[求救] 被CryptoDefense绑架

楼主: cfmusic (来赏山吧)   2014-04-15 11:43:50
1. 叙述问题:
在这里请依序详细说明你的电脑发生了什么事情,如果有图片、影片更好!
今天早上电脑开机后发现所有档案打不开
且所有的路径及资料夹中都出现一个"HOW_DECRYPT"的chrome连结 及 一个记事本档
将记事本档打开后出现下列文字
==================================
All files including videos, photos and documents on your computer are
encrypted by CryptoDefense Software.
Encryption was produced using a unique public key RSA-2048 generated for this
computer. To decrypt files you need to obtain the private key.
The single copy of the private key, which will allow you to decrypt the
files, located on a secret server on the Internet;
the server will destroy the key after a month. After that, nobody and never
will be able to restore files.
In order to decrypt the files, open your personal page on the site
https://rj2bocejarqnpuhm.browsetor.com/2hYh and follow the instructions.
If https://rj2bocejarqnpuhm.browsetor.com/2hYh is not opening, please follow
the steps below:
1. You must download and install this browser
http://www.torproject.org/projects/torbrowser.html.en
2. After installation, run the browser and enter the address:
rj2bocejarqnpuhm.onion/2hYh
3. Follow the instructions on the web-site. We remind you that the sooner you
do, the more chances are left to recover the files.
IMPORTANT INFORMATION:
Your Personal PAGE: https://rj2bocejarqnpuhm.browsetor.com/2hYh
Your Personal PAGE(using TorBrowser): rj2bocejarqnpuhm.onion/2hYh
Your Personal CODE(if you open site directly): 2hYh
=======================================================
上网查了一下得知这是一个绑架电脑档案的程式, 不汇钱档案就等著消失...
2. 系统资料:
使用的作业系统(如:Windows XP、Windows Vista)
使用的防毒软件
作业系统:Windows XP
防毒软件:江民
扫了没有用....也扫不到.....
因为这似乎是把档案加密而已 并非病毒? 可以这样讲吗?
3. 自行上网找似乎都无解....
因为该台电脑中灌有dropbox, 所以里头的档案也全被锁了...
其他台灌有同帐号dropbox的电脑也已经先把dropbox软件停用...目前还没中毒现象
目前非常头大....请问各位除了付钱还有其他解吗 感谢
作者: mmis1000 (秋月恋枫)   2014-04-15 11:57:00
dropbox里的档案应该有历史版本,所以还能从服务器救自己电脑上的大概就只能乖乖付钱了,付了会不会真的给你解也还是问题这种主动写入大量档案的异常行为,防毒应该都会挡才对阿没警告真的很诡异
作者: fish0112 (鱼)   2014-04-15 22:34:00
就..无解..
楼主: cfmusic (来赏山吧)   2014-04-16 08:57:00
谢谢 看来只能认栽了

Links booklink

Contact Us: admin [ a t ] ucptt.com