Your home PC was infected with a STOP Ransomware variant using the
.udjvu extension.
Your work PC apparently was infected with a differect ransomware which appears to use a
random extension. More information is needed to determine specifically what infection you are dealing with since there are
several different ransomware infections which append a random 4, 5, 6, 7, 8, etc character extension to the end of all affected filenames (i.e. CTB-Locker, Crypt0L0cker, Magniber, GandCrab V5, CryptON (Cry9, Cry36, Cry128,
Nemesis), Skull, MrDec (Mr.Dec), SynAck, Maktub Locker, Alma Locker, Princess Locker, Princess Evolution, Locked-In, Mischa, Goldeneye, Al-Namrood 2.0, Cerber v4x/v5x and some Xorist variants).
The best way to identify the different ransomwares that use "random character extensions" is the
ransom note (including it's name), samples of the encrypted files, any obvious
extensions appended to the encrypted files, information related to any
email addresses or hyperlinks provided by the cyber-criminals to request payment and the
malware file responsible for the infection.
You can submit (upload) samples of encrypted files, ransom notes and any contact email addresses or hyperlinks provided by the cyber-criminals to
ID Ransomware (IDR) for
assistance with identification and confirmation of the infection. This is a service that helps identify what ransomware may have encrypted your files, whether it is decryptable and then attempts to direct you to an appropriate
support topic where you can seek further assistance.
Crypto malware (ransomware) and other forms of malware spread via a variety of common vectors...opening a malicious or
spam email attachment, executing a malcious file,
exploits, exploit kits, web exploits, malvertising campaigns, fileless malware, non-malware attack, drive-by downloads, social engineering, and RDP bruteforce attacks against servers particularly by those involved with the development and spread of ransomware.
Section 2 in this topic explains in more detail
the most common methods Crypto malware (file encrypting ransomware) is typically
delivered and spread.
The best defensive strategy to protect yourself from malware and ransomware (crypto malware) infection is a
comprehensive approach to include prevention. Make sure you are running an updated anti-virus and anti-malware product, update all vulnerable software, use supplemental security tools with
anti-exploitation features capable of stopping (preventing) infection before it can cause any damage, close/disable
Remote Desktop Protocol (RDP) if you do not need it and
routinely backup your data...then disconnect the external drive when the backup is completed. If you must use RDP, the best way to secure it is to either whitelist IP's on a firewall or not expose it to the Internet. Put RDP behind a firewall,
only allow RDP from local traffic, setup a VPN to the firewall, use an RDP gateway, change the default RDP port (TCP 3389) and
enforce strong password policies, especially on any admin accounts or those with RDP privileges.
.
For more suggestions to protect yourself from malware and ransomware (crypto malware) infection, see my comments (Post #14) in this
topic.