[求救] 被CryptoDefense綁架

作者: cfmusic (來賞山吧)   2014-04-15 11:43:50
1. 敘述問題:
在這裡請依序詳細說明你的電腦發生了什麼事情,如果有圖片、影片更好!
今天早上電腦開機後發現所有檔案打不開
且所有的路徑及資料夾中都出現一個"HOW_DECRYPT"的chrome連結 及 一個記事本檔
將記事本檔打開後出現下列文字
==================================
All files including videos, photos and documents on your computer are
encrypted by CryptoDefense Software.
Encryption was produced using a unique public key RSA-2048 generated for this
computer. To decrypt files you need to obtain the private key.
The single copy of the private key, which will allow you to decrypt the
files, located on a secret server on the Internet;
the server will destroy the key after a month. After that, nobody and never
will be able to restore files.
In order to decrypt the files, open your personal page on the site
https://rj2bocejarqnpuhm.browsetor.com/2hYh and follow the instructions.
If https://rj2bocejarqnpuhm.browsetor.com/2hYh is not opening, please follow
the steps below:
1. You must download and install this browser
http://www.torproject.org/projects/torbrowser.html.en
2. After installation, run the browser and enter the address:
rj2bocejarqnpuhm.onion/2hYh
3. Follow the instructions on the web-site. We remind you that the sooner you
do, the more chances are left to recover the files.
IMPORTANT INFORMATION:
Your Personal PAGE: https://rj2bocejarqnpuhm.browsetor.com/2hYh
Your Personal PAGE(using TorBrowser): rj2bocejarqnpuhm.onion/2hYh
Your Personal CODE(if you open site directly): 2hYh
=======================================================
上網查了一下得知這是一個綁架電腦檔案的程式, 不匯錢檔案就等著消失...
2. 系統資料:
使用的作業系統(如:Windows XP、Windows Vista)
使用的防毒軟體
作業系統:Windows XP
防毒軟體:江民
掃了沒有用....也掃不到.....
因為這似乎是把檔案加密而已 並非病毒? 可以這樣講嗎?
3. 自行上網找似乎都無解....
因為該台電腦中灌有dropbox, 所以裡頭的檔案也全被鎖了...
其他台灌有同帳號dropbox的電腦也已經先把dropbox軟體停用...目前還沒中毒現象
目前非常頭大....請問各位除了付錢還有其他解嗎 感謝
作者: mmis1000 (秋月戀楓)   2014-04-15 11:57:00
dropbox裡的檔案應該有歷史版本,所以還能從伺服器救自己電腦上的大概就只能乖乖付錢了,付了會不會真的給你解也還是問題這種主動寫入大量檔案的異常行為,防毒應該都會擋才對阿沒警告真的很詭異
作者: fish0112 (魚)   2014-04-15 22:34:00
就..無解..
作者: cfmusic (來賞山吧)   2014-04-16 08:57:00
謝謝 看來只能認栽了

Links booklink

Contact Us: admin [ a t ] ucptt.com