Anyway to beat ransomware?

ChocolateBadger

Expert Member
Joined
Mar 16, 2009
Messages
3,826
Reaction score
8
Location
Vaalie Boet
So a friend just sent me a message in a panic because their entire pc has been encrypted and are faced with a screen demanding bit coin. Anyway around or just pay the ransom?
 
Some of the keys have been released by the creators but it depends on many things.
 
If any of these exist there is a % chance:

Image backups of data: 100%
File version history backups: 80%
Shadow volume copies: 30%
Restore Points:10%
(If there are backups on an external drive, hopefully it wasn't connected when the encryption began.) Cloud backups would be unaffected.


Paying the ransom doesn't guarantee the data being restored.

The existing keys released are about 2 months behind and don't decrypt new instances. If your friend didn't do backups yesterday, they just screwed period. If they did backups a month ago they will lose all the data for the last month.

Removing the malware also destroys any chance of decryption if the private keys are released later.

Anyone that tells you they can fix it is trying to con you again. Only the authors of that Ransomware can decrypt your data. It cannot be cracked.

This is a total screw up without having the backups as I've stated before.

All my clients are doing daily image backups. It's the only real insurance against ransomware.

Btw. If their pc is on a network, unplug immediately. Some Ransomware variants spread over the internal network.
 
//echo

look for shadow or ghost copies. safe to a drive.

then format/zero fill the old drive and reload.
 
All my clients are doing daily image backups. It's the only real insurance against ransomware.

Is this possible in a home-office type of environment where eg. XP is still the flavour of the month?

At the very least have two (or three) portable HDD's and dump your data to these at the end of each day/week. First HDD = mondays, second HDD=wednesdays and third HDD=fridays.
And a fourth HDD for a monthly backup.

This is a sysadmin's purest nightmare.
 
Prevention is better than a cure.

Tell you friend to lay off the dodgy porn sites :D
 
Good point actually, I know very little about this... Where does it come from and what can you do to protect yourself?

We received both our infections from emails and staff opening them without thinking first.
Had to up some security features, firewalls, cryptoprevent, superantispyware, hosts file etc.

www.bleepingcomputer.com decent place to start looking
 
Good point actually, I know very little about this... Where does it come from and what can you do to protect yourself?

Don't open dodgy attachments.

Don't download executables from untrustworthy sources.

Don't click on dodgy looking links.
 
Top
Sign up to the MyBroadband newsletter
X