Sparta6 Posted April 20, 2016 Posted April 20, 2016 Hi All, Long term lurker her, one of my schools has been infected by the above virus all office files/picture/mp3 files are corrupted! I can't find anything about this virus at all on Google which is strange to say the least! Anyone had any experience of it? Regards Danny
3s-gtech Posted April 20, 2016 Posted April 20, 2016 Not corrupted, but encrypted. What do you need to know? It'll most likely be ransomware. Do they have backups? Have you isolated the source of the infection (PC and user)? Have you started taking steps to prevent a reoccurence?
Dos_Box Posted April 20, 2016 Posted April 20, 2016 Hi, what AV were you using that identifed it as this? Is there any text file with a message left behind?
pantscat Posted April 20, 2016 Posted April 20, 2016 Disconnect the affected PC(s) from the network - re-image it. Restore files from backup...
Sparta6 Posted April 20, 2016 Author Posted April 20, 2016 Does anyone know how I can find the source pc/laptop of the virus I have looked at security details of the ransom files but the ownership is blank
mcoyne Posted April 20, 2016 Posted April 20, 2016 Look at the "Owner" of one of the affected files. This will show the user's login that the virus ran from, then you just need to find out what computer they were logged in to and pull it from the network! Then I'd recommend implementing GPO application whitelisting, as the ransomware likes to run from a user's profile location. The whitelist will stop that from happening.
DrPerceptron Posted April 20, 2016 Posted April 20, 2016 If the ownership bit is blank, not really sure... If you use impero, it should appear in the applications used logs under */c DEL*
3s-gtech Posted April 20, 2016 Posted April 20, 2016 A full AV scan of all PCs and servers will be a good place to start - hopefully this will pick up the source of infection if your AV solution is any cop at all. I'm guessing that the damage is done on everything, but you need to make sure it can't recur too. That means finding the source, and possibly hanging the culprit who opened the infected Word doc/web page/scam link up by their ankles.
seanmh Posted April 20, 2016 Posted April 20, 2016 Had same here... had to go back to backup... lost some files. Sent data to Data recovery experts Ransomware Data Recovery - Services - Red Mosquito | Glasgow | Scotland | UK- no fix, no fee. Unfortunately they couldn't unlock the files but worth a try. Found the PC, user came and lots of windows open on screen with ransom notes. If you look in their MY Documents folder there will be a -!recover!-!file!.txt (public key) which the data company will need. Needless to say reimaged the PC and have taken steps with more backups etc. This virus will also kill shadow copies and any NAS robocopy, xcopy etc backups of same data. Good Luck.
cpjitservices Posted April 21, 2016 Posted April 21, 2016 You can find out also by looking in the Open Folders under shares on the server and you can see which user is opening folders on the server which are being encrypted. Doesnt help if its local to the machine but something we have notices if its network based. usually A user will have multiple folders open then when you refresh the screen its a different set of folders and so on.
Sparta6 Posted April 21, 2016 Author Posted April 21, 2016 I've found the individual laptop and restored everything from backup. I explained the virus to its owner and she has spoken to someone she knows in IT who says he can definitely get the data back? Anyway we will see what happens. Thanks for all the advice guys
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now