I had a client last week that got this. Encrypted their local docs as well as all the files on a shared drive. I was able to clean off the virus, but unable to un-encrypt the data. It was early in the morning and was able to do a shadow copy restore from server with essentially no data loss. Nasty little fucker...