Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

SYSVOL and NETLOGON affected by crypto virus

Posted on 2016-09-09
7
Medium Priority
?
317 Views
Last Modified: 2016-09-11
Hi all

We have a SBS 2011 server and somehow the SYSVOL folder was affected by a crypto virus.

This is a server at a charity and they have only just noitced 10 days after it happened.

Is there a way i can recreate the items in these folders?

Thanks
0
Comment
Question by:David
  • 3
  • 3
7 Comments
 
LVL 18

Expert Comment

by:awawada
ID: 41792314
Do you have a backup of the Server?
0
 

Author Comment

by:David
ID: 41792317
we use Mozy to backup and even though the backup set for active directory has been selected i cant see that it would backup the sysvol folder?

The server is running fine. and there are only about 6 hardly used group policies
0
 

Author Comment

by:David
ID: 41792320
sorry also the windows file replication service- sysvol is selected
0
Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

 

Author Comment

by:David
ID: 41792511
i have restored a backup now, but was wondering if there was another way.
0
 
LVL 18

Accepted Solution

by:
awawada earned 2000 total points
ID: 41792529
No, for Crypto virus & Co there is no other way.
0
 
LVL 18

Expert Comment

by:Learnctx
ID: 41792953
How is it possible that someone had write access to Sysvol? Someone needs to seriously audit that environment. Even scarier is the thought someone is running around using an account in domain admins as their day to day account...

Unfortunately though, backup is the only way unless a decryption tool has been released by the security community. There are quite a few of these available where they have been able to reverse engineer the cryto malware and engineer a decryption tool. You just need to see if your variant had such a too. But to me if a DC had been compromised in such a fashion I would be building a new environment from scratch and moving everyone over to it. You have no idea how badly the environment has been compromised.
0
 
LVL 18

Expert Comment

by:awawada
ID: 41793161
Thanks for the points and check with your Antivirus vendor if the Domain Controller is now clean.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question