Become a fighter against malware and join the forum at SensorsTech!  The SensorsTech’s forum is the place where you can solve your PC issues and educate yourself about malware. You are welcome to discuss various security topics with our professional team and other users like you! To unlock all features of the forums, you have to create an account. Otherwise, you can only browse the topics without taking part in the discussions. To leave a comment or ask your questions, read our Registration Agreement and create your free account here.


*

never

  • *****
  • 119
  • +23/-0
  • Network Administrator and Malware Researcher
      • View Profile
  • Publish
  • Independent malware researcher "MalwareHunter" has discovered a new version of the Wanna Decryptor ransomware, calling itself Wana Decrypt0r 2.0. The virus uses .WNCRY file extension which it adds to the files encrypted by the virus. Then, the ransomware drops a ransom note with the following content:

    Ooops, your files have been encrypted!
    What Happened to My Computer?
    Your important files are encrypted.
    Many of your documents, photos, videos, databases and other files are no longer
    accessible because they have been encrypted. Maybe you are busy looking for a way to
    recover your files, but do not waste your time. Nobody can recover your files without
    our decryption service.

    Can I Recover My Files?
    Sure. We guarantee that you can recover all your files safely and easily. But you have
    not so enough time.
    You can decrypt some of your files for free. Try now by clicking <Decrypt>.
    But if you want to decrypt all your files, you need to pay.
    You only have 3 days to submit the payment. After that the price will be doubled.
    Also, if you don't pay in 7 days, you won't be able to recover your files forever.
    We will have free events for users who are so poor that they couldn't pay in 6 months.

    How Do I Pay?
    Payment is accepted in Bitcoin only. For more information, click <About bitcoin>.
    Please check the current price of Bitcoin and buy some bitcoins. For more information,
    click <How to buy bitcoins>.

    And send the correct amount to the address specified in this window.
    After your payment, click <Check Payment>. Best time to check:



    The ransowmare also deletes the backup copies and other system restore points and changes the wallpaper on the victim's computer to the following image:



    More information on the virus can be found on our blog: http://sensorstechforum.com/wncry-file-virus-remove-restore-files/

    This is a help and support topic for the Wana Decrypt0r ransomware virus. Feel free to ask questions, add decryption instructions and suggest methods to remove and restore files by this virus

    Best Regards,
    Never
    Guilty is the love of The Sin.

    *

    Martin

    • *
    • 11
    • +4/-0
        • View Profile
  • Publish
  • Do you think that new attack campaigns are going to be launched soon?

    Augur of Runes

    *

    Execute

    • *****
    • 223
    • +38/-0
    • Your friendly neighbourhood IT guy
        • View Profile
  • Publish
  • This is definitely not the end of it. Who knows what tactic the ransomware developers will try next.
    Also, other ransomware viruses might try to imitate this one and spread via different ways.
    Just be careful and do not open email attachments from unknown sources...
    There is no place like 127.0.0.1

    *

    Abhi

    • *
    • 2
    • +0/-0
        • View Profile
  • Publish
  • Do you think that new attack campaigns are going to be launched soon?
    Yes, thats because everyone have a backup planes expect some who don't have mind and dont keeps backup of your data ,and have to pay ransomeware ! LOL
    yup they are many chances of that as i to have noticed some such talk in USundernet IRC.

     


    Facebook Comments