UNSOLVED

yannick88

updated

11 years ago

Y

yannick88

1 Message

0

1586

March 2nd, 2016 02:00

Locky Ransomware and VNX File System Checkpoints

Hey Guys,

is there any informationen if ransomware like locky also attacks the file system checkpoints (file snapshots) created by the VNX known as fileserver shadow copies aka "previous versions" in windows ?

regards

  • dynamox

    11 Legend

    20419 Posts

    87439 Points

    703

    0

    Posted March 2nd, 2016 04:00

    snapshots are read-only, it can't touch them.

  • umichklewis

    4 Apprentice

    1190 Posts

    703

    0

    Posted March 2nd, 2016 07:00

    Locky uses the Windows VSS service to delete snapshots.  The VNX doesn't use Windows VSS service to manage the snapshots, only it's internal CLI.  As dynamox said, they're read-only and they can't be deleted externally from the filesystem.