{"id":488,"date":"2018-07-05T06:31:33","date_gmt":"2018-07-05T06:31:33","guid":{"rendered":"http:\/\/esolutions.lt\/blog\/?p=488"},"modified":"2018-07-05T06:31:33","modified_gmt":"2018-07-05T06:31:33","slug":"esolutions-warning-nozelesn-ransomware-virus-is-targeting-poland","status":"publish","type":"post","link":"https:\/\/esolutions.lt\/blog\/esolutions-warning-nozelesn-ransomware-virus-is-targeting-poland\/","title":{"rendered":"Esolutions warning: Nozelesn ransomware virus is targeting Poland"},"content":{"rendered":"<h2>Nozelesn\u00a0ransomware &#8211; a\u00a0virus that uses DHL name in virus spreading emails<\/h2>\n<p><a href=\"https:\/\/www.2-spyware.com\/remove-nozelesn-ransomware.html\">Nozelesn ransomware<\/a> infiltrates your system secretly and makes your files useless. This virus came to Esolutions team&#8217;s attention this week. This ransomware has the main purpose of gaining money as typical ransomware. It is known that Nozelsen\u00a0targets Poland.<\/p>\n<p>This virus encrypts files using AES method and adds .nozelesn\u00a0file extension. This locks data and user cannot access their files. The only solution here is restoring those locked files from a backup. You should build a file backing routine in case this happens.<\/p>\n<p>After infiltration and file modification ransomware places ransom note on your\u00a0PC.\u00a0HOW_FIX_NOZELESN_FILES.htm file contains more information and a whole step-by-step guide on creating payment account. We advise you not to pay this ransom and stay away from cybercriminals at all.<\/p>\n<h2>Known\u00a0 company names trick people into getting ransomware<\/h2>\n<p>It appears that many virus developers use names like Paypal, Amazon, FedEx or DHL when creating these cyber infections. Of course, people believe those big names and open attachments or files without thinking it trough.<\/p>\n<p>Lack of knowledge and caution is the main thing that gets people into these frustrating and often dangerous situations. If you know that spam email attachments might be infected with <a href=\"https:\/\/searchsecurity.techtarget.com\/definition\/macro-virus\">macro-viruses<\/a> or those purchases from ads can bring malware, you can avoid infections on your PC.<\/p>\n<h2>Ransomware acts similarly, but different<\/h2>\n<p>Typical ransomware behavior is file encrypting and demanding a ransom for them. Also, file encryption is a process when criminals use either AES or RSA method. This Nozelesn\u00a0ransomware uses <a href=\"https:\/\/www.boxcryptor.com\/en\/encryption\/\">AES encryption<\/a> method.<\/p>\n<p>There are some differences. Some of these viruses display ransom\u00a0notes in text files, some on your desktop or just a few sentences in .exe\u00a0file. In this case, there is a program\/site for the payment, but often there is only a suggested\u00a0site with cryptocurrency wallet provided.<\/p>\n<p>Ransomware is\u00a0very dangerous because file locking might lead to permanent data loss or if you try to contact these criminals and pay the ransom you can lose money. There is a possibility that virus changes more prominent parts of your PC system so be quick and rely\u00a0on trustful sources for the solution.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nozelesn\u00a0ransomware &#8211; a\u00a0virus that uses DHL name in virus spreading [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":491,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/posts\/488"}],"collection":[{"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/comments?post=488"}],"version-history":[{"count":3,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/posts\/488\/revisions"}],"predecessor-version":[{"id":493,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/posts\/488\/revisions\/493"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/media\/491"}],"wp:attachment":[{"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/media?parent=488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/categories?post=488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/esolutions.lt\/blog\/wp-json\/wp\/v2\/tags?post=488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}