PTT推薦

[問卦] KARRHZE 這是什麼加密病毒(勒索病毒)?

看板Gossiping標題[問卦] KARRHZE 這是什麼加密病毒(勒索病毒)?作者
geofrania
(過勞鼠)
時間推噓 1 推:2 噓:1 →:11

電腦的好像中了加密病毒、勒索病毒

有人知道KARRHZE檔這是什麼病毒?

電腦目前所有WORD檔、EXCEL檔、PDF檔副檔名都變成了KARRHZE檔

如下:

https://imgur.com/98uraS6

然後都不能開

裡面出現了一個README文件

文件如下:

ALL YOUR DOCUMENTS PHOTOS DATABASES AND OTHER IMPORTANT FILES HAVE BEEN
ENCRYPTED!

====================================================================================================
Your files are NOT damaged! Your files are modified only. This modification
is reversible.

The only 1 way to decrypt your files is to receive the private key and
decryption program.

Any attempts to restore your files with the third party software will be
fatal for your files!

====================================================================================================
To receive the private key and decryption program follow the instructions
below:

1. Download 'Tor Browser' from https://www.torproject.org/ and install it.

2. In the 'Tor Browser' open your personal page here:



http://da70a6c85c147c1014karrhze.hqi4yxata3v5es3ocbniowfvbzcobro5s5ytk3dxn2rgjerjcjzjceid.onion/karrhze


Note! This page is available via 'Tor Browser' only.

====================================================================================================
Also you can use temporary addresses on your personal page without using 'TorBrowser':


http://da70a6c85c147c1014karrhze.sixtest.quest/karrhze

http://da70a6c85c147c1014karrhze.liecut.monster/karrhze

http://da70a6c85c147c1014karrhze.turnis.art/karrhze

http://da70a6c85c147c1014karrhze.diskwar.tech/karrhze


Note! There are temporary addresses! They will be available for a limited
amount of time!

--
Now that I ask you earnestly and sincerely,
Now you answer me mercifully:
"To prevent the world from being destroyed,
To protect the peace of the world..."

--

※ PTT留言評論
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 114.43.194.128 (臺灣)
PTT 網址
※ 編輯: geofrania (114.43.194.128 臺灣), 07/10/2022 12:50:31

palajuice 07/10 12:50看來對方是寶可夢的重度玩家~

gginin007 07/10 12:51不要再亂看a片了

geofrania 07/10 12:55還有救嗎?

tttxxx 07/10 12:56他把你副檔名全改了 然後加密 要你付錢

tttxxx 07/10 12:58我開ie就會中 所以我把ie移除了

tttxxx 07/10 12:59用chrome之後就沒有在中過了

kklighter 07/10 13:01資料不重要就全部格了吧

sa12e3 07/10 13:16如果你有備份,那麼你可以進行系統還原,

sa12e3 07/10 13:16那就影響沒那麼多

sa12e3 07/10 13:16他再怎麼弄也不太可能弄系統還原的程式

yin7x38x3 07/10 13:55八卦就是付了錢也變不回來!

chaosly0124 07/10 14:54到底要怎麼中勒索病毒我真的很好奇

chaosly0124 07/10 14:54...

tttxxx 07/10 15:16ie 開著就會中