In-depth

If you've been hit by ransomware do this first

Red skull and crossbones atop binary code

When Wannacry hit NHS computers (as well as many other organisations around the world) a few weeks ago, it showed us just how bad the threat of ransomware is.

According to a white paper published by Kaspersky (titled The Ransomware Revolution), in 2016 attacks on business increased three-fold between January and the end of September: the difference between an attack every two minutes and one every 40 seconds. Ransomware has also become more sophisticated and diverse.

If you have become a victim of ransomware, here is what you should do first.

Remove the computer from the network

If the computer is part of a network, remove it from the network either by pulling out the Ethernet cable, or switching off wireless functionality (if you have a physical wireless switch).

Don't pay the ransom

If your PC has been hit by ransomware, do not pay the ransomware, there is very little evidence that hackers will decrypt your computer once the ransom has been paid. According to Kaspersky (download whitepaper here) TeslaCrypt was shut down when the master key to decrypt files was released, apparently by the malware actors themselves. Around 3,500 keys for the Chimera ransomware were release in July 2016 by someone claiming to be behind the Petya/Mischa ransomware.

Another thing to consider here is that if you give a hacker credit card data, they will most likely use this information to commit further fraud. If they do provide an unlock file, this may well infect your PC with further malware.

If you are an individual user, it would be worth contacting someone who is an IT expert to help. If you are business, contact the police to provide as much evidence as possible.

Restore from a backup

If you have kept backups of data, it would be a good time to dig out the last good backup and restore from this. This will not retrieve all your data but will keep data to as much of a minimum as possible. Also, make sure you have external backup; any system restore images on the same drive may well also be locked up by criminals.

Format and reinstall your operating system before you restore your backups from a clean source.

Boot into safe mode to disinfect

When you have restored your computer, always boot into safe mode and run a deep scan with antivirus product, other malware may still reside on your hardware.

If the ransomware has blocked access to your PC, you can use Kaspersky WindowsUnlocker, run from a USB key to clean up a ransomware infected registry and gain access back.

Unlocking the files

Luckily for some victims (and unlucky for criminals), some encryption keys use in ransomware can be cracked. Many IT security firms have had success in finding the keys for locked files. It may be a good idea to look at the websites of legitimate IT security companies to see if any decryption software exists for the strain of ransomware on your PC.

Precautions

Prevention is better than cure, the adage says, so there are a few provisions you can take to ensure you never become a victim of ransomware. 

  • Always keep a backup off-site. If you have cloud storage, use this as well.

  • Don't enable macros in documents attached in emails.

  • Use a Microsoft Viewer instead of opening a document in the full application.

  • Never open an unsolicited attachment.

  • Log in as a guest rather than an administrator.

  • Always update software.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

Hackers publish over 4,000 files stolen from SEPA in ransomware attack
Security

Hackers publish over 4,000 files stolen from SEPA in ransomware attack

22 Jan 2021
Weekly threat roundup: SAP, Windows 10, Chrome
vulnerability

Weekly threat roundup: SAP, Windows 10, Chrome

21 Jan 2021
Biden nominees highlight tough cyber security challenges
cyber security

Biden nominees highlight tough cyber security challenges

20 Jan 2021
Report: Security staff excluded from app development
cyber security

Report: Security staff excluded from app development

20 Jan 2021

Most Popular

SolarWinds hackers hit Malwarebytes through Microsoft exploit
hacking

SolarWinds hackers hit Malwarebytes through Microsoft exploit

20 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021
What is a 502 bad gateway and how do you fix it?
web hosting

What is a 502 bad gateway and how do you fix it?

12 Jan 2021