<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ransomware Archives - CritchCorp Computers Ltd</title>
	<atom:link href="https://www.cc-computers.com/tag/ransomware/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cc-computers.com</link>
	<description>Complete Computer Support</description>
	<lastBuildDate>Thu, 10 Sep 2020 22:09:37 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://www.cc-computers.com/wp-content/uploads/2020/07/favicon.ico</url>
	<title>Ransomware Archives - CritchCorp Computers Ltd</title>
	<link>https://www.cc-computers.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Crypto-mining takes over from ransomware as fastest growing threat</title>
		<link>https://www.cc-computers.com/crypto-mining-takes-over-from-ransomware-as-fastest-growing-threat/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=crypto-mining-takes-over-from-ransomware-as-fastest-growing-threat</link>
					<comments>https://www.cc-computers.com/crypto-mining-takes-over-from-ransomware-as-fastest-growing-threat/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Thu, 03 Jan 2019 12:36:16 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[crypto currency]]></category>
		<category><![CDATA[crypto-mining]]></category>
		<category><![CDATA[ransom ware]]></category>
		<category><![CDATA[Ransomware]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1431</guid>

					<description><![CDATA[<p>&#160; With the invention of bitcoin, Ransomware was made possible. Prior to bitcoin it was difficult for the bad guys to get paid as it was easy to follow the money back to them. With bitcoin it is very difficult to impossible to follow the money back. Ransomware is a form of virus or malware [&#8230;]</p>
The post <a href="https://www.cc-computers.com/crypto-mining-takes-over-from-ransomware-as-fastest-growing-threat/">Crypto-mining takes over from ransomware as fastest growing threat</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>With the invention of bitcoin, Ransomware was made possible. Prior to bitcoin it was difficult for the bad guys to get paid as it was easy to follow the money back to them. With bitcoin it is very difficult to impossible to follow the money back. Ransomware is a form of virus or malware that infects a computer and encrypts all of your documents, pictures and even music and videos on your computer and generally will then go out over the network and encrypt any other resources that it can find. They then ask for money to give you the keys to unencrypt your information. This has been the single biggest problem for a number of years and there are many of knock-off versions of the original which were not as well written as the first and have caused even more problems in that, even after paying the ransom, people have not got their data back due to several errors in the process.</p>
<p><span id="more-1431"></span></p>
<p>Whilst Ransomware is still a very big problem and will continue to be for the foreseeable future, there is a new malware around that is taking over from ransomware in terms of the size of the problem. Instead of going through the process of encrypting your data and getting you to do something to pay them, which is also becoming more and more difficult due to people taking regular backups, and anyone using our Cloud accounts or Backup will have ShareSync, which gives you Ransomware protection for all the backed up files. They cannot be sure they will get any money for each installation making it an expensive and less fruitful endeavour. Now they are just stealing your computer processor, memory and electricity to make crypto currency themselves.</p>
<h2>What do they do?</h2>
<p>Well they install a virus on your computer, and then it sets about making crypto currency on your computer for them. This means that they do not have to pay for the computer or electricity, which is very expensive in creating crypto currency, in fact most of the time the amount you pay for the electricity is more than what you make in the currency itself. This makes it very lucrative to use other people&#8217;s computers and electricity to generate crypto currency for them. Some even use websites to this for them. When you visit a website, it downloads as part of the page a crypto-miner that mines crypto currency for the bad guys. This makes it lucrative to hack websites and install malware on it so when someone visits the website they are infected. It is important to look for the malware checking services such as <strong>SiteLock</strong>, which we use ourselves and you can get FREE copy of SiteLock Lite with every Feature Rich Hosting account, <a href="https://shop.cc-computers.com/cart.php?gid=1">here</a>.</p>
