이거 랜섬웨어?그거 인가요ㅠㅠㅠ

이거 랜섬웨어?그거 인가요ㅠㅠㅠ

작성일 2015.12.31댓글 1건
    게시물 수정 , 삭제는 로그인 필요

어느 사이트에 들어갔다가 버벅대더니만 갑자기 영어로 뭐라고 되어있는 사이트뜨고 막 난리나길래 겁나서 바로 꺼버렸거든요??ㅠㅠㅠ 알약도 막 바이러스?사이트 같은거 감지했다며 경고하면서 사이트가 시행되는 것을 막았다고...

불안해서 막 찾아봤었는데 다행히 확장자가 vvv로 안 바꼈어요 후우..ㅠㅠ

근데 자꾸 이 노트북 킬때마다 계속 메모장이랑 그림이랑 이상한 사이트가 계속 뜨더라고요 어찌하면 없어질까요ㅠㅠㅠ

포멧하면 나아질련지요? 어차피 옮길건 이미 진작에 다 옮겨 놨어서 그닥 미련은 없걸랑요ㅎ

포멧말고도 수리할 수 있는 방법이 있다면 비용이 얼마정도??ㅠㅠ

(글이 너무 긴것 같아서 컴퓨터 사양 댓으로 남길게요!!)

 

<사이트 주소>

C:\Documents and Settings\kim\시작 메뉴\프로그램\시작프로그램\HELP_YOUR_FILES.HTML

 

<그림>


 

 

 

<메모장 내용>

 Cannot you find the files you need? Is the content of the files that you have watched not readable?
It is normal because the files’ names, as well as the data in your files have been encrypted.

Congratulations!!!
You have become a part of large community #CryptoWall.
---

If you are reading this text that means that the software CryptoWall has removed from your computer.

---

What is encryption?
Encryption is a reversible transformation of information in order to conceal it from unauthorized persons but providing at the same time access to it for authorized users. To become an authorized user and make the process truly reversible i.e. to be able to decrypt your files you need to have a special private key.
In addition to the private key you need the decryption software with which you can decrypt your files and return everything in its place.

---

I almost understood but what do I have to do?
The first thing you should do is to read the instructions to the end.

Your files have been encrypted with the CryptoWall software; the instructions that you find in folders with encrypted files are not viruses, they are your helpers.
After reading this text 100% of people turn to a search engine with the word CryptoWall where you'll find a lot of thoughts, advice and instructions.
Think logically - we are the ones who closed the lock on your files and we are the only ones who have this mysterious key to open them.
Any of your attempts to restore your files with the third-party tools can be fatal for encrypted files.
The fact is that changing data within the encrypted file (as 100% of software to restore files do this, except the special decryption software) you break damage to the file and it will be impossible to decrypt the file.
This is the same as to collect a mosaic when some mosaics items were lost, broken or not put in its place - the picture will not emerge, the software to restore the files will not be able to lay down the picture, and ruin it completely and irreversibly.
Using the software to restore files can ruin your files forever, only through your fault.
Remember that any intervention of the extraneous software to restore files encrypted with the Cryptowall software may be the point of no return.

---

In case if these simple rules are violated we will not able to help you, and we will not try because you have been warned.
For your attention the software to decrypt the files (as well as the private key that come fitted with it) is a paid product.
After purchasing the software package you can:
1. Decrypt all your files.
2. Work with your documents.
3. View your photos and other media content.
4. Continue your habitual and comfortable work at the computer.
If you are aware whole importance and criticality of the situation, then we suggest you go directly to your personal page where you will be given final instructions, as well as guarantees to restore your files.

There is a list of addresses below through which you can get on your personal page:
1.3wzn5p2yiumh7akj.waytopaytosystem.com/LjdNRR
2.3wzn5p2yiumh7akj.malkintop100.com/LjdNRR
3.3wzn5p2yiumh7akj.belladonnamonna.com/LjdNRR
4.3wzn5p2yiumh7akj.hiltonpaytoo.com/LjdNRR

What do you have to do with these addresses?

If you browse the instructions in TXT format (if you have instruction in HTML (the file that has an icon of your Internet browser) then for the sake of simplicity it is better to run it):
1. Look at the address number 1 (in this case it is 3wzn5p2yiumh7akj.waytopaytosystem.com/LjdNRR).
2. Select it with the mouse cursor holding the left mouse button and moving the cursor to the right.
3. Release the left mouse button and press the right one.
4. In the menu that appears select “Copy”.
5. Run your Internet browser (if you do not know what it is run the Internet Explorer).
6. Move the mouse cursor to the address bar of the browser (this is the place where the site address is written).
7. Click the right mouse button in the field where the site address is written.
8. In the menu that appears select the button “Insert”.
9. The address 3wzn5p2yiumh7akj.waytopaytosystem.com/LjdNRR must appear there.
9. Press ENTER.
10. The site must load; if it does not load, repeat the same instructions with the address number 2 and so on until the final address if falling.

If for some reason the site does not open check the connection to the Internet; if the site still does not open see the instructions on omitting the point about working with the addresses in the HTML and PNG instructions.
If you browse the instructions in HTML format:
1. Click the left mouse button on the address number 1 (in this case it is 3wzn5p2yiumh7akj.waytopaytosystem.com/LjdNRR).
2. In a new tab or window of your web browser the site must load; if it does not load, repeat the same instructions with the address number 2 and so on until the final address/.
If for some reason the site does not open check the connection to the Internet; if the site still does not open see the instructions on omitting the point about working with the addresses in the PNG instructions.

