39928738
That link didn't work but this does

& yes this look like it , all PC's were scanned with Malware Bytes  All Clean

Will keep checking
Thanks for your help

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
There are many Password Managers (PM) out there to choose from. PM's can help with your password habits and routines, but they should not be a crutch you rely on too heavily. I also have an article for company/enterprise PM's.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question