<p>Some of these crypto miners will only be active when you are on the site and others will download to your computer and remain there and carry on working after you leave the site. Either way you need to be careful with your computer and make sure that you check, if your computer suddenly starts running slow as you may have picked up one of these viruses. Thousands of sites are infected every day so just because it was ok yesterday, doesn&#8217;t mean it will necessarily be ok today. That is why it is important as a website owner to make sure you have a virus scanner that checks your website files as frequently as possible. If you can afford it you should also upgrade to get more protection in the form of advanced checks to check your site is free from cross site scripting and other vulnerabilities, which SiteLock can help you with.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-946 size-full" src="https://cc-computers.com/wp-content/uploads/2018/08/SiteLock_Customers_rectangle_720x300_v1-white-b.png" alt="" width="720" height="300" srcset="https://www.cc-computers.com/wp-content/uploads/2018/08/SiteLock_Customers_rectangle_720x300_v1-white-b.png 720w, https://www.cc-computers.com/wp-content/uploads/2018/08/SiteLock_Customers_rectangle_720x300_v1-white-b-600x250.png 600w, https://www.cc-computers.com/wp-content/uploads/2018/08/SiteLock_Customers_rectangle_720x300_v1-white-b-300x125.png 300w, https://www.cc-computers.com/wp-content/uploads/2018/08/SiteLock_Customers_rectangle_720x300_v1-white-b-500x208.png 500w" sizes="(max-width: 720px) 100vw, 720px" />If you notice that your website or computer are running slower than you think they should be then make sure you run a virus check and possibly get professional help. Another issue is that once you get one of these viruses in to your system, you are then left open as they can then sell space on your computer to other crypto miners or banking Trojans or worms and you then become the conduit for infecting other people&#8217;s computers on your network and occasionally on other websites,</p>
<p><em>If you think you have a problem on your computer then get in touch with your IT department or whoever looks after your computer. If you have no-one or would like a second opinion submit a support ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a> and we will call you to see if we can help you. (Charges will apply and will be fully discussed and agreed before any work commences so you will know the costs).</em></p>
<h2>Why are these viruses not picked up by antivirus software?</h2>
<p>Crypto miners themselves are not viruses, they are legitimate pieces of software that you can go and get yourself and install and mine for crypto currencies. All the bad guys do is take a copy of the crypto currency miner that they want and install it on your computer and then add their account details so any mined currency goes to them and then they tell it to run in the background and not to disturb you. Generally speaking this means that they will not ever be seen as bad software by antivirus software.</p>
<p>[ink-ad-creator ad=&#8221;1327&#8243;][/ink-ad-creator]</p>The post <a href="https://www.cc-computers.com/crypto-mining-takes-over-from-ransomware-as-fastest-growing-threat/">Crypto-mining takes over from ransomware as fastest growing threat</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/crypto-mining-takes-over-from-ransomware-as-fastest-growing-threat/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>Your email account has been hacked, emails</title>
		<link>https://www.cc-computers.com/your-email-account-has-been-hacked-emails/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=your-email-account-has-been-hacked-emails</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Thu, 08 Nov 2018 11:42:00 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[email hacking]]></category>
		<category><![CDATA[phishing email]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Scams]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1239</guid>

					<description><![CDATA[<p>Many of our users have seen this type of email in their spam filters, most don’t actually get through to your account, although the odd one might. That is all the spammers, who are usually organised crime syndicates, need and rely on. A full version of the email is at the bottom of this post. [&#8230;]</p>
The post <a href="https://www.cc-computers.com/your-email-account-has-been-hacked-emails/">Your email account has been hacked, emails</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="aligncenter size-full wp-image-1248" src="https://cc-computers.com/wp-content/uploads/2018/11/blur-business-card-211290.jpg" alt="" width="4752" height="3168" /></p>
<p>Many of our users have seen this type of email in their spam filters, most don’t actually get through to your account, although the odd one might. That is all the spammers, who are usually organised crime syndicates, need and rely on.</p>
<p>A full version of the email is at the bottom of this post.</p>
<h2>What are these emails and why do some of them have my password in them?</h2>
<p>These emails raise many questions and I will try to answer most of them here.</p>
<p>It is of course possible for what they say in the email to be true, but in most cases it is not. There have been many hacked websites over the years and there are now plenty of lists of people’s usernames and passwords, that have been compiled from these hacked websites. There are now two or three main lists that have been compiled and in turn these in to one list of over 500,000,000 usernames and passwords. Security researchers use this list to determine things like frequency of passwords, your chosen password is probably not as unique as you think it is; monkey, password, 123456, abc123 were the top password for many years and although recent research shows that they have moved about, they are still in the top 15.</p>
