South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Will a previous windows restore point not work?
wannacry deletes restore points as part of its process afaik
Not really.
It doesn't infect your documents, only encrypts them. So as soon as it activates you'll know, and before it activates your data backups are OK.
You may need to reinstall everything on a clean OS though.
A real bastard thing to do would be to encrypt stuff, and then on-the-fly decrypt it as it's opened for a few months - then stop doing that and request the ransom...
For most companies just the delayed encryption would be enough to screw them after watching how most small companies it guys operate
Why? last week's backup isn't enrypted, just infected. You can clean it.
Depending on the encryption time frame...
Say it waits 2 or 3 months from original infection date and regardless of the date of restore it automatically encrypts when you restore if you're over that time frame?
For smaller companies it could be devastating...
Hell I even know a few large companies that have pretty amateurish backup policies
wannacry deletes restore points as part of its process afaik
Your backup is still unencrypted though. The damage comes in when the encryption kicks in.
So you create a clean system, install patches and anti-malware, then just restore. No problem.
True... I'm just playing Sunday night stupid devils advocate in a retarded way....
I just know of a good few companies that backup full vm's rather than just the data for their file server backups
that could hurt a lot... If you don't get time to fix the infection on your restore before it triggers... eina
That's mostly my point... if the infection kicks off on a time point it will encrypt everything before the machine even boots for the first time completely
Boot in safe mode. Kill it. Boot normally. ... Profit?hmm, edit the system clock![]()