{"id":2224,"date":"2021-05-23T00:12:35","date_gmt":"2021-05-23T00:12:35","guid":{"rendered":"https:\/\/jimhphoto.com\/?p=2224"},"modified":"2022-02-23T01:18:07","modified_gmt":"2022-02-23T01:18:07","slug":"windows-10-ransomware-protection","status":"publish","type":"post","link":"https:\/\/jimhphoto.com\/index.php\/2021\/05\/23\/windows-10-ransomware-protection\/","title":{"rendered":"Windows 10 Ransomware protection"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">I got hit by ransomware once, maybe 10 years ago.  All the files on my hard drive &#8211; except for the Windows installation &#8211;  disappeared, and a popup asked for a VISA number.   It&#8217;s about the most aggravating thing you can think of.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware wasn&#8217;t as sophisticated back then; this one just set the &#8216;hidden&#8217; attribute on my files, and I was eventually able to get them all back.  Today,  they&#8217;d be encrypted and I wouldn&#8217;t have a chance.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Windows 10 has built-in protection against ransomware<\/strong>, but by default, it&#8217;s <em>turned off.<\/em>   Maybe that&#8217;s because it&#8217;s intended for corporate IT, and they don&#8217;t want to deal with supporting it for ordinary users.  It&#8217;s a bit techy, and the interface is pretty bad, but it&#8217;s serious protection and doesn&#8217;t complicate your life once it&#8217;s set up.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What it does is monitor file accesses in folders you specify, and if the program requesting the access isn&#8217;t on a white list you created, it gets denied.   Any program can still read a file in those folders, or create a new one, but it can&#8217;t modify an existing file unless you&#8217;ve approved it.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That sounded good.   The only stuff I worry about is my photography work, and some personal documents; anything else I can just reinstall if necessary.   So I went through the setup and enabled the protection.  And here&#8217;s a step-by-step which will save you some time and aggravation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Start with Win-Q  (the Windows key and &#8220;Q&#8221;) and enter &#8220;Ransomware Protection&#8221;.<\/strong>  You&#8217;ll  get this:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture3-1024x798.jpg\" alt=\"\" class=\"wp-image-2219\" width=\"512\" height=\"399\" srcset=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture3-1024x798.jpg 1024w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture3-300x234.jpg 300w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture3-768x598.jpg 768w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture3-1536x1196.jpg 1536w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture3.jpg 1786w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\\<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Set &#8220;Controlled folder access&#8221; to &#8220;On&#8221;, with the switch. Then click &#8220;Protected folders&#8221; to get this:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture4-1024x796.jpg\" alt=\"\" class=\"wp-image-2220\" width=\"512\" height=\"398\" srcset=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture4-1024x796.jpg 1024w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture4-300x233.jpg 300w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture4-768x597.jpg 768w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture4-1536x1194.jpg 1536w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Capture4.jpg 1790w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Clicking &#8220;Add a protected folder&#8221; brings up a  File Explorer;  choose a folder you want to protect,  and click &#8220;Select Folder&#8221; at the bottom of the Explorer window. As you do this for each folder, they&#8217;ll show up in the list.  Some common folders are already there by default.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Next you specify the programs (executable files) that will be allowed to modify files in those folders.   Click the &#8220;back&#8221; arrow at the upper left corner to return to the main Ransomware Protection screen (previous image above), and click on &#8220;Allow an app through Controlled folder access&#8221;.   Ignoring the fractured grammar, what this lets you do is browse for an executable and add it to the approved list.   And that&#8217;s a bit of a pain, because those executables are buried deep under Program Files, and you may not know their names.  In fact, an application may have multiple executables under the hood &#8211; for example, many image processing programs use ExifTool.exe for metadata access.   So forget that route, there&#8217;s an easier way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you just go ahead and use a program that tries to write a protected file, you&#8217;ll get a popup like this:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-110024.jpg\" alt=\"\" class=\"wp-image-2231\" width=\"396\" height=\"162\"\/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You might think this popup will give you an option to approve the program on the spot &#8211; dream on, that would be too easy.   Click on the popup and you get this, which at first glance makes no sense:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184528-1024x797.jpg\" alt=\"\" class=\"wp-image-2222\" width=\"512\" height=\"399\" srcset=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184528-1024x797.jpg 1024w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184528-300x233.jpg 300w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184528-768x598.jpg 768w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184528-1536x1195.jpg 1536w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184528.jpg 1776w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But you&#8217;re almost there.  You&#8217;re seeing a list of blocked access attempts, and <em>the one that just occurred is on top of the list<\/em>.  Click it, and you&#8217;ll  get another popup:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184614.jpg\" alt=\"\" class=\"wp-image-2223\" width=\"283\" height=\"391\" srcset=\"https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184614.jpg 565w, https:\/\/jimhphoto.com\/wp-content\/uploads\/2021\/05\/Screenshot-2021-05-21-184614-217x300.jpg 217w\" sizes=\"auto, (max-width: 283px) 100vw, 283px\" \/><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">And <em>finally<\/em>: the Actions dropdown includes an option to &#8220;&#8221;allow on this device&#8221;.   Click that, and the program is whitelisted.   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Repeat this for each application you want to allow, and you&#8217;re set.  Note that you won&#8217;t get the warning until the program actually tries to modify and save a file, not when it&#8217;s first opened; so be prepared to run the fire drill described above or you&#8217;ll lose your work.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I got hit by ransomware once, maybe 10 years ago. All the files on my hard drive &#8211; except for the Windows installation &#8211; disappeared, and a popup asked for a VISA number. It&#8217;s about the most aggravating thing you can think of.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[651],"tags":[],"post_folder":[],"class_list":["post-2224","post","type-post","status-publish","format-standard","hentry","category-photo-tech"],"_links":{"self":[{"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/posts\/2224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/comments?post=2224"}],"version-history":[{"count":0,"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/posts\/2224\/revisions"}],"wp:attachment":[{"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/media?parent=2224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/categories?post=2224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/tags?post=2224"},{"taxonomy":"post_folder","embeddable":true,"href":"https:\/\/jimhphoto.com\/index.php\/wp-json\/wp\/v2\/post_folder?post=2224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}