We just isolated this on a workstation today, removed it from the domain, yanked the Ethernet cable, and reimaged the whole hard drive. The files were totally shot. The network guys traced it back to a file attachment that was saved out on an accounting drive on a local server, and cleaned it before anyone else could get infected. I did the initial triage, and gave the assist getting the PC scrubbed. What a mess. And this little booger actually changes the desktop wallpaper to insert the ransomware warning as the default background. That's a new one. Little maggots.