Solved

User opened email with a bad word doc malware or virus in it

Posted on 2016-07-26
5
23 Views
Last Modified: 2016-09-25
It created a bunch of shortcuts and with the original folder names, Hid the original folders and renamed them to a sid The shortcut if you click on it contains the sid folder name in the command line (they tried to create a script that deleted the folder if you clicked on the shortcut but it didnt work on the NAS we have luckily.  The hard part is right clicking each shortcut looking at the sid name and then renaming and unhide the correct folder.  Has anyone had this and is there any kind of tool to put everything back?
0
Comment
Question by:charles18602
  • 4
5 Comments
 
LVL 92

Accepted Solution

by:
John Hurst earned 500 total points (awarded by participants)
ID: 41730365
Are the files in the folders encrypted?  It looks like the Crypto virus or another kind of virus that affects folders.

Since your NAS is OK (and the contents I assume), isolate this machine immediately, format it, reinstall Windows and recovery the documents from the NAS.
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41749643
@ charles18602 - Did you restore from a backup?
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41768011
You have the Crypto Virus, right?  Did you restore from backup?
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41787141
Have you restored from backup?
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VBA code snippets in a Word 2016 document 3 71
Always hangs on opening 8 65
Roguekiller has no option of deleting 19 88
Regarding Notepad++ 4 35
These are on the increase and getting more common these days. Users who use the Google search engine may complain of having their search redirected to unwanted sites, regardless of what browser is used. This happens when the system is infected with…
HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
This Micro Tutorial well show you how to find and replace special characters in Microsoft Word. This is similar to carriage returns to convert columns of values from Microsoft Excel into comma separated lists.
Office 365 is currently available in five editions. Three of them are for business use: Office 365 Business Essentials, Office 365 Business, and Office 365 Business Premium. Two of them are for home/personal use: Office 365 Home and Office 365 Perso…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now