Am I Infected? RANSOMWARE | Incident Response Symptoms
The symptoms
are as follows:
• You suddenly cannot open normal files and get errors such as the file is corrupted or has the wrong extension.
• An alarming message has been set
to
your desktop background with instructions on how to pay to unlock your files.
• The program warns you that there is a countdown until the ransom
increases or you will not
be
able to decrypt your files.
• A window has opened to a ransomware program
and you cannot close it.
• You see files in all directories with names such as HOW TO DECRYPT FILES.TXT or DECRYPT_INSTRUCTIONS.HTML.
Here is an example of a ransomware screen, the infamous
Crypto
Locker:
If Infected,
immediately take below action.
1. Disconnect:
·
Disconnect
the infected computer from any network
·
Turn
off any wireless capabilities such as Wi-Fi or Bluetooth.
·
Unplug
any storage devices such as USB or external hard drives.
·
Do
not erase anything or “clean up” any files or antivirus. (This is important for
later steps.
Simply unplug the computer from the network and any other
storage devices.)
2.
Determine the Scope:
Determine exactly how
much of your file infrastructure is compromised or encrypted.
Did the infected
machine have access to any of the following?
• Shared or unshared
drives or folders
• Network storage of any
kind
• External hard drives
• USB memory sticks with
valuable files
• Cloud-based storage (Drobox, Google Drive, Microsoft
OneDrive/SkyDrive etc…)
tools
available that have been specifically made to list out encrypted files
3.
Responses:
3
options, listed here from best to worst:
1. Restore from a recent backup
2. Decrypt your files using a 3rd party
decryptor (this is a very slim chance)
3. Format
the PC (lose your data)
RANSOMEWARE ATTACK
CHECKLIST
STEP 1: Disconnect Everything








STEP 3: Determine Ransomware Strain

STEP 4: Determine Response
Response 1: Restore Your Files From Backup

a. Ensure all files you need are there
b. Verify integrity of backups (i.e. media not reading or corrupted files)
c. Check for Shadow Copies if possible (may not be an option on newer ransomware)
d. Check for any previous versions of files that may be stored on cloud storage e.g. DropBox, Google Drive, OneDrive



16

Response 2: Try to Decrypt


If successful, continue steps...

sticks etc.)


Response 3: (Lose Files)


No comments:
Post a Comment