本帖最后由 Love彡丶小笨笨 于 2023-12-24 22:14 编辑中了..mkp勒索病毒,用群晖挂载着虚拟机下东西,虚拟机是开了公网远程,密码和密码提示是一样的,但是端口改了不是默认的,虚拟机把群晖里的文件映射到了进去了,前几天还远程连接虚拟机显示密码错误还纳闷咋回事呢,没往这想,过了几天用pe重置了密码进去才发现中勒索病毒了,群晖有个共享文件夹加密,结果今天打开发现了群晖加密的文件也全都被加密了,但是小姐姐也是群晖加密的但是没被感染,这么多年所有重要的照片视频文件啥的全都毁于一旦。看了下文件修改记录2g多t的文件加密前后加密花了4天时间,黑客改密码估计就是为了延缓发现的时间,让文件能彻底加密,要是当时就关机损失没这么严重了。之前太信任群晖了,想着群晖的风险最大不过硬盘坏了吗,组raid就能解决,没考虑到有这个风险,现在感觉对咱这种小白来说网盘更安全,群晖能被攻破的地方太多了,重要文件得异地备份。
::: Greetings :::
Little FAQ:
Q: Whats Happen?
A: Your files have been encrypted. The file structure was not damaged, we did everything possible so that this could not happen.
Q: How to recover files?
A: If you wish to decrypt your files you will need to pay us.
Q: What about guarantees?
A: Its just a business. We absolutely do not care about you and your deals, except getting benefits. If we do not do our work and liabilities - nobody will cooperate with us. Its not in our interests.
To check the ability of returning files, you can send to us any 2 files with SIMPLE extensions(jpg,xls,doc, etc... not databases!) and low sizes(max 1 mb), we will decrypt them and send back to you. That is our guarantee.
Q: How to contact with you?
A: You can write us to our mailbox: myers@airmail.cc
Or you can contact us via JABBER chat: helprecovery@gnu.gr
Q: How will the decryption process proceed after payment?
A: After payment we will send to you our scanner-decoder program and detailed instructions for use. With this program you will be able to decrypt all your encrypted files.
Q: If I don抰 want to pay bad people like you?
A: If you will not cooperate with our service - for us, its does not matter. But you will lose your time and data, cause only we have the private key. In practice - time is much more valuable than money.
DON'T try to change encrypted files by yourself!
If you will try to use any third party software for restoring your data or antivirus solutions - please make a backup for all encrypted files!
Any changes in encrypted files may entail damage of the private key and, as result, the loss all data.
这个要恢复有点难了 病毒吧问问他们的吧主 个人推测,因为虚拟机开了公网,公网时时刻刻有人在扫描在线设备(软件自动扫描IP 端口号)。弱密码,虚拟机被入侵,因为共享文件夹账号密码,群晖被入侵了,加密。群晖有开自动备份,可以尝试恢复。