Monday 10 March 2014

Cryptolocker - The Bad guys are getting cleverer....






Story...

During the past couple months, ransomware known as CryptoLocker has made its presence known in homes and businesses around the world. So far, we have encountered it in over 10 local businesses located in the the North East. While ransomware is not a new concept, the pervasiveness of CryptoLocker, combined with its strong encryption, make it a particularly nefarious ongoing threat.

What is Cryptolocker?


CryptoLocker is Windows-based ransomware that encrypts files on local drives and network shares, and then demands payment to unlock them. Funds are requested via untraceable payment methods like Bitcoin and MoneyPak. CryptoLocker uses asymmetric encryption, with the private key held by the author or distributor of the malware. Unfortunately, it uses a strong algorithm that makes it practically impossible to decrypt the data without knowing the key.

CryptoLocker has, to date, been spread predominantly through email attachments and through other malware that has already infected PCs via other means. It has also been seen as a payload in drive-by downloads.

While CryptoLocker itself can be removed, the strong encryption prevents data encrypted by the malware from being unlocked.

  What Can I do to prevent it?

  • Be wary of any email attachments from sources you do not usually get emails from.  One popular method of trickery is the old 'DHL attachment' - BE WARY OF EVERYTHING
  • Secondly - Backup - Backup - Backup.  Its crucial to have an offsite backup of your mission critical data as although the Ransomware is relatively easy to remove, but the data is impossible to decrypt without paying the ransom.  If you have an offsite backup - you can easily remove the infection & restore.  


What happens if I get infected?

  • You can contact us on 042-9335355 & we will advise you of your options. Last thing you want to do is lose your data (or paying the baddies!)
Any queries, let us know on 042-9335355 / info@pcrepaircentre.com