How to remove ‘ransomware’ from your computer

  • San Jose Mercury News
  • Wednesday, October 30, 2013 3:27pm
  • Business

Thousands of consumers are getting a nasty shock when they turn on their computers these days.

They find their screen frozen with an alarming note from what appears to be a government agency claiming they’ve accessed child pornography or committed other crimes and demanding money to unlock their machines.

If they fail to pay, the note warns, the authorities will lock them up next.

“It’s probably the No. 1, end-user cybercrime now,” said Kevin Haley, director of security response at Mountain View, Calif.-based Symantec. “It’s pretty serious.”

Experts say the risk of getting infected with “ransomware” can be minimized by making sure all of your software — including your antivirus programs — are updated regularly, not opening spam or email attachments from people you don’t know and avoiding suspicious-looking websites.

If that doesn’t work, you may have to wipe the computer completely clean and reinstall your files afterward. That assumes you have previously “backed up” or stored those files on a USB device, website service or some other way. If you haven’t, your photos, financial records and other documents could be lost.

Windows-based computers often come with a recovery CD for restoring the operating system and other pre-loaded software. But restoring files can be complicated, and people who aren’t tech-savvy may need to get help from a computer-repair store or other experts.

“It’s a nasty type of malware,” concluded Andreas Baumhof, chief technology officer at San Jose, Calif., security company ThreatMetrix. “After one of these incidents, I’m sure people treat their online security differently.”

Although the money-extorting scheme has been around for years, it gained notoriety in 2005, when Russian crooks began using it. Since then, it has evolved to become one of the world’s most pervasive and aggravating cyber schemes.

Symantec, one of several companies offering a free ransomware removal service, recently reported seeing an “explosion of ransomware” spread by criminal gangs. In one case alone, it noted, 500,000 computers were infected over a period of just 18 days.

At least 16 variations of the scam have been documented. A typical version freezes the victim’s computer with a message bearing an official-looking FBI logo, accusing the person of having visited child porn websites and of sending “messages with terrorist motives.” It demands $200 or more to unlock the machine, adding, “you have 72 hours to pay the fine, otherwise you will be arrested.”

In earlier versions, victims were told to pay the ransom by sending a premium-rate text message, which was charged to their phone bill. More recently, crooks have demanded payment via prepaid electronic systems such as MoneyPak. Those are sold for cash in stores and provide coded numbers used to pay bills online.

“A conservative estimate is that over $5 million a year is being extorted from victims,” Symantec’s report said, though it added that the actual total is “likely much higher.”

Experts generally advise against paying the ransom, because there’s no guarantee the crooks will ever unfreeze the computer. If you do pay, said ThreatMetrix’s Baumhof, all you can do is “hope and pray that the bad guys have some sense of humanity in them.”

———

10 STEPS FOR REMOVING RANSOMWARE

Here’s how to use a free Symantec service that the company says often removes the virus:

1. If the computer is Internet-connected, shut it off by holding down the power button for about 10 seconds.

2. Turn it back on while repeatedly tapping the F8 key.

3. When it brings up the “advanced boot options,” use the down arrow to select “safe mode with networking” and hit “enter.” You should see a screen that says “safe mode.”

4. Open a browser — such as Google Chrome, Mozilla Firefox or Internet Explorer — and go to http:/// www.norton.com/npe

5. Click the button to download the Norton Power Eraser, save it to your desktop and double-click the icon to run the file.

6. After reading the user license and clicking “agree,” click “scan for risks.”

7. As Power Eraser restarts the computer, repeatedly hit the F8 button and again select safe mode with networking.

8. Click “run” so Power Eraser can scan for the virus.

9. Once it finishes, you’ll see “scan complete” in a window with the results. Then click the “fix” button.

10. Click “restart” to reboot the computer again. You should see a confirmation that threat has been removed.

SOURCE: Symantec

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Szabella Psaztor is an Emerging Leader. (Olivia Vanni / The Herald)
Szabella Pasztor: Change begins at a grassroots level

As development director at Farmer Frog, Pasztor supports social justice, equity and community empowerment.

Owner and founder of Moe's Coffee in Arlington Kaitlyn Davis poses for a photo at the Everett Herald on March 22, 2024 in Everett, Washington. (Annie Barker / The Herald)
Kaitlyn Davis: Bringing economic vitality to Arlington

More than just coffee, Davis has created community gathering spaces where all can feel welcome.

Simreet Dhaliwal is an Emerging Leader. (Olivia Vanni / The Herald)
Simreet Dhaliwal: A deep-seated commitment to justice

The Snohomish County tourism and economic specialist is determined to steer change and make a meaningful impact.

Emerging Leader John Michael Graves. (Ryan Berry / The Herald)
John Michael Graves: Champion for diversity and inclusion

Graves leads training sessions on Israel, Jewish history and the Holocaust and identifying antisemitic hate crimes.

Gracelynn Shibayama, the events coordinator at the Edmonds Center for the Arts, is an Emerging Leader. (Olivia Vanni / The Herald)
Gracelynn Shibayama: Connecting people through the arts and culture

The Edmonds Center for the Arts coordinator strives to create a more connected and empathetic community.

Eric Jimenez, a supervisor at Cocoon House, is an Emerging Leader. (Olivia Vanni / The Herald)
Eric Jimenez: Team player and advocate for youth

As an advocate for the Latino community, sharing and preserving its traditions is central to Jimenez’ identity.

Nathanael Engen, founder of Black Forest Mushrooms, an Everett gourmet mushroom growing operation is an Emerging Leader. (Olivia Vanni / The Herald)
Nathanael Engen: Growing and sharing gourmet mushrooms

More than just providing nutritious food, the owner of Black Forest Mushrooms aims to uplift and educate the community.

Molbak's Garden + Home in Woodinville, Washington closed on Jan. 28 2024. (Photo courtesy of Molbak's)
Molbak’s, former Woodinville garden store, hopes for a comeback

Molbak’s wants to create a “hub” for retailers and community groups at its former Woodinville store. But first it must raise $2.5 million.

DJ Lockwood, a Unit Director at the Arlington Boys & Girls Club, is an Emerging Leader. (Olivia Vanni / The Herald)
DJ Lockwood: Helping the community care for its kids

As director of the Arlington Boys & Girls Club, Lockwood has extended the club’s programs to more locations and more kids.

Alex Tadio, the admissions director at WSU Everett, is an Emerging Leader. (Olivia Vanni / The Herald)
Alex Tadio: A passion for education and equality

As admissions director at WSU Everett, he hopes to give more local students the chance to attend college.

Dr. Baljinder Gill and Lavleen Samra-Gill are the recipients of a new Emerging Business award. Together they run Symmetria Integrative Medical. (Olivia Vanni / The Herald)
Emerging Business: The new category honors Symmetria Integrative Medical

Run by a husband and wife team, the chiropractic and rehabilitation clinic has locations in Arlington, Marysville and Lake Stevens.

People walk along the waterfront in front of South Fork Bakery at the Port of Everett on Thursday, April 11, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett inks deal with longtime Bothell restaurant

The port will break ground on two new buildings this summer. Slated for completion next year, Alexa’s Cafe will open in one of them.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.