SYSVOL file got Encrypted via Ransomeware attack

Rashid Kamal 21 Reputation points
2020-12-15T15:11:44.797+00:00

Dear Experts ,

We have faced ransomware attack recently , it encrypted files of Domain Controller 2012 SysVol Windows Server 2012 Standard working as Primary Domain Controller while two more additional domain controllers are there with GC enabled, what's the easiest way to recover the SysVol folders only ?

We have taken System State Backup of DC that's older after that many Policies have been made, 600+ users were created, if we go with recovery option, we have to create them all a very hectic job.

Please suggest and share the easiest way to recover only the SysVol from the backup, if there is any option available to reconstruct sysvol from the scratch, please suggest.

I always taken benefits from this community and expecting again from you.

Regards,
Kamal

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,457 questions
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2020-12-15T15:35:09.473+00:00

    Then you can restore the backup some where then use this one as a guide to replace contents.
    https://support.microsoft.com/en-us/help/315457/how-to-rebuild-the-sysvol-tree-and-its-content-in-a-domain

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

7 additional answers

Sort by: Most helpful
  1. Vicky Wang 2,731 Reputation points
    2020-12-16T09:17:18.307+00:00

    》》》If I restore system estate backup on any other location and copy the entire contents of SYSVOL as per mentioned detail, can i be able to restore all files ?

    According to my knowledge, it is possible.

    Hope this information can help you

    Best wishes
    Vicky

    0 comments No comments

  2. Rashid Kamal 21 Reputation points
    2020-12-18T18:43:06.22+00:00

    Dear DSPatrick & VickyWang-MFST,

    Thank you for your Support and and confidence, Let me write brief about what I have done to restore SYSVOL Files,

    1- First I stopped Domain Controller FRS Services and disabled it,
    2- Then I cleaned all encrypted files in windows\SYSVOL\sysvol folders,
    3- Once it was ensured that all encrypted files are cleaned, I copied data from backup to Sysvol.

    On Additional Domain Controllers, I repeat the same steps,

    (Performing a Nonauthoritative Restore of an FRS-Replicated SYSVOL Folder)

    1- First I stopped Domain Controller FRS Services and disabled it,
    2- Then I cleaned all encrypted files in windows\SYSVOL\sysvol folders,
    3- Configure the BurFlags registry key by setting the value of the following registry key to the DWORD value D2.

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtFrs\Parameters\Backup/Restore\Process at Startup\BurFlags

    4- Restart the FRS service on Primary Domain Controller, Additional Domain Controllers.

    5- When the FRS service is restarted, the following actions occur:

    The value of the BurFlags registry key is reset to zero.

    Files in the reinitialized FRS folders are moved to a pre-existing folder.

    The FRS database is rebuilt.

    Ref: https://video2.skills-academy.com/en-us/windows/win32/vss/backing-up-and-restoring-an-frs-replicated-sysvol-folder

    This has worked for me and made it simple for the whole community. :)

    0 comments No comments

  3. Anonymous
    2020-12-18T18:47:22.66+00:00

    Glad to hear of success.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.