<p>The bad guys use these username and password lists to try to gain access to your accounts on other wesites and even your email account. Now some bright spark has decided to take your username and password combination where your username is your email address and send an email to you, firstly showing your password to you and secondly faking the sending address, which is trivialy to do, and then tells you that they know something about you that you don&#8217;t want revealed to others. This is a typical phishing scam in that they don&#8217;t have any access to your email (that is not say that they don&#8217;t but they tend to use other scams that are more profitable when they actually have access to your email).<span id="more-1239"></span></p>
<p><em><strong>NOTE</strong>: If you receive these emails to your inbox, then please contact your hosting provider or website maintenance company or computer support company in order to ensure that your SPF records and spam filtering are setup correctly. Our clients can submit a ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=2">here</a> anyone else who needs help can submit a support ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a> and we will see if we can help. (<span style="color: #ff0000;"><strong>WARNING</strong></span> &#8211; incorrectly setting up SPF records can cause you to stop receiving legitimate emails and still allow spam through as well as prevent your emails from reaching their destination, it also requires those sending you legitimate emails to have their email system correctly configured with or without SPF records).</em></p>
<p>Facebook, Vodafone and Dropbox are all examples of large databases of usernames and passwords that have been stolen as well as many smaller companies that have lost control of their databases and not had them properly encrypted. Even those that are encrypted with a basic hash can still be deciphered using rainbow tables. Sites need to hash passwords using individual salts and store the salt in a different database to the username and password database, but that is starting to get technical so I won’t go further in to that.</p>
<p>What is important is that if you, like many people, use the same password on multiple sites then you need to change your password immediately on all sites where the password has been used. You should really consider using a password manager to save individual unique passwords for each site. We could go in-depth in to the various password managers and the pros and cons of each and which ones to avoid completely but that is for another time, for now we will just recommend our own ConnectID which is available with all of our cloud accounts to manage your websites and web apps and auto log you in without you needing to remember your passwords. If you would like more details on this then go here and <a href="https://shop.cc-computers.com/cart.php?gid=16">here</a> or submit a ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a>.</p>
<p>If you have received one of the emails that is warning you that your account has been hacked, then you probably do not have too much to worry about (note that there is some worry as mentioned above). The email suggests that you have had your computer hacked as well and that malicious software has been installed. Whilst this could be true in some cases it is not for most and it is just a phishing exercise to get people to pay up. Email addresses are easy to spoof. These emails can usually be deleted. DO NOT click any of the links in the email as bad things may happen. They can then install a virus which can watch or steal passwords and bank details or do worse things. If you have clicked the link you should take immediate precautions to secure your PC, run antivirus on the highest level or deepest scan and perhaps get in contact with your support company, we can provide remote support, please click <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a> to submit a ticket or <a href="https://shop.cc-computers.com/register.php">here to signup</a> and then call or submit a ticket from your account.</p>
<p>This scam should not be confused with <strong>real hijacking of your data</strong>, Ransomware is around, just like the radio advert says and they will take your money and not necessarily give you your data back. It costs businesses millions of pounds in lost earnings whilst trying to get things fixed. See our articles on this subject <a href="https://www.cc-computers.com/?s=ransom&amp;submit=Search">here</a>. It is a very real and serious problem if you get ransomware in to your network. You should ensure you have backups that protect against this, as not all backups will. Backups should be Ransomware proof, like our backup ShareSync, available as a standalone product or with our cloud accounts. As far as we know it is the only one to give this protection as well as the file sharing capabilities of Dropbox or Box, OneDrive or iCloud. If your data is hijacked and you don&#8217;t have sufficient backups then you could lose your data completely as has happened to many people and businesses, including a Police station in the USA. The same thing that happened to the NHS in England some months ago which caused operations to be cancelled and days of disruption to the service it provides before it was finally fixed (see BBC news article <a href="https://www.bbc.co.uk/news/health-39899646">here</a>).</p>
