Not sure what went wrong.
Workstation on network had a correctly identified threat during an unattended scan at the end of a business day.
Next morning staff logged into the computer and locky successfully implimented payload across the network to all shares available to that account. Due to a good backup procedure disruption was minimal but I'm now concerned that web root failed to prevent the payload from being executed at the next log in.
Suggestions ?
W32.Ransomware.locky
Login to the community
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.