Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Posted: 1/22/2015 8:20:09 PM EDT
Got hit with the Cryptowall Virus today at work. Encrypted all of our PDF, XLS, and DOC files on our file server. Been working on fixing for 6 hours, Still trying to clean up this mess. Anyone have any ideas on fixing this problem without utilizing backups?
Link Posted: 1/22/2015 8:58:19 PM EDT
[#1]
You don't have too many options, either restore from backups or pay the ransom.
Link Posted: 1/23/2015 1:30:41 AM EDT
[#2]
fixed 2.0 ,
havent seen 3.0
Link Posted: 1/23/2015 9:32:10 AM EDT
[#3]
Backups, backups, storage level snapshots with lots of room for changes.
Link Posted: 1/23/2015 12:14:06 PM EDT
[#4]
Quoted:
Got hit with the Cryptowall Virus today at work. Encrypted all of our PDF, XLS, and DOC files on our file server. Been working on fixing for 6 hours, Still trying to clean up this mess. Anyone have any ideas on fixing this problem without utilizing backups?
View Quote


I haven't followed the 3rd version of it, so I can't say for certain, but if you don't have backups, this will likely be a... life lesson for you.

If you can't afford to have backups, you can't afford to have data.   And if your backups aren't easily usable, they aren't much good.
Link Posted: 1/23/2015 9:22:04 PM EDT
[#5]
Hope you have backups son, otherwise you're starting from scratch.
Link Posted: 1/23/2015 9:58:44 PM EDT
[#6]

Discussion ForumsJump to Quoted PostQuote History
Quoted:


Hope you have backups son, otherwise you're starting from scratch.
View Quote
One of our users opened a Link that invited a similar scourge onto my network. Crypto locker maybe...some crazy 1024 bit encryption...backups are a life saver. You must kill the bug...then restore from backups. It's the only way.

 
Link Posted: 1/23/2015 10:36:23 PM EDT
[#7]
OP, I will sell you managed offsite backup right now.
Link Posted: 1/23/2015 10:45:16 PM EDT
[#8]
Thanks for reminding me... I needed to back-up my files.
Link Posted: 1/24/2015 3:22:34 AM EDT
[#9]
Will this encrypt files on mapped drives from a NAS?  If that NAS isn't running a Windows filesystem?
Link Posted: 1/24/2015 3:35:10 AM EDT
[#10]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Will this encrypt files on mapped drives from a NAS?  If that NAS isn't running a Windows filesystem?
View Quote


Yes
Link Posted: 1/24/2015 4:49:21 AM EDT
[#11]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


Yes
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Will this encrypt files on mapped drives from a NAS?  If that NAS isn't running a Windows filesystem?


Yes




Well my word, I guess I need to get up to speed on this.  I have an unraid server and a dozen drives mapped to my PC, and more alarmingly, my kid's PC, and I had no idea it could encrypt a drive on a linux system.
Link Posted: 1/24/2015 5:09:24 AM EDT
[#12]
Discussion ForumsJump to Quoted PostQuote History
Quoted:




Well my word, I guess I need to get up to speed on this.  I have an unraid server and a dozen drives mapped to my PC, and more alarmingly, my kid's PC, and I had no idea it could encrypt a drive on a linux system.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:
Will this encrypt files on mapped drives from a NAS?  If that NAS isn't running a Windows filesystem?


Yes




Well my word, I guess I need to get up to speed on this.  I have an unraid server and a dozen drives mapped to my PC, and more alarmingly, my kid's PC, and I had no idea it could encrypt a drive on a linux system.


It acts on the files that the infected OS has access to, doesn't matter on what or where they are.  If it can get read/write access, it will encrypt them.  NAS box, File Server, your flash drive, your external, doesn't matter.  Some will even seek out local backups and delete Volume Shadow Copies and encrypt those as well.
Link Posted: 1/25/2015 3:11:05 AM EDT
[#13]
Luckily,  we backup the server everynight, isolated the infected computer. Going to nuke it and put on some Internet restrictions on the domain. Just sucks that because of one domain user that had read write access on our mapped document drive is causing me 2 day's worth of work.
Link Posted: 1/25/2015 3:26:37 PM EDT
[#14]
We have changed our snapshot policies and backups for this reason. We now have dedicated 50 % volume space for snapshot reserve. Makes it easy to restore if file are messed with on a large scale. We keep 3 weeks in snapshot history for all network files.
 



We also take daily backups to a offsite repository.
Link Posted: 1/25/2015 3:29:51 PM EDT
[#15]
bleeping computer.com are your friends
Link Posted: 1/25/2015 3:42:56 PM EDT
[#16]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
We have changed our snapshot policies and backups for this reason. We now have dedicated 50 % volume space for snapshot reserve. Makes it easy to restore if file are messed with on a large scale. We keep 3 weeks in snapshot history for all network files.  

We also take daily backups to a offsite repository.
View Quote


I'm assuming you're not talking about VSS snapshots and are referring to storage level snapshots
Link Posted: 1/25/2015 4:04:07 PM EDT
[#17]

Discussion ForumsJump to Quoted PostQuote History
Quoted:
I'm assuming you're not talking about VSS snapshots and are referring to storage level snapshots
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:



Quoted:

We have changed our snapshot policies and backups for this reason. We now have dedicated 50 % volume space for snapshot reserve. Makes it easy to restore if file are messed with on a large scale. We keep 3 weeks in snapshot history for all network files.  



We also take daily backups to a offsite repository.





I'm assuming you're not talking about VSS snapshots and are referring to storage level snapshots
Storage Level

 
Link Posted: 1/25/2015 5:40:18 PM EDT
[#18]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Storage Level  
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:
We have changed our snapshot policies and backups for this reason. We now have dedicated 50 % volume space for snapshot reserve. Makes it easy to restore if file are messed with on a large scale. We keep 3 weeks in snapshot history for all network files.  

We also take daily backups to a offsite repository.


I'm assuming you're not talking about VSS snapshots and are referring to storage level snapshots
Storage Level  


Good, it deletes VSS snapshots.
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top