Link to home
Start Free TrialLog in
Avatar of Bruce Corson
Bruce CorsonFlag for United States of America

asked on

CTB-Locker on Dropbox

CTB-Locker has encrypted many, not all, files on our Dropbox account. Once I get rid of the infected files (I am assuming they are the ones with the 6 or7 character file extensions), how can I use the Dropbox account again? If I delete everything, is it safe?

Help? Thank you.
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

find the compromised machine and restore from a backup to before you were infected or do a clean install.  There will be others that say just clean the machine using various tools and you will be fine.. The nagging question will always be did I get it all.. Once a machine is compromised the best rule of thumb is to not trust it again unless you follow my suggestion - re-install from a known good backup or a format and reinstall from scratch. delete the encrypted files from dropbox and you should be good to go afterwards.. but first before you re-enable dropbox client that your machine is good.
ASKER CERTIFIED SOLUTION
Avatar of Thomas Zucker-Scharff
Thomas Zucker-Scharff
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
>>  CTB-Locker has encrypted many, not all, files on our Dropbox account.

Have you identified the source of the virus?  Is it your machine or is another computer with access to the Dropbox account?
Avatar of Bruce Corson

ASKER

dbrunton...source of virus I BELIEVE is on the main laptop. It is the most heavily infected. Looks like DB was just in the process of deleting files and replacing with encrypted files.

David Johnson...thank you, that's what we're doing for the computer. It's the Dropbox over which I was most puzzled. And, this one account, which belongs to a large non-profit, had shares going out to many people.

Thomas Zucker-Scharff, thank you, exactly what I was looking for.
It's the Dropbox over which I was most puzzled. And, this one account, which belongs to a large non-profit, had shares going out to many people. Glad you found the source otherwise it would be near impossible to locate it as any computer that can access it could encrypt the files. Unfortunate that you can't finger point elsewhere..