Cryptolocker Ransomware – IMPORTANT UPDATE
Posted: Wednesday, March 12, 2014
We have seen a new variant of the Cryptolocker virus over the past week that has rendered 100s of our customers files useless. The helpdesk has been dealing with a very large volume of calls in relation to this and have spent hours to date restoring files and clearing infections.
David Alleeson, Head of Support Services here at Utilize, has confirmed that early diagnosis and action is key and damage to networks can be limited by completing the following steps upon discovering infection:
- Ensure staff are being vigilant when opening emails and attachments from an unknown source
- Unplugging the network lead from the PC where an infection was noticed
- Unplugging the network lead from the Server once staff have saved all work (only do this if you are confident in doing so)
- Call Utilize to notify us of the infection so a qualified engineer can begin diagnosis and decryption / restoration from backup
Source
The source of these infections are generally from email and often appear as “double-extension” attachments or other filenames in emails that appear to be legitimate. Customers who have Ignite Email Filtering Service (IEFS) are already largely protected against this new threat as we have turned on dual engine scanning and created rules to prevent the emails we have seen pass through to date. Monitoring these trends allows us to make centralised changes to IEFS and will allow us to be pro-active protecting client networks. Customers without IEFS or on premise based email security may be exposed unless rules are tweaked which won’t happen automatically. This new variant isn’t being detected by major AV vendors as yet so isn’t being picked up even on a manual endpoint scan. Having anti-virus doesn’t mean you are protected!
Backups
What is critical to our clients is a full backup. Customers who do not have a backup working risk losing data when encryption occurs, as we usually have to restore files from the last successful backup or volume shadow copy.
Any questions please speak with Utilize service or your account manager.











