POZOR na nějakého hajzla!!!
Napsal: 13 úno 2014 01:38
Na ext. HDD mi "něco" uzamklo větší množství souborů. Všechny mají za orig. příponou ještě jednu "LOCKED". A v každém adresáři, kde se nacházejí tyto zamčené soubory, přibyl ještě jeden texťák s příponou LOCKED. V něm je napsáno, abych si stáhl Tor a z něho otevřel uvedenou stránku, kde se dozvídám, že mi zamknul soubory a pokud mu do pěti dnů nepošlu nějaké Bitcoiny, tak mi nepošle klíč od těch zamčených souborů. Přikládám orig. text oné výzvy k zaplacení a log z RogueKiller a prosím jeho kontrolu.
===========================================================================================
Your files are locked and encrypted with a unique RSA-1024 key!
To regain access you have to obtain the private key (password).
++++++++++++++++++++
To receive your private key (password):
Go to hxxp://u5ubeuzamg54x5f3.onion.to and follow the instructions.
You will receive your private key (password) within 24 hours.
Your ID# is 28403489
If you can't find the page, install the Tor browser (hxxps://www.torproject.org/projects/torbrowser.html.en) and browse to
hxxp://u5ubeuzamg54x5f3.onion
++++++++++++++++++++
BEWARE - this is NOT a virus.
The ONLY way to unlock your files/data is to obtain your private key (password) or you may consider all your data lost.
You have just 5 days before the private key (password) is deleted from our server, leaving your data irrevocably broken.
++++++++++++++++++++
LOCKED ON POSSESSION OF COPYRIGHTED MATERIAL AND SUSPICION OF (CHILD)PORNOGRAPHIC MATERIAL.
===========================================================================================
RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Online [Práva správce]
Mód : Kontrola -- Datum : 02/13/2014 00:59:13
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : NextLive (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Online\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l [7][-][x]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-2000478354-682003330-1177238915-1004\[...]\Run : NextLive (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Online\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l [7][-][x]) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 2 ¤¤¤
[All Users][SUSP UNIC] Bluetooth.lnk : C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk [-] -> NALEZENO
[All Users][SUSP UNIC] Windows Search.lnk : C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk [-] -> NALEZENO
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Inline] EAT @firefox.exe (LdrLoadDll) : ntdll.dll -> HOOKED (C:\Program Files\Mozilla Firefox\mozglue.dll @ 0x10001FFD)
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HM100JC +++++
--- User ---
[MBR] 8b0257836674089172f89a21593946c8
[BSP] 98df373da9cfd9eb0294c90d1716c5cd : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 95385 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) StoreJet Transcend USB Device +++++
--- User ---
[MBR] 4d89696ef6a53561efe5b5138298e4bf
[BSP] e814dd6c275bec56aca7d58b7c61466d : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 56 | Size: 953867 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] Po?adavek není podporován. )
Dokončeno : << RKreport[0]_S_02132014_005913.txt >>
RKreport[0]_S_02132014_003124.txt

===========================================================================================
Your files are locked and encrypted with a unique RSA-1024 key!
To regain access you have to obtain the private key (password).
++++++++++++++++++++
To receive your private key (password):
Go to hxxp://u5ubeuzamg54x5f3.onion.to and follow the instructions.
You will receive your private key (password) within 24 hours.
Your ID# is 28403489
If you can't find the page, install the Tor browser (hxxps://www.torproject.org/projects/torbrowser.html.en) and browse to
hxxp://u5ubeuzamg54x5f3.onion
++++++++++++++++++++
BEWARE - this is NOT a virus.
The ONLY way to unlock your files/data is to obtain your private key (password) or you may consider all your data lost.
You have just 5 days before the private key (password) is deleted from our server, leaving your data irrevocably broken.
++++++++++++++++++++
LOCKED ON POSSESSION OF COPYRIGHTED MATERIAL AND SUSPICION OF (CHILD)PORNOGRAPHIC MATERIAL.
===========================================================================================
RogueKiller V8.8.7 [Feb 11 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com
Operační systém : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v : Normální režim
Uživatel : Online [Práva správce]
Mód : Kontrola -- Datum : 02/13/2014 00:59:13
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : NextLive (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Online\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l [7][-][x]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-2000478354-682003330-1177238915-1004\[...]\Run : NextLive (C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Online\Data aplikací\newnext.me\nengine.dll",EntryPoint -m l [7][-][x]) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 2 ¤¤¤
[All Users][SUSP UNIC] Bluetooth.lnk : C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk [-] -> NALEZENO
[All Users][SUSP UNIC] Windows Search.lnk : C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Search.lnk [-] -> NALEZENO
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Browser Addons : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Inline] EAT @firefox.exe (LdrLoadDll) : ntdll.dll -> HOOKED (C:\Program Files\Mozilla Firefox\mozglue.dll @ 0x10001FFD)
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) SAMSUNG HM100JC +++++
--- User ---
[MBR] 8b0257836674089172f89a21593946c8
[BSP] 98df373da9cfd9eb0294c90d1716c5cd : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 95385 Mo
User = LL1 ... OK!
User = LL2 ... OK!
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) StoreJet Transcend USB Device +++++
--- User ---
[MBR] 4d89696ef6a53561efe5b5138298e4bf
[BSP] e814dd6c275bec56aca7d58b7c61466d : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 56 | Size: 953867 Mo
User = LL1 ... OK!
Error reading LL2 MBR! ([0x32] Po?adavek není podporován. )
Dokončeno : << RKreport[0]_S_02132014_005913.txt >>
RKreport[0]_S_02132014_003124.txt