@hobbit666 said in What Are You Doing Right Now:
@prcssupport said in What Are You Doing Right Now:
What security was on the affected workstation?
Pretty much zero hence it was shut down and replaced have a list of 15+ mchines so far that need replacing and then a further 30+ that need re-configuring/joining to the domain/AV/remote support tools etc.
Busy month or two for me as it's along side with getting new Citrix going moving 250 users to it and then Upgrading GP2010 to GP2015
I was just rereading your first post again and this last one.
The affected system was off... Yet was encrypting data on your server?
Or
Was the data written in the past while the offending system was on, and you just found it?
I just wondered I don't recall (In my limited memory or whatever else you wanna call it) a ransom-ware strain that infects a workstation and has the ability to "encrypt data on a network while (said workstation) is in an off state"
That would then indicate another system must be running the code, while purporting to be the "off workstation."
Just wondering, I know many things are possible.