

Congratulations when you see this picture! You hit the jackpot! It means that you have been infected by the Bitcoin ransomware virus. All server web files are encrypted. Generally, you are required to pay 3 Bitcoins to decrypt them. One Bitcoin is approximately equal to 10,000 yuan, and 3 Bitcoins are also more than 30,000 yuan. As shown below
The latest report from the National Network and Information Security Information Reporting Center:
Monitoring found that WannaCry broke out around the world A variant of the ransomware virus has emerged: WannaCry 2.0.
The difference from the previous version is that this variant cancels the Kill Switch and cannot turn off the spread of the variant ransomware by registering a domain name. This variant may spread faster.
Internet users are requested to upgrade and install Windows operating system-related patches as soon as possible. If a machine infected with the virus is infected, please disconnect it from the Internet immediately to avoid further spread of infection.
Previous notification:
The National Network and Information Security Information Reporting Center earlier issued an emergency notification stating that at around 20:00 on May 12, 2017, a new type of "worm" A ransomware virus broke out. Tens of thousands of computers in more than 100 countries and regions have been infected by this ransomware virus. Some users of Windows series operating systems in my country have been infected.
Computer users are requested to upgrade and install the patch as soon as possible. The address is: https://technet.microsoft.com/zh-cn/library/security/MS17-010.aspx.
There is no official patch for Windows 2003 and XP. Relevant users can open and enable Windows Firewall, enter "Advanced Settings", disable "File and Printer Sharing" settings; or enable personal firewall to turn off 445 and 135, 137, 138 , 139 and other high-risk ports.
If the machine is infected with the virus, please disconnect it from the Internet immediately to avoid further spreading of infection.
Analysis: The threat of ransomware is far from gone
Cyber security experts pointed out that a large-scale ransomware cyberattack broke out in Beijing At around 8 pm on the 12th, the network nodes of a large number of domestic institutions and enterprises were shut down, so the startup on the 15th will face a security test. Many important computer systems are in an intranet environment and cannot access the aforementioned domain names, and may not be able to update security patches in a timely manner, so they may still face greater risks.
Network security experts recommend that users disconnect from the Internet and turn on the computer, that is, unplug the network cable and then turn on the computer. This can basically avoid being infected by ransomware. You should find a way to apply security patches as soon as possible after turning on the computer, or install defense tools launched by various network security companies for this matter before you can connect to the Internet.
After being invaded by this ransomware, almost all types of files such as photos, pictures, documents, audios, and videos in the user's host system will be encrypted, and the suffix names of the encrypted files will be uniformly changed to. WNCRY will pop up a ransomware dialog box on the desktop, asking the victim to pay hundreds of dollars worth of Bitcoin to the attacker's Bitcoin wallet, and the ransom amount will increase over time.
Han Zhihui, a doctor and engineer at the National Internet Emergency Center, said that at present, the security industry has not been able to effectively break the malicious encryption behavior of the ransomware. Once a user's host is penetrated by ransomware, the ransomware can only be removed by using specialized killing tools or reinstalling the operating system, but the user's important data files cannot be fully restored.
What should I do if the server is infected by the Bitcoin ransomware virus?
Suggested solutions:
In addition to the recommendations of the National Network and Information Security Information Notification Center, we have helped you organize a temporary solution. Now Let me teach you step by step: how to set up your computer to prevent ransomware.
Temporary solution:
Turn on the system firewall
Use the advanced system firewall settings to block connections to port 445 (this operation will affect the use of port 445 Service)
Turn on automatic system updates, and detect updates for installation
Download address of the "Bitcoin Ransomware Virus" immunity tool released by 360: http://dl.360safe.com/ nsa/nsatool.exe
Steps to restore data:
1: Kill the virus first
If you use free anti-virus software, it is recommended to use 360 Security Guard 11 can currently detect and kill encrypted viruses. As shown in the figure
-note-if there are two wallet virus mailboxes http://india.com or http://aol.com, then one payload_xxxx will be detected. exe.
2: Modify the weak RDP (Remote Desktop Control) password (password) before the poisoning
(Some children say that my QWEasd!@# is not strong, I can only say The salary your boss offers you is too low. Using such a password is no different than leaving the door open to let hackers in)
3: Restore data
A: Please use the free Kaspersky cracking tool for XTBL http://media.kaspersky.com/utilities/VirusUtilities/RU/rannohdecryptor.zip?_ga=1.69588624.1814211149.1453294100 (Personal test Valid, please back up before testing to avoid damaging the file)
B: Wallet is a variant virus of XTBL. Currently, there is no cracking tool for wallet encrypted data. You can only pay Bitcoin to hackers for processing (general hacker quotation is 3 Bitcoins. The total amount is about RMB 30,000). If you are not in a hurry to use the data, please wait patiently for Kaspersky to reveal it. The more urgent the data, the more you need to pay attention to the risks. Please find professional and experienced people to handle it.
Recovery instance snapshot: This is a server with more than 700,000 files encrypted with the suffix fly_goods@aol.com.wallet. The recovery of more than 600,000 files was completed by purchasing a private key, which took 4 Hours and 20 minutes, it is estimated that it will take 1-2 days to restore everything to normal, about 5 hours to restore 700,000 files, and at least 1 day to reconfigure the server environment. ------To paralyzed hackers, you also encrypt exe applications.
C: Generally, better servers have their own disk snapshot function. You can restore the snapshot to before the infection to minimize the loss, and then enable the personal firewall to turn off 445 and high-risk ports such as 135, 137, 138, and 139, then install the necessary anti-virus software and apply the latest patches.
【Guess you like】
1.php Chinese website special recommendation: php programmer toolbox download (one-click to build a php environment)
3. Ranking of web front-end development tools: 8 Recommended downloads of html development tools

