Identify Cryptolock encrypted files

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • DavidElkin
    New User
    • Aug 2015
    • 1

    Identify Cryptolock encrypted files

    Over the past year, we have had 3 different occurrences of staff getting infected with versions of CryptoLocker. We are in the process of removing mapped drives to our network servers to try to slow down this terrible malware. In most cases the computers were recognized as being infected and were taken offline before they were able to encrypt all drives the computer had access to.

    I have found that given a mountable restore point from our backup software, I can use Beyond Compare to identify files that are showing differences on both sides of the grid. The encrypted files will be different in size but have the same timestamps.

    Would there be a way, or can I recommend a feature to add these options to the comparison settings? It would be helpful to identify just those files that are the same date/time, but with a different size.

    Great product that I have been using for more than 15 years.

    Thanks
  • Aaron
    Team Scooter
    • Oct 2007
    • 15997

    #2
    Hello,

    Files that have an equal timestamp but different sizes get a specific "Different" status where both files are red. The default Display Filters: Show Differences includes Newer, Older, Different and Orphan, but you can switch to Toggles mode to show only Different.

    Right click the Display Filter buttons, and switch from Favorites to Toggles. Once in toggles, you'll see each status type as a button you can enable/disable. Disable all other buttons (Left Orphans, Equal, Right Newer, etc), but enable the two red squares Differences button to find files that are equal timestamps but different sizes.

    How does this work for you?
    Aaron P Scooter Software

    Comment

    Working...