03/22/2016
We encountered a particularly nasty Ransom ware infection today. The files end in .locky.
Please, never open file attachments from unknown or un trusted sources.
In this case the user opened an attached Word file, it displayed gibberish and asked to 'enable macro's.' The user enabled macro's and it was done.
The malware then disabled the backup services, deleted the backup files then encrypted all the documents on the boot drive.
It then removed itself from the drive and erased all information that could trace it.
It then asks for a 'ransom' to be paid by bitcoin.
Fortunately good procedure affords this client the option to restore most lost files and avoid the ransom...except what they are paying for us to fix this.