Jump to content

-!Rec0ver-xkoti++ Virus Corrupted Office/Media Files


Recommended Posts

Posted

Hi All,

 

Long term lurker her, one of my schools has been infected by the above virus all office files/picture/mp3 files are corrupted!

 

I can't find anything about this virus at all on Google which is strange to say the least!

 

Anyone had any experience of it?

 

Regards

 

Danny

Posted
Not corrupted, but encrypted. What do you need to know? It'll most likely be ransomware. Do they have backups? Have you isolated the source of the infection (PC and user)? Have you started taking steps to prevent a reoccurence?
Posted
Does anyone know how I can find the source pc/laptop of the virus I have looked at security details of the ransom files but the ownership is blank
Posted
Look at the "Owner" of one of the affected files. This will show the user's login that the virus ran from, then you just need to find out what computer they were logged in to and pull it from the network! Then I'd recommend implementing GPO application whitelisting, as the ransomware likes to run from a user's profile location. The whitelist will stop that from happening.
Posted
A full AV scan of all PCs and servers will be a good place to start - hopefully this will pick up the source of infection if your AV solution is any cop at all. I'm guessing that the damage is done on everything, but you need to make sure it can't recur too. That means finding the source, and possibly hanging the culprit who opened the infected Word doc/web page/scam link up by their ankles.
Posted
Had same here... had to go back to backup... lost some files. Sent data to Data recovery experts Ransomware Data Recovery - Services - Red Mosquito | Glasgow | Scotland | UK- no fix, no fee. Unfortunately they couldn't unlock the files but worth a try. Found the PC, user came and lots of windows open on screen with ransom notes. If you look in their MY Documents folder there will be a -!recover!-!file!.txt (public key) which the data company will need. Needless to say reimaged the PC and have taken steps with more backups etc. This virus will also kill shadow copies and any NAS robocopy, xcopy etc backups of same data. Good Luck.
Posted
You can find out also by looking in the Open Folders under shares on the server and you can see which user is opening folders on the server which are being encrypted. Doesnt help if its local to the machine but something we have notices if its network based. usually A user will have multiple folders open then when you refresh the screen its a different set of folders and so on.
Posted

I've found the individual laptop and restored everything from backup. I explained the virus to its owner and she has spoken to someone she knows in IT who says he can definitely get the data back?

 

Anyway we will see what happens.

 

Thanks for all the advice guys

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...