比特币之父中本聪(SatoshiNakamoto)消失多年后终于出现新线索。根据Blockchain.com链上数据,最新的数据显示,今天凌晨,有一个以bc1q9开头的地址从币安购买了27枚比特币。根据当前的比特币价格(43,506.45美元),这笔交易价值约为117.4万美元。这些比特币随后被发送到中本聪的钱包地址:"1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa"。这一发现引起了人们对中本聪真实身份的猜测与关注。该地址是被标记为"Satoshi1",是中本聪在2009年

比特币当前已经在全球普及,很多企业也开始接受比特币作为支付方式,但是比特币在各个国家发展并不相同,每个国家有自己的法律法规,比如中国已经明确禁止比特币挖矿,但其他国家、地区则表示对比特币的交易表示支持、欢迎,比如非洲、美国等,关于比特币最受欢迎的国家是哪个?也是一个有意思的话题,因为似乎支持比特币的国家都欢迎比特币的加入,根据Google搜索指标,非洲的尼尔利亚在比特币搜索领域名列第一,接下来小编为大家详细说说。比特币最受欢迎的国家是哪个?比特币在非洲大陆的尼日利亚是最受欢迎的国家之一。据统计,

二选一订单(OneCancelstheOther,简称OCO)可让您同时下达两个订单。它结合了限价单和限价止损单,但只能执行其中一个。换句话说,只要其中的限价单被部分或全部成交、止盈止损单被触发,另一个订单将自动取消。请注意,取消其中一个订单也会同时取消另一个订单。在币安交易平台进行交易时,您可以将二选一订单作为交易自动化的基本形式。这个功能可让您选择同时下达两个限价单,从而有助于止盈和最大程度减少潜在损失。如何使用二选一订单?登录您的币安帐户之后,请前往基本交易界面,找到下图所示的交易区域。点

全球最大的资产管理公司BlackRock(贝莱德)最新文件显示,其正式名称代号为「IBIT」。再进一步:确认代号IBIT贝莱德的现货比特币ETF最近公开确认其交易代码为「IBIT」,在本周一提交给SEC的修订版S-1文件中披露了这一重要进展。重点解读:SEC与贝莱德协商模式中BlackRock(贝莱德)在最新文件中增加了关于基金创建和赎回机制的新设计,这一点尤其引人注目。据了解,BlackRock(贝莱德)希望采用「实物创建」(in-kind)的模式,以增加管理投资组合的灵活性。然而,SEC更倾

根据日本经济新闻报道,二手交易电商平台Mercari计划从今年6月开始接受比特币支付。为了处理比特币支付,Mercari的子公司Melcoin将负责相关服务,并将所有比特币支付转换为日元。这意味着买家可以选择使用比特币进行支付,但卖家最终会收到法定货币。在Mercari平台上,商品的定价是以日元计算的,而不是以比特币计价。然而,用户在结账时可以选择使用比特币作为付款方式。日本最大二手交易电商平台Mercari成立于2013年,是日本最大的二手交易电商平台。2018年,该公司在东京证交所创业板上市

随着市场预测美国证券交易委员会(SEC)将在1月8号至1月10号期间批准首个比特币现货ETF,现货ETF似乎已接近最后一步。越来越多的迹象和消息显示这一进展,使得投资者对比特币市场的前景更加乐观。根据最新提交给SEC的文件显示,一些著名的比特币现货ETF发行商,如富达、灰度、方舟、Valkyrie和VanEck等,都已经递交了证券注册的「8-A表格」。而Bitwise则是在上周五就率先递交了8-A表格。这些举动表明这些公司正计划发行比特币ETF,以满足市场对于加密货币的投资需求。这也意味着投资者

监管政策仍在不断演变和发展中,一些国家对加密货币持开放态度,将其视为一种数字资产,允许合法交易和持有,而另一些国家则对加密货币持谨慎态度,可能限制或禁止其交易和使用,因此了解在交易所买卖数字货币合法吗?对于投资者合法合规地进行数字货币交易十分重要。在交易所买卖数字货币合法吗?在大部分国家,购买和出售数字货币是合法的,比如比特币、以太坊等。然而,不同国家和地区对数字货币的法律和监管状况存在差异,因此投资者需要根据所在地的法律了解相关规定。在一些国家,政府已经制定了特定的法规和监管机制来管理数字货币

比特币现货ETF发行商在1月8日提交修订文件和公布费用结构,同时注入种子基金。SEC主席GaryGensler在此时发推呼吁加密相关风险,被视为发行前的最后提醒。SEC前主席JayClayton接受CNBC专访时也表明,批准ETF是势在必行。JayClayton:批准ETF势在必行JayClayton表示,批准比特币ETF已经是不可避免的事情,而且目前没有任何未解决的疑虑。他强调,SEC对各方提供的信息感到满意。CNBC主持人JoeKernen最近了解到投资比特币ETF所需的成本,这是需要让大家

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

EditPlus Chinese cracked version
Small size, syntax highlighting, does not support code prompt function

MinGW - Minimalist GNU for Windows
This project is in the process of being migrated to osdn.net/projects/mingw, you can continue to follow us there. MinGW: A native Windows port of the GNU Compiler Collection (GCC), freely distributable import libraries and header files for building native Windows applications; includes extensions to the MSVC runtime to support C99 functionality. All MinGW software can run on 64-bit Windows platforms.

SublimeText3 Chinese version
Chinese version, very easy to use

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool

SublimeText3 Linux new version
SublimeText3 Linux latest version