Restarted my Windows Server the other day, to discover my files locked and a message on my desktop about how they want 1 Bitcoin (~ 590 AUD) to unlock it. I don't use Anti-Virus, because I'm very careful, and haven't had any viruses in my 3 years of doing it. That changes this year.
Lost about 2TB / 8TB of my data, as it only hit one drive, and the boot SSD.
Noticed my friends were asking a tonne of questions, so curious, anyone want to ask anything about it? Just shoot.
did it changed your default homepage or left a notepad file on your desktop? In that should able to tell what ransomware it is.
One of my clients got hit with cryptolocker last year and only way to restore their files was from 4 weeks old backup and shadow copy. Shadow copy doesn't work on XP or before Server 2008.