Recovering from screen-locking ransomware
Screen-locking ransomware prevents you from accessing your computer by blocking access to the operating system. When you turn on your computer, you will usually see a ransom note claiming that your device has been locked and demanding payment before you can use it again.
This type of infection often occurs after visiting a malicious website, clicking a malicious link, or opening an infected email attachment.
If you have experienced screen-locking ransomware, consider reporting your experience through your organisation's reporting process or any trusted cyber incident reporting programme. Sharing information about attacks helps improve understanding of emerging threats and can assist in protecting future victims.
We want to better understand the impact of you experiencing this issue, can you share your experience by filling in this online form? This will help us better protect future victims.
Screen-locking ransomware - do this first!
Before attempting to remove the ransomware, take the following steps:
Disconnect your device from the internet and from any other connected devices to reduce the risk of the infection spreading. Disconnect Wi-Fi or Ethernet connections and unplug external hard drives, USB devices and other removable media.
Use a smartphone or camera to take clear photographs of the ransom note and any error messages. This evidence may assist with reporting the incident and any future investigation.
Avoid making changes to the system until you have preserved any important evidence.
Are you going to get your data back?
Screen-locking ransomware is generally one of the less sophisticated forms of ransomware. In many cases, the malicious software only prevents access to the operating system and does not encrypt your files.
Cyber criminals rely on fear and urgency to pressure victims into paying the ransom. Many people are able to regain access to their computers without paying.
By following the recovery steps below, there is a good chance you will be able to recover your device and your data.
If the criminals are threatening to publish your personal or sensitive information, you may find our outing guide useful.
Should you pay the ransom?
The recommended approach is not to pay the ransom.
Paying encourages criminal activity and provides financial support to cybercriminals. There is also no guarantee that payment will restore access to your computer, and paying may identify you as someone who is willing to pay future demands.
Because screen-locking ransomware can often be removed without payment, it is usually better to focus on recovery before considering any other options.
Approaches to removing screen-locking ransomware
Depending on the ransomware involved, there are several approaches you can try. Work through the following steps in order and stop once you have successfully regained access to your computer.
If you are not comfortable performing these steps yourself, seek assistance from a trusted IT professional.
Important: Removing the ransomware does not decrypt encrypted files (if encryption has occurred). Removing the malware may also remove your ability to communicate with the attackers should you later decide to pay. Only remove the ransomware if you are confident you can recover your system without paying or have decided that you will not pay the ransom.
Restart Your Computer in Safe Mode - Safe Mode starts Windows with only essential software and services, preventing most malware from running. Once in Safe Mode:
Update your antivirus software (if possible).
Perform a full system scan.
Remove any threats that are detected.
Try Windows system restore- If you cannot access the Windows recovery environment but have installation media for your version of Windows, boot from the installation media and choose Repair your computer instead of reinstalling Windows.
Check for a free decryption tool - Before attempting more advanced recovery methods or considering payment, check whether a free decryption tool exists for your specific ransomware variant.
Trusted initiatives such as No More Ransom provide free decryption tools for many known ransomware families. If a suitable decryptor is available, carefully follow the instructions provided.
If recovery is still not successful - If you are unable to remove the infection using the steps above, seek assistance from a trusted IT professional before making further changes to your system.
Report the Crime
If you are in South Africa, you can report cybercrime to the South African Police Service (SAPS), particularly where there is:
financial loss;
extortion or ransom demands;
threats;
unauthorised access to systems or accounts; or
theft or exposure of personal information.
Keep copies of:
the ransom note;
screenshots;
cryptocurrency wallet addresses;
payment instructions;
emails;
phone numbers;
chat messages; and
any other communications from the attackers.
You may also report cyber incidents to the South African Cybersecurity Hub where appropriate.
If the ransomware may have exposed personal information belonging to other people, and you are responsible for that information, you should also consider your obligations under the Protection of Personal Information Act (POPIA). Responsible parties may need to notify the Information Regulator and affected individuals where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.
How to avoid being infected with encrypting ransomware again
Keep regular backups – Maintain regular backups of important files using an external drive or reputable cloud backup service. If using an external drive, disconnect it after the backup completes so that ransomware cannot encrypt the backup as well.
Use reputable antivirus software – Install reputable antivirus software and keep it up to date. Modern security software can detect and block many ransomware threats before they execute.
Install updates promptly – Install operating system and software updates as soon as they become available. Security updates often fix vulnerabilities that ransomware exploits. Where possible, enable automatic updates.
Be cautious with emails and links– Be careful when opening attachments or clicking links received through email, SMS, messaging apps or social media. Even legitimate accounts can be compromised and used to distribute malicious files or links. If something seems unusual or unexpected, verify it with the sender before interacting with it.
Donate
Your generosity makes our free support possible. Please consider giving today.
Without donations, we cannot keep our service free or provide help to the most vulnerable victims of cybercrime when they need it most. As a not-for-profit organisation, every donation goes directly towards keeping The Cyber Helpline up and running. Donate now and help us support victims of cybercrime.