[求救] wanadecryptor勒索病毒
打擾了
我是W7使用者,安裝後搭配avast使用,系統一直沒升級過
最近每天只是用電腦上兩個小時左右的網,只上FB bilibili 巴哈 disp
今天防毒一直警告C/WINDOWS下有個MSS***.exe的檔案有問題(*號是我不記得的字母)
點防毒也只建議我作開機掃描,我執行智能掃描以及特定資料夾掃描都一無所獲,就以為是誤報
因為一直跳警告很吵,妨礙我看影片就耍笨關掉防護,結果過一會發現桌面放的文件被加密,還有勒索聲明及金額的文件檔
一時心慌我就關機,剛剛斷網重開機在執行開機掃描,現在偵測到這一步,我不知該怎麼執行?也不知該怎麼救檔案
求意見
http://i.imgur.com/A9dHVfB.jpg
半年的創作都毀了...
-----
Sent from JPTT on my Asus ASUS_T00F.
--
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 114.42.234.10
※ 文章網址: https://www.ptt.cc/bbs/AntiVirus/M.1494600425.A.ADA.html
→
05/12 22:48, , 1F
05/12 22:48, 1F
→
05/12 22:49, , 2F
05/12 22:49, 2F
→
05/12 22:49, , 3F
05/12 22:49, 3F
→
05/12 22:49, , 4F
05/12 22:49, 4F
→
05/12 22:50, , 5F
05/12 22:50, 5F
推
05/12 22:54, , 6F
05/12 22:54, 6F
→
05/12 22:54, , 7F
05/12 22:54, 7F
→
05/12 22:55, , 8F
05/12 22:55, 8F
→
05/12 22:55, , 9F
05/12 22:55, 9F
推
05/12 23:06, , 10F
05/12 23:06, 10F
因為他偵測的警告只能引導到智能掃描,而智能掃描又沒有結果
針對同個資料夾掃也掃不到毒,同時又一直跳提示
就疑惑那到底是有沒有毒可殺?
推
05/12 23:07, , 11F
05/12 23:07, 11F
→
05/12 23:07, , 12F
05/12 23:07, 12F
→
05/12 23:07, , 13F
05/12 23:07, 13F
F8安全模式跟你這個方法比,哪個比較穩呢?
系統還原有用嗎
話說我發文主要是因為,現在Avast卡在開機掃描的這麼頁面
我想問它是在問甚麼?建議該執行哪個動作好?
※ 編輯: Omlet (114.42.228.216), 05/12/2017 23:10:51
→
05/12 23:08, , 14F
05/12 23:08, 14F
→
05/12 23:11, , 15F
05/12 23:11, 15F
推
05/12 23:13, , 16F
05/12 23:13, 16F
→
05/12 23:14, , 17F
05/12 23:14, 17F
推
05/12 23:16, , 18F
05/12 23:16, 18F
→
05/12 23:16, , 19F
05/12 23:16, 19F
→
05/12 23:16, , 20F
05/12 23:16, 20F
→
05/12 23:16, , 21F
05/12 23:16, 21F
推
05/12 23:21, , 22F
05/12 23:21, 22F
那我該選哪個好呢?現在該砍了病毒再退出用別的OS開機,然後...?
我想了幾個方案:
1. 系統還原看看
2. 找看台北市有什麼解資料勒索的救援公司(但這病毒若很新,應該只能暴力嘗試?)
老實說剛剛關機前有緊急看了一下放創作用PSD的資料夾,依稀是都加密了...
剛剛爬了M01那篇文,沒有任何一家防毒公司的解密工具有解這支病毒的...
我這難道是伊莉那隻嗎...現在一整個厭世
※ 編輯: Omlet (114.42.228.216), 05/12/2017 23:30:49
推
05/12 23:33, , 23F
05/12 23:33, 23F
推
05/12 23:38, , 24F
05/12 23:38, 24F
推
05/12 23:40, , 25F
05/12 23:40, 25F
推
05/12 23:42, , 26F
05/12 23:42, 26F
→
05/12 23:42, , 27F
05/12 23:42, 27F
→
05/12 23:42, , 28F
05/12 23:42, 28F
我是沒放桌面,但怕已經吃到F槽...
我的配置是SSD*1(C D)HDD*1(E F),其中F是放重要資料的
※ 編輯: Omlet (114.42.228.216), 05/12/2017 23:46:30
→
05/12 23:46, , 29F
05/12 23:46, 29F
※ 編輯: Omlet (114.42.228.216), 05/12/2017 23:46:46
推
05/12 23:48, , 30F
05/12 23:48, 30F
推
05/12 23:48, , 31F
05/12 23:48, 31F
→
05/12 23:48, , 32F
05/12 23:48, 32F
推
05/12 23:49, , 33F
05/12 23:49, 33F
→
05/12 23:50, , 34F
05/12 23:50, 34F
推
05/12 23:51, , 35F
05/12 23:51, 35F
推
05/12 23:52, , 36F
05/12 23:52, 36F
→
05/12 23:52, , 37F
05/12 23:52, 37F
剛剛掃到F槽,30幾本舊相簿的JPG都被加密為.WNCRY,心好痛...
後面有些.NEF的攝影原檔,似乎因為格式關係,沒被改檔名
目前還在等開機掃描完成......
※ 編輯: Omlet (114.42.228.216), 05/13/2017 00:08:47
→
05/13 00:13, , 38F
05/13 00:13, 38F
推
05/13 00:53, , 39F
05/13 00:53, 39F
推
05/13 01:12, , 40F
05/13 01:12, 40F
噓
05/13 01:30, , 41F
05/13 01:30, 41F
→
05/13 01:42, , 42F
05/13 01:42, 42F
→
05/13 01:48, , 43F
05/13 01:48, 43F
→
05/13 02:09, , 44F
05/13 02:09, 44F
推
05/13 04:42, , 45F
05/13 04:42, 45F
推
05/13 05:26, , 46F
05/13 05:26, 46F
噓
05/13 07:35, , 47F
05/13 07:35, 47F
噓
05/13 07:54, , 48F
05/13 07:54, 48F
噓
05/13 10:06, , 49F
05/13 10:06, 49F
→
05/13 10:06, , 50F
05/13 10:06, 50F
推
05/13 11:22, , 51F
05/13 11:22, 51F
→
05/13 11:23, , 52F
05/13 11:23, 52F
→
05/13 11:57, , 53F
05/13 11:57, 53F
推
05/13 12:28, , 54F
05/13 12:28, 54F
→
05/13 12:28, , 55F
05/13 12:28, 55F
噓
05/13 15:56, , 56F
05/13 15:56, 56F
→
05/13 16:49, , 57F
05/13 16:49, 57F
→
05/13 17:19, , 58F
05/13 17:19, 58F
→
05/13 17:19, , 59F
05/13 17:19, 59F
推
05/13 18:12, , 60F
05/13 18:12, 60F
→
05/14 19:38, , 61F
05/14 19:38, 61F
推
05/15 17:30, , 62F
05/15 17:30, 62F
→
05/15 17:31, , 63F
05/15 17:31, 63F