• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

PSA: Nasty Trojan Virus (Ransom)

Status
Not open for further replies.
Our office got his yesterday by a derivative of the "Troj/Ransom-U" virus. We think it came through a legit-looking PDF from a legit sender. It began "encoding" our files, giving them the ".Encoded" file extension. The virus also puts a text file on the desktop, asking for a $120.00 USD ransom.

More information here.

If anyone has expertise on dealing with this one, I would be happy to entertain your comments.

Note: Did not post this in the Security forum because no one goes there. Sorry.
 
This reinforces the notion that you need to have good backups of your data. With no backups, you'd be up the creek, paying some crook money to restore your files and probably still not getting anything back.
 
Thanks for the info. I'll pass this on to our CA rep to be sure they can get a jump on it, since etrust seems to be the last to update their definitions.
 
This reinforces the notion that you need to have good backups of your data. With no backups, you'd be up the creek, paying some crook money to restore your files and probably still not getting anything back.

We do back-ups on a frequent basis but there is concern that the virus also interferes with Windows System Restore.
 
We do back-ups on a frequent basis but there is concern that the virus also interferes with Windows System Restore.
Thanks for the heads-up man. Yeah, any virus worth a crap will break system restore, right after it kills your antivirus and breaks regedit.
Good luck with your recovery.

Hey, did it spread like a worm on the LAN as well, or is it in just one computer?
 
I'm guessing it's international guys pulling this since I don't see how the FBI can't trace any money transaction.
 
Status
Not open for further replies.
Back
Top