NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Bains's avatar
Bains
Guide
Nov 11, 2015
Solved

CryptoLocker and a backup strategy

I am requesting the community to evaluate and criticize this approach to CyberLocker   We are basically a Windows shop and we are scared to death about the CyperLocker virus.   From what I read, ...
  • Bains's avatar
    Bains
    Nov 13, 2015

    Let's summarize this thread.  I will open a new thread regarding the Netgear implementation/use of the rsync command.

     

    CryptoLocker and its variants are ‘in the wild’ and using an infected PC to encrypt most files as well as the file and directory names. The malware chases all local drives and any mapped drives as it encrypts the data. Once encrypted users are told to pay a ransom of between $700 and $70,000 dollars in bitcoins or never recover their data.

     

    Currently the only way to feasibly recover the data is either pay a ransom or restore the data from backup files. The backup files should be on a ReadyNAS share that does not have SMB access enabled so the malware cannot detect the data – it is not part of a mapped drive.

     

    The intention is to have backup of various Windows files and directories on a ReadyNAS that are the object of drive mapping in local PC network.

    • The backup share should be established without SMB protocol enabled. Turn SMB off in the Network Access tab in the file properties
    • The rsync protocol should be enabled and Read/Write access should be allowed. Use the Network Access tab in the file properties.

    Now there is a location for file backups that will not be discovered by CryptoLocker.

     

    The next step is to establish a backup job(s) to copy the ‘live’ mapped data to the essentially hidden data area.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More