CryptoLocker and other types of “ransomware” are particularly destructive pieces of malware (“bad stuff”) that make most or all of your files unusable. Your computer can get infected through one of several different methods, and most regular antivirus software will NOT necessarily prevent an infection. Most ransomware also keeps being changed, and newer versions work in different ways and can be harder to detect.

When your computer is initially infected with CryptoLocker or other ransomware, you probably won’t notice much wrong. While your system is running, it will look at every data file it can find on every mapped drive it can find, all in the background without you suspecting. It will then encrypt each of those files using a key that only it knows. Those encryption keys are then sent off to a server owned by the crooks somewhere out in the Internet.

When CryptoLocker has finished encrypting all of your files – rendering them useless to you without the encryption key – it will then pop up a notice, letting you know that your files have been encrypted. That notice instructs you to send the crooks money via Bitcoin, Moneypak, or some other untraceable method. In effect, they’re holding your data hostage and demanding a ransom.

If you send them money, then supposedly the infection will then go back and unencrypt your files. Some people have had success doing this, while others have not and merely ended up spending money paying a ransom and still not getting their data back.

There are some things you can do to protect yourself, however.

  1. Always, always, always have a recent backup of everything on your computer and any servers at your organization. That backup should include historical backups, meaning that it keeps the last several versions because if all you’re keeping is the latest, you may very well just be backing up the unusable, encrypted version of your files.
  2. Make sure that your backups are replicated offsite. If your backups are accessible by your computer, they can be encrypted and then your backups are unusable.
  3. Windows should always be kept up to date with patches and fixes. Setting your computer to automatically update can help, but you’ll still be missing certain patches. The best method is to have a reputable IT firm or department manage this process.
  4. All utility programs such as Adobe Reader, Flash Player, Java, etc. should be kept up to date with patches and fixes. While CryptoLocker and other pieces of malware can make use of bugs in such programs, CryptoLocker sometimes gets installed by posing as a Flash Player update. It is best to have a reputable IT firm or department manage the update process for you.
  5. If you see a pop-up – particularly in a web browser – that tells you that you need to update your version of Flash Player, or Java, or similar, do NOT click on it! Most of the time, that’s bogus and will actually install CryptoLocker or other malware. If you see this, call your IT support people.
  6. Don’t log in with administrator privileges. On a network, it is likely that you’re not and are simply a standard user with limited rights, but even if this is your own computer or laptop, it is best to create a separate user with limited rights and use that for your daily work. While it won’t prevent an infection, it will prevent some things from running and will help prevent some methods of infection.
  7. Have a good, reputable antivirus program installed, be sure it is running properly, and be sure it is updated often. Some antivirus software vendors put out updates once a day, while some do it multiple times during the day. The quicker you can get updates, the more likely you’ll be protected from new attack methods.
  8. If a web page asks you to install something, NEVER allow it. Ever. Unless you’re being instructed to do something specific by your IT support provider.
  9. If you get an attachment via email, don’t open it unless it is something you’re expecting. If you’re not expecting something with an attachment, call or separately email (don’t just “reply”) to the original sender and ask if they intended to send you something. If it is from someone you don’t know, just delete it.
  10. TOR is a sort of "hidden" version of the Internet. It bypasses most normal controls, and is often used by CryptoLocker and other ransomware to avoid detection. While not easy to defeat, there are ways of stopping the use of TOR networks via a firewall, DNS, etc.
  11. Use a safe computing mindset. That is, don't go to likely unsafe web sites. While even a major website can get infected, or pop-up ads displayed on a major website can be infected, you are far less likely to get something from major, known sites than from questionable ones.

While there is no 100% sure-fire way to prevent against all types of ransomware, doing a few things can reduce your likelihood of getting infected and can reduce the impact if you do.