<p>I digress, but it important to note the difference between ransomware and these opportunistic phishing emails which are trying to scare people into handing over cash. In the last few days they have increased dramatically as others have taken the idea and have now started to send these emails, without the password, to any and all email addresses they have.</p>
<p>The short side of this story is, make sure your email is setup correctly and your spam filtering is doing its job and delete these emails if they get through without opening them and definitely don&#8217;t click any link in the email, in fact, never click the link in an email unless you are expecting it and you have made sure it comes from the person you are expecting it from.</p>
<p>Some of these are bound to get through your spam filtering at some point, just delete them.</p>
<p>If your computers are important to you or your business, make sure that you have sufficient backups and your computer and network are checked and maintained regularly by someone trained and experienced in computer and network security.</p>
<p>Below is a couple of examples of the email as it is being sent out:</p>
<blockquote><p>Hello, my victim.<br />
I know your password &#8211; {a password}</p>
<p>That is my last warning.</p>
<p>I write you inasmuch as I set a trojan on the net site with pornography that you have visited.<br />
My spyware grabbed all your own personal information and switched on your web cam which captured the procedure of your masturbation.<br />
Right after that trojan stored your contact list.<br />
I will remove the compromising video and all the information if you pay me 600 USD in bitcoin.<br />
This is wallet address for payment : 1HqUTGvbvDWCSTFDdYtPVviPW2iF8HsNUc<br />
(you can google on &#8220;how to buy bitcoin&#8221;)</p>
<p>I give you twenty four hours once you view my message to make the payment.<br />
When you see the email I&#8217;ll know it right away.<br />
It&#8217;s not required to inform me that you have delivered BTC to me. This address is connected to you, my script will erase everything instantly after payment confirmation.<br />
You are able to visit the police but no one can not help you.<br />
In the event that you try to cheat me, I&#8217;ll see it straight away!<br />
I don&#8217;t live in your country. So no one can not track my place even for 9 months.<br />
Don&#8217;t forget about the disgrace. Your life may be ruined.</p></blockquote>
<p>Another:</p>
<blockquote><p>Dear user of xxxxxxxxxx.xx.xx!</p>
<p>&nbsp;</p>
<p>I am a spyware software developer.</p>
<p>Your account has been hacked by me in the summer of 2018.</p>
<p>&nbsp;</p>
<p>I understand that it is hard to believe, but here is my evidence:</p>
<p>&#8211; I sent you this email from your account.</p>
<p>&#8211; Password from account xxxxxxxxxx@xxxxxxxxxx.xx.xx: xxxxxx (on moment of hack).</p>
<p>&nbsp;</p>
<p>The hacking was carried out using a hardware vulnerability through which you went online (Cisco router, vulnerability CVE-2018-0296).</p>
<p>&nbsp;</p>
<p>I went around the security system in the router, installed an exploit there.</p>
<p>When you went online, my exploit downloaded my malicious code (rootkit) to your device.</p>
<p>This is driver software, I constantly updated it, so your antivirus is silent all time.</p>
<p>&nbsp;</p>
<p>Since then I have been following you (I can connect to your device via the VNC protocol).</p>
<p>That is, I can see absolutely everything that you do, view and download your files and any data to yourself.</p>
<p>I also have access to the camera on your device, and I periodically take photos and videos with you.</p>
<p>&nbsp;</p>
<p>At the moment, I have harvested a solid dirt&#8230; on you&#8230;</p>
<p>I saved all your email and chats from your messangers. I also saved the entire history of the sites you visit.</p>
<p>&nbsp;</p>
<p>I note that it is useless to change the passwords. My malware update passwords from your accounts every times.</p>
<p>&nbsp;</p>
<p>I know what you like hard funs (adult sites).</p>
<p>Oh, yes .. I&#8217;m know your secret life, which you are hiding from everyone.</p>
<p>Oh my God, what are your like&#8230; I saw THIS &#8230; Oh, you dirty naughty person &#8230; 🙂</p>
<p>&nbsp;</p>
<p>I took photos and videos of your most passionate funs with adult content, and synchronized them in real time with the image of your camera.</p>
<p>Believe it turned out very high quality!</p>
<p>&nbsp;</p>
<p>So, to the business!</p>
<p>I&#8217;m sure you don&#8217;t want to show these files and visiting history to all your contacts.</p>
<p>&nbsp;</p>
