There are three things I'm afraid of, first me getting assosiated with he ransom, which can be no problem if someone investigate, then I just show them the whatsup conversation I had with this familly frind.
I don't think an outgoing transaction would get you in trouble, an incoming one may.
Second the ransom software will somehow learn who I am and will target me
Anyone with detect computer skills should be able to avoid this script-kiddie malware stuff online these days.
and third that they won't release the encrypted files and this friend will say I didn't pay them (I guess this can be avoided by sending the friend to the blockchain to view the transaction).
You have a fair point here. Get him to install Electrum or a similar SPV client. Additionally, I made a small edit that you didn't see:
Depending on the type of malware, it is possible to 'unlock' the system.
So what's the name on the ransom note?