Link to home
Start Free TrialLog in
Avatar of unrealone1
unrealone1Flag for United Kingdom of Great Britain and Northern Ireland

asked on

Cryptolocker virus infection

Hello Experts,

A client of ours has been hit with a cryptolocker virus. The client uses a Domain controller running Server 2003 which we are in the process of upgrading.

They also use drop box & recently this has been compromised.

Attached are the file types which are contained in each subfolder that has been encrypted.

We are currently running Sophos Enterprise 5.2.1 R2. Any advice would be appreciated as we are unable to restore unless we pay the ransom fee.
Avatar of Wayne88
Wayne88
Flag of Canada image

Unfortunately there I don't know of any fix for this except to reimage from backup.  Do your client have a solid daily backup in place?

There is no attachment.  Can you repost?  Thanks.
Avatar of unrealone1

ASKER

Please find the image attached. We have checked our backup retention period & this runs up to 14 days only. The infection occurred on the 17th of Sept
Capture.PNG
SOLUTION
Avatar of Wayne88
Wayne88
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
this is a stinker of a virus everyone, make sure AV is up to date and backups are robust.