Link to home
Start Free TrialLog in
Avatar of jspaziano
jspazianoFlag for United States of America

asked on

Cryptowall and Windows Server Backup

We have seen a number of CryptoWall infections over the last couple of months.  In one case, we had to pay the ransom.  My question relates to the potential encryption of backups.  We have a number of clients running Windows Server Backup on Server 2008 or 2012.  We back up to an external drive on the server.  Does CryptoWall affect the Windows Server backup file when the server has been infected?  I know that the latest variation deletes Shadow Copies, but cannot find a reference to the Windows Backup file.  Most of our clients use ShadowProtect and we send their backups offsite.  I feel pretty safe with those clients.  However, some clients use the built-in Windows Server backup and do not send offsite.
ASKER CERTIFIED SOLUTION
Avatar of rindi
rindi
Flag of Switzerland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Another thing I forgot to mention, servers themselves shouldn't not get infected (unless you are talking terminal servers), as people would need to be directly working on the server itself to get the virus installed on it. So only the users' workstation would be running the virus. As the normal PC's shouldn't have access to the backup files, they can't easily get changed by any malware.