Dapi Editor: Blog

Back to Dapi Editor's Blog
February 18, 2015
Posted at 10:08 pm
 

Ransomware

As you've read one of our writers has had his computer hijacked. The hijackers' MO is to extort money-usually between US$500-$1,000 for the possibility of getting your files back in one piece.

Just so you know this is usually not a one time payment, they hit you up for the initial funds and then want a smaller payment on a regular basis or they will shut down your machine.
The following website has some useful information regarding this http://deletemalware.blogspot.jp/2014/10/how-to-remove-cryptowall-20-virus-and.html

Ok, my take on this issue is, if you really need the files and don't want to take a chance on their being damaged or corrupted then pay the money and hope that the hijackers will follow through and return your data. If the files aren't that important and you have good backups then I suggest you toss the brick, get a new computer-preferably a Mac/Hackintosh, Linux or Android machine. And if you must run windows then get a good firewall
Comodo Firewall Pro https://personalfirewall.comodo.com/
ESET Smart Security http://www.eset.com/us/aff/mac/?ref=AFC-CJ&attr=7105813&pub=10843110&shop=skim33330X911647Xa09819e9fa3ed22e8168dd6b5fb6df8c
ZoneAlarm Free Firewall http://www.zonealarm.com/

and a good defensive antivirus
ESET NOD32 http://www.eset.com/us/home/products/antivirus/
F-Secure https://www.f-secure.com/en/web/home_global/home
Kaspersky http://www.kaspersky.com/

And if you must run Windows, do it in a virtual environment. The ransomware that's currently in use will not activate on a virtual or sandboxed system. There are two reasons for this;
1) the ransomware can't phone home
2) virtual and sandboxed systems are used by hackers to capture and study viruses. The ransomware has been taught to avoid those systems.

http://lifehacker.com/5714966/five-best-virtual-machine-applications
http://www.howtogeek.com/169139/sandboxes-explained-how-theyre-already-protecting-you-and-how-to-sandbox-any-program/
http://www.sandboxie.com/