Got a situation where were a computer was infected with ransomware which encrypted some shared drives. The infected computer itself was wiped by someone before I could determine the name of the file doing the encryption. The files encrypted retain their filenames but the extension is now ".f1crypt". ID Ransomware states its GlobeImposter 2.0, but after doing some research, I was unable to find any information regarding this particular extension type. Ideally, I would hope there's a decryptor but I am not holding my breathe. We have some cloud backups, but not all since some files were unable to be backed up due to it occurring before the backup kicked in. If anyone can provide any insight on this, I would greatly appreciate it.
Edited by skyhigh00, 01 September 2017 - 11:07 AM.