barack obama

Well-known member
  • Jun 12, 2008
    3,281
    467
    83
    38
    United Arab Emirates
    Mage lap eke virus ekak ewilla, files okkoma “Coot” kiyala format ekata change wela,
    menna me vidhihata,
    .jpg.coot
    .pdf.coot
    .exe.coot


    Open karanna behe, files okkoma locked,

    kavru hari dannawada meka remove karana vidhiha :( ?
     

    maheshsenadheera

    Well-known member
  • Mar 13, 2009
    18,399
    3,712
    113
    කන්ද උඩරට
    ransomeware attack

    okata karanna deyak na machan
    ransomeware eke name eka gahala search karala balapan decrypt keys tiynwda kiyala .
    tiynwanam ewa dila file unlock karaganna puluwan.
    ehema nattan format karala recover karaganna tama wenne
     

    nrjayasinghe

    Well-known member
  • Mar 7, 2007
    18,109
    3,527
    113
    46
    Buttala
    ransomware attack එකක් බං. මං දන්න කොල්ලෙකුගේ ස්ටුඩියෝ එකේ තිබුන සියල්ලම නැති වෙලා ගියා. Offline key එකකින් encrypt වෙලා නම් විතරයි ගොඩ දාන්න පුළුවන්.
     

    imhotep

    Well-known member
  • Mar 29, 2017
    14,823
    8
    35,328
    113
    ransomware attack එකක් බං. මං දන්න කොල්ලෙකුගේ ස්ටුඩියෝ එකේ තිබුන සියල්ලම නැති වෙලා ගියා. Offline key එකකින් encrypt වෙලා නම් විතරයි ගොඩ දාන්න පුළුවන්.

    Correct. The removal of the virus can be done easily but Decryption is totally different story.
    At the moment the recent .coot cannot be decrypted. Unless you have a backup it's a sorry situation. :sorry:
     

    imhotep

    Well-known member
  • Mar 29, 2017
    14,823
    8
    35,328
    113
    This is a variant of the STOP (Djvu) ransomware... There are more than 175 of these existing now and the recent ones are .derp, .coot and .nols
    Normally distributed thorough fake cracks and activators eg: KMSPico, Cubase, Photoshop or other antivirus software.
    If you are brave enough to download these then make sure you have a backup. Otherwise virus scanners are not going to protect you.