I was passed the following message in a text file from a small regional charity. It was on the start up screen when the computer was turned on.
were encrypted using strong RSA-1024 algorithm with a unique key.
To restore your files you have to pay 0.49965 BTC (bitcoins).
Please follow this manual:1. Create Bitcoin wallet here: https://blockchain.info/wallet/new2. Buy 0.49965 BTC with cash, using search here: https://localbitcoins.com/buy_bitcoins3. Send 0.49965 BTC to this Bitcoin address:1FkFRVWCvTyimcAAxq19dhYGspQ4KaeoabL4. Open one of the following links in your browser to download decryptor:
http://tt-metall.ru/counter/?a=1FkFRVWCvTyimcAAxq19tidShQ4KaeoabL
http://technocooks.com/counter/?a=1FkFRVWCvTyimcAAxqsHyiLppQ4KaeoabL
http://projectdare.co.uk/counter/?a=1FkFRVWCvTyimcAAxq19ssHppQ4KaeoabL
http://grutorax.com.br/counter/?a=1FkFRVWCvTyimcAAxq19mITppQ4KaeoabL
http://www.wordbaasoverdebal.nl/counter/?a=1FkFRVWCvTyimcAAxq13SDppQ4KaeoabL
5. Run decryptor to restore your files.
PLEASE REMEMBER:
– If you do not pay in 3 days YOU LOOSE ALL YOUR FILES.
– Nobody can help you except us.
– It`s useless to reinstall Windows, update antivirus software, etc.
– Your files can be decrypted only after you make payment.
– You can find this manual on your desktop (DECRYPT.txt)
(In the above example I have edited all of the links to make them void just in case anyone was curious to take a look and land in more trouble.)
Is it real what should I do?
First, tell your manager. It may represent a risk to the office and everything connected to the local area network.
There are recorded cases where a hacker has gained access to a network in a small business, generally through a remote access connection and have either encrypted everything they can reach, or deleted it. They have left a message on the screen to indicate that if the user wishes to recover their files then they have to pay a ransom. This is effectively what this message is indicating.
Unfortunately I am not close to this office so there is little I can do, however if you find yourself in this position there are some things you can do in terms of self help before calling in an expert.
Isolate the computer from other computers
In this case the computer is connected to a network with file sharing enabled and other computers can access the same information. We have to assume that this is real and that there may be a virus on the system and it may be encrypting files. So the first step is to remove this computer from the network by disconnecting it and isolating it from the rest of the computers in the office.
It may also be worth considering shutting down the other computers just in case the problem is coming from somewhere else, while the investigation is carried out. Also disconnecting your router from the Internet in case someone is accessing your systems remotely, which it the highest threat when this happens.
Run a good quality* Anti Virus Check
Next run your anti virus software on the computer to establish the likelyhood of anything running on it. It is most likely a scam and not real, but we cannot be sure. So taking some precautions are wise steps.
*I state good quality because there are so many charitable organisations I work with that have only free Anti Virus running on their systems. These do not offer robust protection. I recommend using one of the leading brands such as Eset, Symantec or McAfee, there are others out there of course, and in most cases as a charity you can get up to 50% discount on AV software. But the bottom line is if it is free, why should the developer spend any time on developing a robust solution to protect you if you are unwilling to pay for it. You generally do not get something for nothing.
If your AV check does not return any results then you are probably safe, and this is a simple scam to terrorise your office. Regrettably something that is very real these days.
How did it get there?
Next you need to ask the question; how did it get there? If your system is locked down with a good quality AV product and security protection enabled, nothing should be installed on your computer without your express knowledge.
You may need to call in an expert to remove it and independently check your systems at this stage. Things you can check are as follows:
Browser plugins; Can you locate them, should they all be there, and if not, remove what you do not recognise, or simply disable it until you are sure it should be there. Many things can be introduced by accident through the browser if you are not paying attention.
MSConfig; If you have a Start Menu item called “Run” then you can open a command prompt and enter “msconfig” on a Windows machine. This will allow you to check what files are loaded when the system starts. If a message is popping up on your screen it is most likely coming from a file loaded when the computer is turned on. If you are not familiar with this area, take a look around, and see what is there. Anything suspicious, look it up first (use google) before disabling it. You can always re-enable it later.
IT Partners; If you have an external IT partner, then they may use a remote login to access your computer system because it is cheaper than sending someone around to your location. Some IT partners provide free services to charities. However that should not mean that you should accept anything less than an equivalent paid service. Your security is still your responsibility. A breach at your IT partner should not spell a disaster for you.
Ask your IT partner if it is possible to independently access and take over any computer in your office from a remote location. (You might be surprised!) If there are ports open on the firewall into your organisation and ports open on computers listening for remote access requests you should know how to turn them off. There are several examples of breaches into organisations and encrypting systems using this method of a hacked or compromised remote access login. Lock it down and render it unusable until you need to use it and then enable it.
Get the experts in
If you have any doubts about messages like this when they appear, call in an expert to get their opinion. Do not ignore it, it may be a case of a virus with a bug in it that has crashed, and not completed the process for some reason. You need to locate what it is and remove it, don’t tolerate it.
Don’t panic
If you see examples of computers behaving oddly, crashing, reporting files cannot be accessed, then this might be real. While there are ways to cripple a computer at the disk level quite quickly, to encrypt a disk takes time. It also means your computer needs to be switched on to encrypt files, or a remote computer with read/ write access to your files is switched on and performing the task.
If the world is crashing down around you; you can temporarily halt the process by turning the computers off. They may recommence when they are turned on, however if you bring in IT consultants at this stage, they may be able to take some action to recover some of your system. If you leave it on, and the process is encrypting your system then nothing will be recoverable without locating the people that initiated it.