Ransomware: what it looks like and what to do

Ransomware: what it looks like and what to do

Ransomware is software that locks up your files and then asks for money to unlock them. Businesses of every size get hit, and getting hit is not evidence that anyone was careless. What separates a bad week from a very bad month is what happens in the first hour and whether the backups are sound.

What it looks like

It rarely announces itself politely. The usual signs are:

  • Files you use every day will not open, and Word or Excel says the file is corrupt or in an unknown format.
  • File names have changed, often with an extra ending added to every one of them.
  • A text file or a full-screen message appears in your folders with instructions for paying to get the files back.
  • The shared drive is affected as well as your own computer, which is often how a whole office notices at once.
  • The computer becomes very slow or the fan runs hard while the files are being encrypted.

Very often the first symptom is much duller: two or three people mention they cannot open something, minutes apart.

Try this first

  1. Disconnect the affected computer from the network. Unplug the network cable, or turn wi-fi off from the icon near the clock. This is the single most useful thing anyone can do, because ransomware spreads across shared folders while it works. Disconnecting stops it reaching files it has not touched yet.
  2. Do not turn the computer off and do not restart it. Some useful evidence, and occasionally recovery information, only exists while the machine is running. Leave it on and disconnected.
  3. Call us on 03 9028 4358. Say the word ransomware. Do not email, because if the attacker also has a mailbox they will see it, and because this needs a person immediately rather than a queue.
  4. Tell everyone else to stop using shared drives and to leave their computers alone, without shutting them down. If one machine is affected, others may be, and normal work can spread the damage.
  5. Do not delete anything, including the ransom note. It tells us which ransomware family this is, and for some families a free decryption tool already exists.

Do not pay

Not as a moral point, as a practical one. Paying is a purchase from a criminal with no obligation to deliver, decryption tools that are provided are frequently slow or incomplete, and paying marks the business as one that pays. There may also be legal considerations around making the payment. If money is being discussed at all, that is a conversation for you, your insurer and your lawyer, not something to decide in the first hour.

Focus the first hour on containment and on establishing what backups exist.

How recovery actually goes

Once we are involved, the shape is usually: work out which machines and which shares are affected, isolate them, confirm the backups are intact and were not reachable from the infected computer, then rebuild affected machines from clean images and restore data from the last good backup.

The honest part is that this takes time, and the amount of time depends almost entirely on the backups. A business with recent, tested, offsite backups is inconvenienced. A business whose only backup was a drive plugged into the affected server has a much harder road. We will tell you which situation you are in early rather than let you find out slowly.

We will also help you work out what has to be reported and to whom. If personal information may have been accessed, there are obligations under Australian privacy law, and there is a separate article in this knowledge base covering that in plain English.

How to reduce the risk beforehand

  • Backups that are separate from the network, and that someone has actually restored from as a test. An untested backup is a hope, not a backup.
  • Multi-factor authentication everywhere. That is the code or approval on your phone. Most incidents start with a stolen password.
  • Updates applied promptly to Windows, macOS and the applications on them.
  • Staff who feel safe reporting a click. The gap between the click and the phone call is usually the difference between one machine and the whole office.

If you are not sure where your business stands on any of those, ask us and we will tell you plainly.

Still stuck?

Log a ticket at portal.yougrowit.com.au or email support@yougrowit.com.au. If it is stopping you working right now, call 03 9028 4358.

Support hours are Monday to Friday, 8:30am to 5:30pm Melbourne time, excluding Victorian public holidays.

    • Related Articles

    • You think you have been phished: what to do in the first ten minutes

      You clicked a link, typed your password into a page that looked right, and something feels off. Maybe the page reloaded and asked again. Maybe a colleague replied to an email you never sent. This one catches everyone, including people who are good ...
    • Invoice fraud and payment redirection: the scam that costs the most

      Of everything that goes wrong with email, this is the one that takes real money out of a small business, and often tens of thousands of dollars at once. It is not a virus and it is not clever software. It is an ordinary email that asks you to pay the ...
    • How to spot a phishing email

      Phishing is an email designed to get you to do one of three things: type your password into a fake page, open an attachment, or pay someone. The good ones do not look like scams. They look like a Microsoft notice, a delivery slip, a signature ...
    • Using your own phone or laptop for work, safely

      Most small businesses run on personal devices to some extent. Someone checks email on their own phone, a director works from a home laptop, a part-timer uses their own machine two days a week. That is normal and it can be done safely. The risk is not ...
    • Why we send you security alerts, and which ones matter

      If we look after your systems, you will get emails from us about security. Some ask you to do something, most do not, and after a while it is easy to stop reading them. That is the outcome we most want to avoid, so here is exactly what we send and ...