I had a user with cryptolocker yesterday at 5pm. The user complained of not being able to open an excel file on the network. Turns out his laptop had crytpolocker and had started to lock files on mapped drives when we caught what was happening. We restored the files from backup to a new location. Setup a spare laptop with email for the user. Now I have to figure out how to remove it from the infected laptop.
↧
Cryptolocker Struck at 5pm ysterday
↧