- What is Ransomware?
They’re called Locky, Petya — you’ve certainly heard of them on tech websites or even in the news media. They are the latest “trendy” viruses: ransomware (literally “ransom software”)
The principle is simple: once your computer is infected, it locks up and a message appears asking you to send money (sometimes more than 20 000 euros) in order to keep using your computer and, above all, recover your precious data.
As long as you don’t pay this ransom, access to your machine remains completely blocked, your data is held hostage, and the virus’s author is the only person who can give it back to you.
- How to protect yourself?
The best way to avoid the virus is prevention. Equip yourself with good antivirus software and update it regularly. There are thousands of different ransomware variants, and new ones are created every day.
Email is the most common way ransomware spreads. Be careful if you receive emails from suspicious senders, and above all, never open the attachments.
Also make sure you only download files from sites you know and that have a good reputation. If your antivirus warns you, turn back — don’t take the risk, because once your hard drive is infected, it is IMPOSSIBLE to get rid of the ransomware without completely reformatting your computer. The files are encrypted using algorithms known only to their creators.
- My computer is infected, what should I do?
You’ve been infected by ransomware, whether by accident or simply bad luck! You can restart your computer endlessly, boot into safe mode, or remove the drive to connect it to another machine — the result will always be the same.
Here are the options available to you:
You can trust your “captor” and agree to pay the requested ransom (usually in dollars, euros, or bitcoins). The problem is that nothing guarantees the hacker’s good faith, so you risk paying for…nothing! Other hackers use a multi-step method, leading you to believe that all your data will be handed over once you pay the ransom. But once the transfer is made, they only hand over part of the data and ask for another payment for the rest…and this can escalate VERY quickly. That said, there are cases where all the data is returned after the ransom is paid. The choice to take this risk is yours, but remain extremely vigilant and don’t make a decision too hastily.
Recently, a hospital that fell victim to ransomware agreed to pay the ransom in bitcoins (a virtual currency in the form of tokens), except they never got their data back.
If you had the good sense to back up your data to the cloud, you can replace the drive and reinstall your data locally. If part of the data was stored on an old hard drive that was later formatted, a USB key, or another device, the Chronodisk lab can attempt to recover the data from that old storage device.
Finally, there are solutions developed by hackers and security experts to work around ransomware — because yes, hackers aren’t only harmful, and they’re often behind some of the best antivirus software. Some even create viruses so powerful and so widespread that they end up creating an antivirus for them, much like a chemist who creates a deadly poison alongside its antidote.
- Data recovery from a hard drive infected by ransomware
The Chronodisk lab receives an increasing number of hard drives infected by ransomware. We won’t hide it: it is very difficult to guarantee 100% data recovery for our clients in these very particular cases.
As there are several types of viruses, there are several types of ransomware. In many cases our data recovery specialists have succeeded in freeing this “hostage” data. But depending on the complexity of the ransomware it is sometimes simply impossible to recover even a single photo.
Once again, we recommend being as careful as possible with your emails and while browsing the internet — ransomware is just one danger among many…