<p>Transfer $847 to my Bitcoin cryptocurrency wallet: 1GXazHVQUdJEtpe62UFozFibPa8ToDoUn3</p>
<p>Just copy and paste the wallet number when transferring.</p>
<p>If you do not know how to do this &#8211; ask Google.</p>
<p>&nbsp;</p>
<p>My system automatically recognizes the translation.</p>
<p>As soon as the specified amount is received, all your data will be destroyed from my server, and the rootkit will be automatically removed from your system.</p>
<p>Do not worry, I really will delete everything, since I am &#8216;working&#8217; with many people who have fallen into your position.</p>
<p>You will only have to inform your provider about the vulnerabilities in the router so that other hackers will not use it.</p>
<p>&nbsp;</p>
<p>Since opening this letter you have 48 hours.</p>
<p>If funds not will be received, after the specified time has elapsed, the disk of your device will be formatted, and from my server will automatically send email and sms to all your contacts with compromising material.</p>
<p>&nbsp;</p>
<p>I advise you to remain prudent and not engage in nonsense (all files on my server).</p>
<p>&nbsp;</p>
<p>Good luck!</p></blockquote>
<p>&nbsp;</p>
<p>There are other variants as well with other messages in them to catch other people out, these are just two examples we hae seen.</p>
<p>Stay Safe.</p>
<p>CritchCorp Computers Ltd.</p>The post <a href="https://www.cc-computers.com/your-email-account-has-been-hacked-emails/">Your email account has been hacked, emails</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Ransomware attacks Mac and PCs</title>
		<link>https://www.cc-computers.com/pc-mac-ransomware/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=pc-mac-ransomware</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Thu, 14 Jun 2018 10:03:00 +0000</pubDate>
				<category><![CDATA[Informational]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[box]]></category>
		<category><![CDATA[carbonite]]></category>
		<category><![CDATA[dropbox]]></category>
		<category><![CDATA[file sharing]]></category>
		<category><![CDATA[mozy]]></category>
		<category><![CDATA[online backup]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[sharesync]]></category>
		<category><![CDATA[viruses]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=621</guid>

					<description><![CDATA[<p>Ransomware is one of the most profitable illegal software on the internet. It affects many thousands of people every year and has done so for around 5 years now, since the first ransomware attacks which were well crafted pieces of software that had been really well written so that there is no hope at all [&#8230;]</p>
The post <a href="https://www.cc-computers.com/pc-mac-ransomware/">Ransomware attacks Mac and PCs</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p><img decoding="async" class="alignnone" title="Protect your visitors from malware" src="https://cc-computers.com/wp-content/uploads/2018/08/code-computer-cyberspace-225769-1000x288.jpg" alt="Use cWatch Website Protection available in the shop now" width="1000" height="288" data-json="" />Ransomware is one of the most profitable illegal software on the internet. It affects many thousands of people every year and has done so for around 5 years now, since the first ransomware attacks which were well crafted pieces of software that had been really well written so that there is no hope at all of getting your files back without the key, unless you have a secure backup. No one is safe, even Mac users are under attack.</p>
<p>Firstly, what is ransomware and what does it do, how do you get rid of it and get your data back.</p>
<p>Then we will look at how to prevent and recover from an attack.</p>
<p><strong>What is ransomware and what does it do?</strong></p>
<p>Well it is software that you get in any of the normal virus/malware routes via email, download or visiting a website with malicious intent or malicious adverts, even good websites can fall foul to giving you viruses though delivering adverts from third parties that are infected. When you get ransomware on your computer (PC or Mac) it will quietly sit in the back ground and after making contact back &#8220;<em>home</em>&#8221; it will start to encrypt any important documents it can find. What it calls important documents is up to the maker of the ransomware but generally includes all your Word, Excel, and PowerPoint, database, email, pictures and music files. Some are clever enough to start with the files you use least and then work up to the ones you use more often in order to get more files encrypted before being discovered, others just work on a first come first served basis. Many these days will then also see what other computers are on your network and try to infect them also. This creates further problems down the line as you will see later. Depending on the actual ransomware you have, you may not notice anything is wrong until you try to open a file and it says you can&#8217;t because it is corrupt. The ransomware will finish encrypting everything and then pop up a message to politely inform you that &#8220;You’ve been got&#8221; and give you instructions on how to get your files back with a countdown timer. Others will do this on completion but also if you look in the folder with your file you will see a text files with every encrypted file that tells you basically the same thing and how you can pay to stop and reverse the process. Because the files are encrypted with the best encryption known to man they are impossible to crack without the key. Banning such encryption would not solve the problem because at the end of the day encryption is just maths and you can&#8217;t undo what has been learned in maths. All that would happen is the bad guys would continue to use it and it would make it easier for the bad guys to get you stuff if you don&#8217;t use encryption yourself.</p>
