Quantcast
Viewing all articles
Browse latest Browse all 31638

Ransomware encrypted GPT.ini

In a Server 2003 setting, the gpt.ini file in our SYSVOL folder has been encrypted across all our DCs.   I have a backup of the "system state" on the DCs made using NTBackup and was going to just restore the GPT.ini file that had been corrupted but it appears NTBackup will only restore the entire system state at once.  I can try to redirect that restore to an alternative location but I'm not sure that will have the desire affect and instead the full system state will be restored, which I don't want since I know that group policy had not been changed since the last system state backup.   I could run the dcgpofix tool but we are also running Exchange server and I'm worried that resetting the GPO back to the default will cause problems there.  Any suggestions for recovering my domain and DC policy?   


Viewing all articles
Browse latest Browse all 31638

Trending Articles