搞不好KEY也同時存在硬碟裡

luzibin wrote:
上周三上午我公司電腦所有檔案都能正常運作,下午請假,隔天上午來上班,發現我常用的 EXCEL、WORD、PDF、TXT 、JPG等檔案,不是打開變亂碼,就是無法開啟,然後仔細查看我電腦連線的主機硬碟,只要是有檔案的目錄,全部都有以下這四個檔案:
HELP_DECRYPT.HTML
HELP_DECRYPT.png
HELP_DECRYPT.txt
HELP_DECRYPT
然後點HELP_DECRYPT.txt,就出現以下的文字說明
What happened to your files ?
All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0.
More information about the encryption keys using RSA-2048 can be found here: http://en.wikipedia.org/wiki/RSA_(cryptosystem)
What does this mean ?
This means that the structure and data within your files have been irrevocably changed, you will not be able to work with them, read them or see them,
it is the same thing as losing them forever, but with our help, you can restore them.
How did this happen ?
Especially for you, on our server was generated the secret key pair RSA-2048 - public and private.
All your files were encrypted with the public key, which has been transferred to your computer via the Internet.
Decrypting of your files is only possible with the help of the private key and decrypt program, which is on our secret server.
What do I do ?
Alas, if you do not take the necessary measures for the specified time then the conditions for obtaining the private key will be changed.
If you really value your data, then we suggest you do not waste valuable time searching for other solutions because they do not exist.
For more specific instructions, please visit your personal home page, there are a few different addresses pointing to your page below:
1.http://7oqnsnzwwnm6zb7y.payoptionserver.com/
利用有限的英文能力,看來就大事不妙,果然用GOOGLE翻譯一下,我中鏢了,這病毒只能給你免費解一個小於512KB的檔案,其他的檔案只要他有辦法加密,就全部加密,然後刪除原檔案,我問過IT,他說這個病毒有江湖道義,一段時間內只要付相當於500美金的比特幣,他就送你解密程式,超過那段時間,就變成1000美金。我選擇先解開一個小於512KB的檔案,然後剩下的就全送給他,一切重新來過。
這個病毒給我一個教訓,自己辛辛苦苦做的檔案,一定要備份,最好再加密碼保護被複寫,不過我也看開了,如果真的有備份,心中還是要有檔案不見的最壞打算。
luzibin wrote:
上周三上午我公司電...(恕刪)