S
S
susnake2014-09-19 13:33:26
Malware
susnake, 2014-09-19 13:33:26

Some crap encrypted the file, what should I do?

Good afternoon.
Today, users have discovered that some of the files cannot be opened and have a strange *.just extension, i.e. there was a document.doc file, but it became document.doc.just and message.txt lies next to these files:

Purchasing a decryptor: [email protected]
When applying, indicate your ID in the subject line: 1117114721 The
key is stored until 09/22/2014 Applications
after 09/22/2014 will be ignored.
Letters are processed by an automatic system.
Possible response delays

I scanned CureIt on one machine and found several log files . I don't know if these malware are ransomware or not.
The initials of the employee are set in the file properties, nothing was found when scanning his car. If necessary, the archive contains examples of encrypted files. password virus.
Damn, I don’t know what to do, only at the weekend they wanted to introduce TrendMicro.
We called several more companies where we have valid keys:
Kaspersky support says that try to decrypt the files with our decryptors, and if it doesn’t help, then write a statement to the authorities (of course it didn’t help). Yeset said send the files - terms from two weeks to two months - sent.
Moreover, what is most interesting, encryption began only on the server where the working documents were, on other machines not a single file with the *.just extension was found. And the worst thing is that we cannot determine whether this malware has been removed or not.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
C
Cool Admin, 2014-09-19
@susnake

Everything is bad. If the amount is commensurate with the losses - pay - pray that they will scan and the decoder will really be sent (sometimes it helps, sometimes they throw it).
Then, after decrypting and uploading files to a secure FTP or SFTP (by no means SMB) server, you remove the disks and check them on a separate machine. Better to reinstall the system. You were tricked either through unstable passwords - they themselves are to blame, or your OS is very old - they are also to blame.

S
Sergey, 2014-09-19
@bk0011m

If you want to receive files - pay money. There are no other options yet. People have been struggling with this since July.
They just caught a virus, I don’t remember the exact name, it usually comes by mail. Here is a discussion: forum.kaspersky.com/lofiversion/index.php/t300728.html

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question