Switch the machine off and unplug your external drives. Every extra minute of activity extends the encryption.
Ransomware does not stop at the infected machine : it goes after everything within reach, including external drives that are plugged in, shared network folders and synced backup spaces. That is why isolating it comes before anything else.
The authorities advise against it unanimously, and for sound practical reasons : nothing guarantees you will be given a working key, a proportion of victims who pay recover nothing or only part of their files, paying marks you out as able to pay and exposes you to a second demand, and it directly funds the continuation of the activity.
Paying is not the only route either, whatever the message implies.
Several ransomware families have been dismantled, and their keys made public by the authorities and by security companies. Free decryption tools exist for a number of them. That is exactly what identifying the family is for - hence the importance of keeping the message and the file extension rather than wiping everything in a hurry.
A police report is possible and advisable : insurers often ask for one, and it feeds ongoing investigations. Keep the ransom message, the screenshots and one example of an encrypted file.
If the incident affects a business holding personal data about customers, a notification to the data protection authority may be compulsory within a short deadline. That point is worth checking quickly.
The machine will have to be reinstalled cleanly : cleaning up is not enough once an attacker has had that level of access. And the real lesson is about backups : a copy that is permanently plugged in gets encrypted along with everything else. You need at least one disconnected medium, or an online backup with version history. See recovering files and securing your computer.
We examine the machine, identify the ransomware family, attempt recovery by whatever routes are open, and hand back a clean system. See also data recovery.
No. It can remove the program responsible, but the encryption stays. Only a key, a known decryption tool for that family, or a backup will bring the data back.
Not necessarily. Syncing may have spread the encrypted files, but version history often lets you go back to a clean copy. That is the first avenue to explore.
Identification and the recovery attempt generally take one to several days. The clean reinstall comes on top of that. Much depends on whether a backup exists.
Would you rather we took care of it ? See our ransomware protection service, in Lyon and across the Rhone.
Do not switch off in a hurry without calling us : some of what is there is useful.
Automatic assistant: it can make mistakes. Never share a password or a card number.