<p>Now they have the keys to your files and you need to pay for the key to get your files back. Many companies and individuals have paid making this a very profitable scheme and it has made way for thousands of copycat ransomware, some not written as well as the original but just as effective if you don&#8217;t know what you’re doing and can&#8217;t afford thousands of Pounds to get an expert in to resolve it for you. Although I have not seen any yet, it is possible that you may get charged with supporting terrorism or organised crime if you pay the fees as that is what you are actually doing, these viruses are not done by kids trying to prove themselves they are done by organised crime syndicates and terrorist groups, so as far as I am concerned paying the &#8220;fee&#8221; is not an option.</p>
<p><strong>How do get rid of it and get your data back?</strong></p>
<p>To get rid of the virus itself is usually not too difficult. At the end of the day, if you aren’t going to pay then they aren’t bothered if you remove it, so many will go without too much of a fight. However if you remove it, you also remove the chance to get your data back as there is generally no way to get it back after you remove the virus itself. If you decide to pay the ransom, then there is a 20% chance it will not be able to give your data back anyway and you will also have to pay the ransom for each device infected, <em>why?</em> Because as we said earlier the virus will look over the network and try to infect any devices it can and starts to do the same thing from each new device infected. It will also infect all your data stored on any shared folder or drive and by default on older PCs you will be sharing your entire drive over the network, even if it is hidden. Severs typically will be encrypted by the virus as they are generally open to all users. That means that each instance of the virus will encrypt the files. To recover them you must unencrypt each file in the reverse order to which it was encrypted; so if you have 5 pcs infected and they encrypt a file in the order of PC1, then PC2, then PC3, then PC4 and then PC5, you must unencrypt them in the order of PC5, then PC4, then PC3, then PC2 and then PC1. Needless to say that you do not know (and neither do they) which PC encrypted which files first, yet alone in other order and they may not be sequential, so if a file was in use at the time PC2 was looking at it then it will move on to the next file and be the first one to encrypt that file and then go back later to infect the other file and be the last one to encrypt that particular file, there is no way for anyone to know. There is of course the fact that some are not written as well and the recovery process, which is after you have paid, is not the focus of their attention; and as there is no refunds if you’re not happy, they don’t care if it works or not.</p>
<p>The best way to guarantee getting your files back is good disaster recovery planning, and this is a disaster. Most victims (around 80%) lose at least 2 days to this type of attack with 20% losing around 5 days or more. Getting the right backup plan is place is the key. Online backup only solutions are great but do typically suffer from time issues. To download from Carbonite or Mozy or any other online backup can take as long as 12 hours per 50GB of data to recover. File sharing programs, such as box or drop box, one drive, iCloud, etc. are even worse as in most cases these will also be encrypted with no way to get them back, although some do offer recovery for a price and it is a telephone call away and a day or twos work.</p>
<p>The only solution that we are aware of that actually does work is our ShareSync app, which comes as a standalone product or as part of other cloud services such as cloud email. This will give you the best of both worlds with easy access and sharing of files with anyone you choose and a backup copy made each time a file is changed. This means that you can just revert a file or files or everything back to a previous state, i.e. before the ransomware attack, and carry on. Backup, sharing and disaster recovery taken care of.</p>
<p>It can take the place of your Drop Box or similar program and your tape or online backup so saving you money.</p>
<p>We do recommend though that you still keep at least three copies of any files that are critical. The working version and two backups on different media. There are different reasons for these which we will cover in another story.</p>
