Google is your friend...
Worked on my first one of these today, Googled first. Removal of the infection is easy... Saving customer data is another story.
Vista Business and Ultimate, and all versions of Win 7 have a feature called "Previous Version"... Found out thanks to Google that other versions of Vista also have it, and it is turned on by default, they just don't provide an interface for it. A freeware program called "Shadow Explorer" provides that interface. Using Shadow Explorer, I was able to grab three day old "Previous Versions" of all the customer's data.
Score one for the "Good Guys."
Rick
Worked on my first one of these today, Googled first. Removal of the infection is easy... Saving customer data is another story.
Vista Business and Ultimate, and all versions of Win 7 have a feature called "Previous Version"... Found out thanks to Google that other versions of Vista also have it, and it is turned on by default, they just don't provide an interface for it. A freeware program called "Shadow Explorer" provides that interface. Using Shadow Explorer, I was able to grab three day old "Previous Versions" of all the customer's data.
Score one for the "Good Guys."
Rick