Перейти к содержанию

Рекомендуемые сообщения

Надо искать устройство, где был процесс шифрования. На этом ПК может быть папка C:\Temp в которой содержится файл лога шифрования MIMIC_LOG.txt

И с этого устройства снимать необходимые логи.

Ссылка на сообщение
Поделиться на другие сайты

Пожалуйста, войдите, чтобы комментировать

Вы сможете оставить комментарий после входа в



Войти
  • Похожий контент

    • Ans
      От Ans
      Я был бы признателен, если бы кто-нибудь мог помочь мне с ключом для этой rasomware, мне срочно нужно восстановить мои файлы, я был бы признателен за это.
    • dominiquetchamba
      От dominiquetchamba
      S'il vous plaît, aidez-moi à décrypter mes fichiers.
      Merci d'avoir répondu
    • Alexander Seregin
      От Alexander Seregin
      Заразились все физические компьютеры с работающим RDP
      virus.zipinfo.txtфайлы.zip
    • Iwan Herdian
      От Iwan Herdian
      Hi,
       
      This morning I got infected by DM7X4LO. So many of my files have extension DM7X4LO
       
      I got some messages like below:
       
      Data on Your network was exfiltrated and encrypted.
      Modifying encrypted files will result in permanent data loss!
      Get in touch with us ASAP to get an offer:
      1. Download and install Tor Browser from https://www.torproject.org/
      2. Access User Panel at 
         
      THIS IS YOUR PRIVATE USER PANEL ADDRESS, DO NOT SHARE IT WITH ANYONE!
      See also:
        Visit our Blog: http://alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion
        Social Media: https://twitter.com/search?q=%23alphv
        
      Ÿ¤G"ø´%g%VÅÄg¼3ºþ"‰¤6-TÇŠÌ=æ c
       
      kindly advise,
       
      How to resolve this
       
      Regards,
      Ivan
    • malcolmxxx
      От malcolmxxx
      Hello guys,
      I am writing from Turkey. Please help.
      I don't know much about English and Russian, please excuse me, I'm sure you will understand.
      details and extension are as follows !
      can you help me ? You're welcome.
      ------------------------------

       
      Hi!
      All your files have been encrypted with Our virus.
      Your unique ID: 8-kHRuHwJCEzK9plqHQBRCDTLGAgzGS287zgQONpqjg*bigspermhorseballs

      You can buy fully decryption of your files
      But before you pay, you can make sure that we can really decrypt any of your files.
      The encryption key and ID are unique to your computer, so you are guaranteed to be able to return your files.
      To do this:
      1) Send your unique id 8-kHRuHwJCEzK9plqHQBRCDTLGAgzGS287zgQONpqjg*bigspermhorseballs and max 3 files for test decryption
      OUR CONTACTS
      1.1)TOX messenger (fast and anonimous)
      https://tox.chat/download.html
      Install qtox
      press sing up
      create your own name
      Press plus
      Put there my tox ID
      95CC6600931403C55E64134375095128F18EDA09B4A74B9F1906C1A4124FE82E4428D42A6C65
      And add me/write message
      1.2)ICQ Messenger
      ICQ live chat which works 24/7 - @Bigspermhorseballs
      Install ICQ software on your PC here https://icq.com/windows/ or on your smartphone search for "ICQ" in Appstore / Google market
      Write to our ICQ @Bigspermhorseballs https://icq.im/Bigspermhorseballs
      1.3)Skype 
      Bigspermhorseballs DECRYPTION
      1.4)Mail (write only in critical situations bcs your email may not be delivered or get in spam)
      * Bigspermhorseballs@onionmail.org
      In subject line please write your decryption ID: 8-kHRuHwJCEzK9plqHQBRCDTLGAgzGS287zgQONpqjg*bigspermhorseballs
      2) After decryption, we will send you the decrypted files and a unique bitcoin wallet for payment.
      3) After payment ransom for Bitcoin, we will send you a decryption program and instructions. If we can decrypt your files, we have no reason to deceive you after payment. 
      FAQ:
      Can I get a discount?
          No. The ransom amount is calculated based on the number of encrypted office files and discounts are not provided. All such messages will be automatically ignored. If you really only want some of the files, zip them and upload them somewhere. We will decode them for free as proof.
      What is Bitcoin?
          read bitcoin.org
      Where to buy bitcoins?
                 https://www.alfa.cash/buy-crypto-with-credit-card (fastest way)
                 buy.coingate.com
          https://bitcoin.org/en/buy
          https://buy.moonpay.io
                 binance.com
          or use google.com to find information where to buy it
      Where is the guarantee that I will receive my files back?
          The very fact that we can decrypt your random files is a guarantee. It makes no sense for us to deceive you.
      How quickly will I receive the key and decryption program after payment?
          As a rule, during 15 min
      How does the decryption program work?
          It's simple. You need to run our software. The program will automatically decrypt all encrypted files on your HDD.
×
×
  • Создать...