I am very surprised not able to find anything on Experts Exchange referencing CryptoDefense Software
It appears a folder on the users Desktop, his networked H-Drive and many folders and many folders under his other networked drive are severely infected with CryptoDefense Software. All folders and files have a time stamp 4/2/2014 4:27pm. Every folder has a “decrypt” file. Can’t open anything that has the dycrpto files in its folder
- updated and ran the new Malwarebytes but it found nothing.
- ran a full MSE scan. Found no issues
- attempted to run the Carbonite restore and it failed to open with script errors. Rebooted PC. Carbonite still fails with script errors
- ran a rogue killer program. Found and removed several malicious entries. Required another reboot
- I don’t see the actual QuickBooks files infected but many of its related folders have been infected
I have not yet performed a system restore to an earlier time. I contacted one of my very experienced Windows engineers and he stated that would not help
We could try logging on as the administrator and in safe mode but bottom line is that we need a restore.
From everything I read, we need to perform a restore from before 4/2/2014. Since the Carbonite will not run from the PC, I need to get in touch with the person who has access to the credentials to Carbonite access and restore
Any help would be appreciated