LPACMQ 发表于 2019-8-13 20:02

求助,中了勒索病毒扩展名NewCore要求支付比特币

本帖最后由 LPACMQ 于 2019-8-14 08:26 编辑

All your files have been blocked for more information, please contact us by e-mail.

E-Mail: info_newcore@p-security.liand info_newcore@protonmail.com
You PC id: ehpeq8

The faster you contact us the faster we can help you.

黑客发回的邮件如下

Your files are encrypted because you don't give enough attention to the safety of your system.

To decrypt your data, you must to pay us. After payment we will send to you personal decoder.

We are not liars or cheaters. You pay - we help.

The more time you wait before you pay = the more expensive price. It's simple. Be reasonable.

Now the price is 700$ after 48 hours 1400$. The price will grow. Hurry up!

Payment is made only in BITCOIN or DASH!


How to obtain Bitcoins

The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.

https://localbitcoins.com/buy_bitcoins

Also you can find other places to buy Bitcoins and beginners guide here:

http://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!

write to Google how to buy Bitcoin in your country?


How to obtain DASH

The easiest way to buy DASH

https://www.dash.org/where-to-buy/

Attention!

write to Google how to buy Bitcoin in your country?


Our Bitcoin wallet - 3KZJeLqDQi5i2ybZiezehhfxAcqCjDAnG7

Our Bitcoin wallet - 3KZJeLqDQi5i2ybZiezehhfxAcqCjDAnG7


Our DASH wallet - XxXvuHfvDNvEuSzZpxUxkVrGJhjdSSWgbU

Our DASH wallet - XxXvuHfvDNvEuSzZpxUxkVrGJhjdSSWgbU


if you afraid - you can send three files for test decrypting.

we don't decrypt ".exe" files, databases, and backups for test(read: for free),

you can send another files like jpg pdf xls doc and other. Total max size of files is 5 mb.

but don't forget - time is running out.

Your wish to get test files don't affect on the discount time. Only send files via e-mail.






┅┅┅? Original Message ┅┅┅?




All your files have been blocked for more information, please contact us by e-mail.


E-Mail: info_newcore@p-security.liand info_newcore@protonmail.com

You PC id: ehpeq8
中毒后整个局域网都是这样,整个共享盘的资料全部被黑






YuniNan0 发表于 2019-8-13 20:23

推荐楼主使用火绒安全软件

LPACMQ 发表于 2019-8-13 21:59

本帖最后由 LPACMQ 于 2019-8-13 22:03 编辑

hurted 发表于 2019-8-13 21:01
txt文件,也要上传。光上传中毒文件没用。无法解开。
txt文件是什么?

下面这几行就是截图那里txt的内容

All your files have been blocked for more information, please contact us by e-mail.

E-Mail: info_newcore@p-security.liand info_newcore@protonmail.com
You PC id: ehpeq8

The faster you contact us the faster we can help you.

战言灬永不败 发表于 2019-8-13 20:23

楼主试试论坛里的解密工具行不行

mp123456 发表于 2019-8-13 20:34

难道不是先提供样本吗

zerzul 发表于 2019-8-13 20:44

试试火绒呢

hurted 发表于 2019-8-13 21:01

txt文件,也要上传。光上传中毒文件没用。无法解开。

jsgyhy 发表于 2019-8-13 21:34

怕怕啊,知道中的原因吗?

ericwise 发表于 2019-8-13 21:59

怎么中的毒啊?重要资料没备份的话就难受了。

LPACMQ 发表于 2019-8-13 22:01

战言灬永不败 发表于 2019-8-13 20:23
楼主试试论坛里的解密工具行不行

我试过了,无效
页: [1] 2
查看完整版本: 求助,中了勒索病毒扩展名NewCore要求支付比特币