In-depth

If you've been hit by ransomware do this first

When Wannacry hit NHS computers (as well as many other organisations around the world) a few weeks ago, it showed us just how bad the threat of ransomware is.

According to a white paper published by Kaspersky (titled The Ransomware Revolution), in 2016 attacks on business increased three-fold between January and the end of September: the difference between an attack every two minutes and one every 40 seconds. Ransomware has also become more sophisticated and diverse.

If you have become a victim of ransomware, here is what you should do first.

Remove the computer from the network

Advertisement
Advertisement - Article continues below

If the computer is part of a network, remove it from the network either by pulling out the Ethernet cable, or switching off wireless functionality (if you have a physical wireless switch).

Don't pay the ransom

If your PC has been hit by ransomware, do not pay the ransomware, there is very little evidence that hackers will decrypt your computer once the ransom has been paid. According to Kaspersky (download whitepaper here) TeslaCrypt was shut down when the master key to decrypt files was released, apparently by the malware actors themselves. Around 3,500 keys for the Chimera ransomware were release in July 2016 by someone claiming to be behind the Petya/Mischa ransomware.

Another thing to consider here is that if you give a hacker credit card data, they will most likely use this information to commit further fraud. If they do provide an unlock file, this may well infect your PC with further malware.

If you are an individual user, it would be worth contacting someone who is an IT expert to help. If you are business, contact the police to provide as much evidence as possible.

Restore from a backup

If you have kept backups of data, it would be a good time to dig out the last good backup and restore from this. This will not retrieve all your data but will keep data to as much of a minimum as possible. Also, make sure you have external backup; any system restore images on the same drive may well also be locked up by criminals.

Format and reinstall your operating system before you restore your backups from a clean source.

Boot into safe mode to disinfect

When you have restored your computer, always boot into safe mode and run a deep scan with antivirus product, other malware may still reside on your hardware.

Advertisement
Advertisement - Article continues below

If the ransomware has blocked access to your PC, you can use Kaspersky WindowsUnlocker, run from a USB key to clean up a ransomware infected registry and gain access back.

Unlocking the files

Luckily for some victims (and unlucky for criminals), some encryption keys use in ransomware can be cracked. Many IT security firms have had success in finding the keys for locked files. It may be a good idea to look at the websites of legitimate IT security companies to see if any decryption software exists for the strain of ransomware on your PC.

Precautions

Prevention is better than cure, the adage says, so there are a few provisions you can take to ensure you never become a victim of ransomware. 

  • Always keep a backup off-site. If you have cloud storage, use this as well.

  • Don't enable macros in documents attached in emails.

  • Use a Microsoft Viewer instead of opening a document in the full application.

  • Never open an unsolicited attachment.

  • Log in as a guest rather than an administrator.

  • Always update software.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/business/business-strategy/354195/where-modernisation-and-sustainability-meet-a-tale-of-two
Sponsored

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019