I apologize if this is the wrong forum for this. One of our users got infected with some ransomware. We run Endpoint and it did not detect it, the quarantine is empty. Files on the local hard drive started getting encrypted in the .crypz format. The user also had several network shares where files started getting encrypted. We isolated the PC from the network and restored backups on our file server. I opened a case with support and they installed Hitman Pro on the file server and started a scan. Support tech instructed me to submit whatever the Hitman pro scanner finds as a sample, then he hung up. The scan came up clean so I had nothing to submit. I attempted to call back, but after 30+ minutes on hold, someone picked up the phone and hung right up. It was near the end of the day so I decided to not wait around again.
So far I have ran the following on the user's PC:
- Hitman Pro
- Sophos Endpoint full system scan
- Sophos Clean
- Malwarebytes
All scans from these programs came up clean - no detected threats.
I updated the case online asking support to log in and take a look at the infected PC. The last response I received from Support was 4 business days ago. I don't have any samples to submit because nothing I run will detect the malware. I assume that Sophos could have someone do a screen sharing session on it and try to detect the ransomware. What steps can I take from here? Should I try some other AV software to see if I can detect something?
This thread was automatically locked due to age.