<p>In March 2016 CNBC reported on a story about ransomware in Macs (see their story <a href="https://www.cnbc.com/2016/03/07/apple-mac-users-targeted-by-first-full-ransomware-attack.html">here</a>) and that story also showed that ransomware for macs has been around since at least 2014.</p>
<p>The best advice we can give you, is &#8220;Don&#8217;t get infected in the first place, but make sure your disaster recovery plans include this type of disaster. Test it to make sure it works&#8221;</p>
<p>We can certainly help any size business or individual to plan for this and other types of disaster, so use our new chat, call or submit a support ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a>.</p>
<p>Whatever you do, make sure you are protected against this type of attack. Virus and Malware checkers are good, but they are reactive, not proactive (that would be nice but it is impossible). They can only find a new virus or any sort after it has been discovered, which means that there is at least, usually more, when they can attack and no one will know they are there. Also many virus makers know how to get round the antivirus programs so that is another thing the antivirus makers are constantly trying to combat.</p>
<p>Stay safe,</p>
<p>CritchCorp Computers Ltd</p>
<p style="text-align: center;"><img loading="lazy" decoding="async" class="alignnone wp-image-1745 size-full" src="https://cc-computers.com/wp-content/uploads/2019/04/cCW_920x100_2-100.jpg" alt="Get protection fro your website" width="921" height="101" srcset="https://www.cc-computers.com/wp-content/uploads/2019/04/cCW_920x100_2-100.jpg 921w, https://www.cc-computers.com/wp-content/uploads/2019/04/cCW_920x100_2-100-600x66.jpg 600w, https://www.cc-computers.com/wp-content/uploads/2019/04/cCW_920x100_2-100-300x33.jpg 300w, https://www.cc-computers.com/wp-content/uploads/2019/04/cCW_920x100_2-100-768x84.jpg 768w, https://www.cc-computers.com/wp-content/uploads/2019/04/cCW_920x100_2-100-500x55.jpg 500w" sizes="auto, (max-width: 921px) 100vw, 921px" /></p>The post <a href="https://www.cc-computers.com/pc-mac-ransomware/">Ransomware attacks Mac and PCs</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Update to the new Ransomware</title>
		<link>https://www.cc-computers.com/update-to-the-new-ransomware/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=update-to-the-new-ransomware</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Wed, 11 Dec 2013 17:46:27 +0000</pubDate>
				<category><![CDATA[Informational]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Updates]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[data encrypted]]></category>
		<category><![CDATA[data encryption]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[lose data]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[police hit]]></category>
		<category><![CDATA[ransom]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[viruses]]></category>
		<guid isPermaLink="false">http://www.cc-computers.biz/Blog/?p=250</guid>

					<description><![CDATA[<p>For the original post see: https://www.cc-computers.com/ransomware-takes-hold/ In the original post I talked about the new ransomware that it taking hold all over the world. It has even hit a police station in America that had to pay the &#8220;fee&#8221; to get back their data. The latest version of this virus now takes advantage of all [&#8230;]</p>
The post <a href="https://www.cc-computers.com/update-to-the-new-ransomware/">Update to the new Ransomware</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>For the original post see: https://www.cc-computers.com/ransomware-takes-hold/</p>
<p>In the original post I talked about the new ransomware that it taking hold all over the world. It has even hit a police station in America that had to pay the &#8220;fee&#8221; to get back their data.</p>
<p>The latest version of this virus now takes advantage of all the help that has been available on line to &#8220;improve their product&#8221;. Now if you thought that you could get your data back through shadow copies (Also known as previous versions), think again. The virus now encrypts those too.</p>
<p>Here is what it does now, which is the same as before but better.</p>
<p>Currently the infection vector is through email as an attachment; usually a zip file or pdf that is actually an exe file but as most people have the &#8220;Hide extension of known file types&#8221; ticked on you would not normally see it. You will see filename.pdf when the actual filename is filename.pdf.exe. I expect that this will change or be improved on as well with links in email and other file types, etc.</p>
<p>When you open this file it infects your computer and immediately contacts a server from a list of around 1000 possible domain names generated through an algorithm. When it finds a live server it exchanges details with it and starts the encryption process. At this point it doesn&#8217;t let you know that you have been infected and is not picked up by most antivirus software. The first version would finish its work without interruption of antivirus software.</p>
