i really need help here.
yesterday at work, I tried opening my work computer but a message was shown before it got to load windows.
message was as following:
I asked the IT staff and found that all PCs and servers that were running on that night got the same thing.
we contacted the hacker and he wants BTC for the decryption code.
He gave us the password for one PC as proof.
after i enter the passcode, windows runs normally and no files are encrypted
when i looked into the PC after unlocking it. i noticed that Diskcryptor is used to encrypt the hard drive.
can anybody help me with recovering the data and removing this malware from the whole network?
Edited by wasimgad, 09 April 2017 - 12:40 PM.