If you browse the instructions in PNG format:
1. We are very sorry but unfortunately your antivirus deleted instructions files in the TXT and HTML format for your comfortable work and most importantly for help to restore access to your files.
2. Try to enter the address of your page manually from a picture, good luck and patience for you.

Unfortunately, these sites are temporary because the antivirus companies are interested that you cannot restore your files but continue to buy their products.
Unlike them we are ready to help you always.
If the temporary sites are not available and you need our help:
1. Run your Internet browser (if you do not know what it is run the Internet Explorer).
2. Enter or copy the address into the address bar https://www.torproject.org/download/download-easy.html.en your browser and press ENTER.
3. Wait for the site loading
4. On the site you will be offered to download TorBrowser; download and run it, follow the installation instructions, wait until the installation is completed.
5. Run Tor-Browser.
6. Connect with the button Connect (if you use the English version).
7. After initialization a normal Internet browser window will be opened.
8. Type or copy the address 3wzn5p2yiumh7akj.onion/LjdNRR in this browser address bar.
9. If for some reason the site is not loading, wait a moment and try again.

If you have any problems during installation or operation of TorBrowser, please, visit www.youtube.com and type request in the search bar “install tor browser windows”. As a result you will see a training video on TorBrowser installation and operation.

If TOR address was unavailable for a long time (2-3 days) it means you were late; on average you have about 2 weeks after reading the instructions to restore your files.

---

Additional information:
Instructions to restore your files are only in those folders where you have encrypted files.
For your convenience the instructions are made in three file formats - html, txt, and png.
Unfortunately, antivirus companies cannot protect and moreover restore your files but they make things worse removing the instructions to restore encrypted files.
The instructions are not malwares; they have informative nature only, so any claims on the absence of any instruction files you can send to your antivirus company.

---

CryptoWall Project is not malicious and is not intended to harm a person and his/her information data.
The project is conducted for the sole purpose of instruction in the field of information security, as well as certification of antivirus products for their suitability for data protection.
Together we make the Internet a better and safer place.
----------
If you oversee this text in the Internet and understand that something is wrong with your files and you have no instructions to restore the files, contact your antivirus support.
----------
Remember that the worst has already happened and now the further life of your files depends directly on your determination and speed of your actions.

 

 



profile_image 익명 작성일 -

아마도 랜섬웨어(Ransomware) 악성코드가 파일 암호화를 시도하던 중 알약이 차단한 듯 합니다.

하지만 악성 파일이 제거된 것은 아닌 것 같으므로 신고하기 기능으로 반드시 신고해서 악성 파일을 찾아 제거하시기 바랍니다.

참고로 제거 방법은 http://hummingbird.tistory.com/6230 내용을 참고하여 알약 이벤트 로그에 찍힌 악성 파일을 찾아 삭제하시기 바랍니다.

또한 메시지 제거 도구(http://cafe.naver.com/malzero/113930)를 사용해 보시기 바랍니다.

랜섬웨어 Trojan:Win32/Malagent!MSR

... 일단 이거 보고나서 혹시싶어서 전체검사는 돌려봤어요 별 문제 없는거 맞나요???... 트로이목마 랜섬웨어라길래 불안하고 찝찝해서 물어봅니다ㅠㅠㅠ;;; 인뱅은 걍 써도...

이거 랜섬웨어인가여?

갑자기 원래 있던 한글파일이랑, pdf파일이 깨져요 근데 새로 파일을 만들면 그건 정상적이에요 유튜브 보니까 랜섬웨어?라던데 그건가요? 그리고 만약 그거면 어떻게 고치나요?...

랜섬웨어....

사남매의 추억이 가득한 컴퓨터가 랜섬웨어에 걸맂거 같아요... 이거 어찌해야하나요ㅠㅠㅠ 풀수 있나요..? ㅜㅠㅠㅠㅠㅠ 랜섬웨어에 감염된 경우, 일반적으로 파일을...

이거 랜섬웨어 걸리나요?ㅠㅠㅠ

... 걸리면 어떻게 해야 하나요 급해요 ㅠㅠㅠㅠ 안녕하세요. 한국랜섬웨어침해대응센터입니다. 현재 랜섬웨어의 감염경로는 매우 다양해서 유투브 추출사이트에서 노래를...

랜섬웨어 관련 질문입니다

... exe 가 랜섬웨어 공격시도를 했다네요 그래서 v3로 검사도 했는데 그건 또 별로... 답해주세요 ㅠㅠㅠ 랜섬웨어 감염이 아닙니다. 지금 현재 알약 오진 현상이 진행되고...

랜섬웨어인가요 해킹인거요 ㅠㅠ?

이거 랜섬웨어인가요ㅠ? 길어도 사람 살리는 셈 치고 한번만 읽어주세요ㅠㅠ... 부탁드립니다 ㅠㅠㅠ 1. 처음에 컴퓨터를 켰을 때 이름 모를 파일 950개가 어디론가...

@@WfM 이거랜섬웨어인가요?

... 랜섬웨어를 유인하려고 알약이 만든 디코이 폴더입니다. 그걸 없애면 알약의 랜섬웨어 탐지 기능이 떨어집니다. 관련 참고 글 링크- https://hummingbird.tistory.com/6230 " " <