<p>It encrypts all user content that it can find on your PC, mapped network drives and any shares that it can find on the network and file sharing programs data such as box.net and drop box. It also encrypts any shadow copies and backups that it can get to. When it has finished its work it pops up a message to tell you what it has done, it even gives you a list of the files that it has encrypted so that you can verify that they are your files. It then gives you a countdown timer starting around 72 hours. You have this amount of time to pay the fee and get your files back. Now where the old version used to just delete the key if you didn&#8217;t pay up in time the new version will give you a discount for paying within the time frame. Currently it is 1/2 bit coin (which is now about £500). If you fail to pay in time then it goes up to 10 bit coin (About £5000). This &#8220;service&#8221; is available for an extended amount of time.</p>
<p>In short get yourself protected and keep offline backups and redundant copies.</p>
<p>CritchCorp Computers Ltd.</p>
<p>&nbsp;</p>The post <a href="https://www.cc-computers.com/update-to-the-new-ransomware/">Update to the new Ransomware</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New ransomware takes hold</title>
		<link>https://www.cc-computers.com/ransomware-takes-hold/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ransomware-takes-hold</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Fri, 25 Oct 2013 16:14:38 +0000</pubDate>
				<category><![CDATA[Informational]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[encrypted data]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[lose data]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[viruses]]></category>
		<guid isPermaLink="false">http://www.cc-computers.biz/Blog/?p=241</guid>

					<description><![CDATA[<p>New ransomware has been taking hold of businesses and households around the world. Be very careful with the email attachments that you open, although this is probably only the first wave; they will find other ways to get to you. What&#8217;s new about this virus then? This virus; actually it is a malware strain named [&#8230;]</p>
The post <a href="https://www.cc-computers.com/ransomware-takes-hold/">New ransomware takes hold</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>New ransomware has been taking hold of businesses and households around the world. Be very careful with the email attachments that you open, although this is probably only the first wave; they will find other ways to get to you.</p>
<p>What&#8217;s new about this virus then? This virus; actually it is a malware strain named ransomware, named that for a very good reason, is an example of modern encryption done right. They have created a perfect system that can encrypt your data using public key technology that cannot be cracked!!</p>
<p>How does it work? Well, at the moment you get an email about something that is relevant to you (that&#8217;s how they trick you in to opening the attachment, or clicking the link). Once the software is running, it quickly establishes a connection to its command and control server, where it generates a random encryption key specifically for your system. This type of encryption is particularly cleaver as the key that encrypts it cannot be used to decrypt it without the other part that is held on the command and control server (it never gets sent to your computer, so there is no record of it for you to find). it then searches your computer and network, any backup drives you have access to, in fact, any resource that contains user created or user data and encrypts them all! Any evidence of the key locally is then destroyed and a page pops up to inform the user that they have been robbed! It can show you a list of the files you once had so that you can verify the threat is real and then gives you the ultimatum of pay $300 or 300 of your local currency or lose your data, you have 72 hours to make your mind up. After 72 hours have passed the only key that could decrypt your data, which is on the command and control server, is deleted, permanently!</p>
<p>If you do not have any backups of your data and you need it, then you have no choice but to pay up, and thousands of people and businesses have done so. They have also been very cleaver with the payment method as they cannot be tracked through the payment either. When law enforcement find the servers and take them offline, the only people hurt are the people who now cannot get their data back. The ad guys have their command and control servers moving around and are not needed for the payment loop; they just create and hold the keys to your data.</p>
<p>The other point on this is that they seems to have written the encryption part exceptionally well, not so good is the decryption side of the program with reports that not all and in some cases none of the data is returned and there is nothing you can do to get it back.</p>
<p>Be careful and watch this space as it will only get worse!!</p>The post <a href="https://www.cc-computers.com/ransomware-takes-hold/">New ransomware takes hold</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
