Jlhoffman Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 26 October 2013

The CryptoLocker battle continues - part 2 - paying the ransom

Posted on 15:40 by Unknown
In my last post I talked about a client network that was devastated by CryptoLocker.  A local competitor had unsuccessfully tried to remove the malware before first determining whether the client had a good backup of their data. 

By the end of the first day, we had exhausted all possible sources of backup copies of their server and data files and it was obvious that their only option was to trust the hackers word that if we paid the ransom they would send the decryption key to restore the data.

The ransom can only be paid in one of two ways.  Send them 2 Bitcoins (value about $460) or use a Green Dot prepaid debit card to transfer $300 to them through the malware program itself.

First through, for the first time in our 25 year history, we actually had to re-install the malware that had been partially removed by the first company to pay the ransom.  Then we had to wrestle with the CryptoLocker payment screen to get it to accept the payment before finally getting the decryption process started.  The decryption program has been running for 2 days so far and has reported that it has restored over 75,000 files and failed on about 50. 

We can't tell whether the decyption is working fur sure because it's still running and it looks like it's going to run another day or so based upon a rough estimate of the number of files the client thinks are lost. 

So far, the client has lost 3 days of office and technical staff productivity. 

This was a hard lesson to learn and even if paying the ransom worked and the client gets back most of their data it's going to be an expensive one.  We've probably still got a day of work left cleaning up this mess across the network on the server and all of the other workstations and then installing a reliable data protection system.

Stay tuned, the program is still running.  Find out if the hackers were true to their word and if the data comes back after the ransom was paid.

Have similar concerns about the safety of your business data? 
Call ACT today @ (847) 639-7000 for a free consultation.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Ransomeware Now #1 MalwareThreat - Learn More Here
    I just read an outstanding white paper from a couple of researchers at Sophos Security outlining how Ransomware is passing up FakeAlert malw...
  • Computer Support Rates - When Cheap Really Isn't
    What's in a labor rate?  Why are some IT companies more expensive than others?  Our company is neither the most expensive in our market ...
  • Server Configuration - Heaven Save Us From Well-Meaning Amateurs!
    How do I tell the client what their old tech did to them?  They've got to spend a bunch of money to correct the mess he made and I'm...
  • When It's Time To Fire A Customer
    What?  Isn't that backwards?  Isn't it the customer that usually does the firing? Usually, as business people, we work so hard to fi...
  • Using Personal Computers In the Workplace
    At ACT, we support a great many organizations that allow employees to use their own computers at work.  Sadly, I've noticed that some of...
  • What to do with Windows XP
    Well, it had a good long run.  Windows XP is now 13 years old.  In less than 10 months Microsoft is pulling the plug on our old friend XP.  ...
  • Wireless Networking Is Due For A Big Jump In Performance
    Just when we were getting comfortable with the 802.11n wireless standard, here comes a newer and better wireless solution - 802.11ac.  It wi...
  • Documentation - The Key To Client Support Success
    Recently, we won the trust of a new client that was unhappy with the service provided by their previous IT company.  After the client notifi...
  • Going to the Cloud is easy, getting out is a lot tougher!
    Everyone is pushing you to take your business to the cloud, right?  It's easy, right?  The sales rep used all the right words in his pit...
  • Support for Windows XP and Office 2003 stops on April 8th.
    All Microsoft support for Windows XP and Office 2003 stops on April 8th. What are the risks to your business if you don't upgrade? Let...

Blog Archive

  • ▼  2013 (39)
    • ►  November (3)
    • ▼  October (4)
      • The CryptoLocker battle continues - part 2 - payin...
      • CryptoLocker Strikes Again With Disasterous Results
      • Support for Windows XP and Office 2003 stops on Ap...
      • Beware Hacker Watering Hole Exploits
    • ►  September (2)
    • ►  August (4)
    • ►  July (3)
    • ►  June (9)
    • ►  May (3)
    • ►  April (3)
    • ►  March (6)
    • ►  January (2)
  • ►  2012 (12)
    • ►  December (2)
    • ►  November (8)
    • ►  October (2)
Powered by Blogger.

About Me

Unknown
View my complete profile