today again some user got a Crypto-Virus by e-mail and started it. After rempaging around I stopped it, just to see, we don't have a Backup of this Server.
Now im pretty sure, that the data is lost but at least I have to try.
When the User logs on a small website display, with the same text as in the txt-file on the desktop.
Now some information:
Infected OS: Server 2012
Encrypted file Ending: [oldnames].vault
Found on the desktop: vault.key | 00088.key | vault1.txt
Object found by Kaspersky Virus Removal Tool:
- File: C:\Users\[Usrname]\AppData\Local\Micro…nternet Files\Content.IE5\1ZRKHGKL\pr.css
I'm sorry as english is not my native language and look forward for some help.