Serious computer ransomware alert - please read

Status
Not open for further replies.
PLEASE SHARE THIS WIDELY: Normally I would not post this sort of thing off-topic, so apologies to the moderators ahead of time, but this is particularly malicious, so I wanted to make sure you guys don't get hit with it. I work for a managed service provider and we received our first call on it today. Luckily not one of our regular clients. They've lost about 30GB of business data because of this.

Some of you may know already, but there is a recently emerged ransomware called "Cryptolocker", which once infected on a machine, ENCRYPTS ALL DATA ON ALL LOCAL AND MAPPED DRIVES with RSA 2048. There are also reports that it will affect online backups, such as DropBox.

Removing the malware is easy, but your drives will still be encrypted; and you won't guess the decrypt key even if you're the NSA. Bad juju!

See bleepingcomputer for details:

CryptoLocker Ransomware Information Guide and FAQ

See the section on how to prevent your computer from becoming infected.

Be careful out there!
 

ycatsce

Full Member
Verified Member
Apr 9, 2009
25
11
I recently had an old client call me up after moving to another IT firm whose prices were $50 a month cheaper than mine in order to "cut costs". They hadn't sent out word to their clients warning of this virus, and they had allowed his antivirus subscription to lapse. When he got infected, they found out that when they changed his shared folder structure to match theirs, they hadn't updated the backup schedules to reflect the changes, so a proper backup hadn't been made in about 9 months. Boy was he upset.

It took me almost 2 days to get their financial data and documents back and I was only able to get about 90% of it all recovered. Needless to say, I am now handling their IT work again.

This is a nasty one though. Thankfully, I have only dealt with it on 2 systems so far, only one of which was actually a client of mine at the time of the infection. At least the current client was as simple as wiping out the virus and restoring the files from the onsite backup.
 
  • Like
Reactions: VivaSan
Status
Not open for further replies.

Users who are viewing this thread