WannaCrypt ransomware

Discussion in 'Lounge' started by Regz, May 13, 2017.

  1. yuriswita

    yuriswita Newbie

    Joined:
    May 16, 2017
    Messages:
    2
    Likes Received:
    0
    WannaCrypt Emergency Patch for pre-Windows 10 computers targeted
    http://www.catalog.update.microsoft.com/Search.aspx?q=KB4012598

    (Microsoft) Customer Guidance for WannaCrypt attacks

    https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/

    Source: (Microsoft + )

    Note: I've had a few timeout failures with the Microsoft sites, so try again if it times out on you - it's very busy :)

    Windows XP SP3 http://download.windowsupdate.com/d..._eceb7d5023bbb23c0dc633e46b9c2f14fa6ee9dd.exe

    Windows Vista x86 http://download.windowsupdate.com/d..._13e9b3d77ba5599764c296075a796c16a85c745c.msu

    Windows Vista x64 http://download.windowsupdate.com/d..._6a186ba2b2b98b2144b50f88baf33a5fa53b5d76.msu

    Windows 7 x64 http://download.windowsupdate.com/d..._2decefaa02e2058dcd965702509a992d8c4e92b3.msu

    Windows 7 x86 http://download.windowsupdate.com/d..._6bb04d3971bb58ae4bac44219e7169812914df3f.msu

    Windows 8 http://download.windowsupdate.com/c..._f05841d2e94197c2dca4457f1b895e8f632b7f8e.msu

    Windows 8.1 http://download.windowsupdate.com/c..._5b24b9ca5a123a844ed793e0f2be974148520349.msu

    Windows 10 http://download.windowsupdate.com/c..._e805b81ee08c3bb0a8ab2c5ce6be5b35127f8773.msu

    Windows 2003 x86 http://download.windowsupdate.com/c..._f617caf6e7ee6f43abe4b386cb1d26b3318693cf.exe

    Windows 2003 x64 http://download.windowsupdate.com/d..._f24d8723f246145524b9030e4752c96430981211.exe

    Windows 2008 http://download.windowsupdate.com/d..._6a186ba2b2b98b2144b50f88baf33a5fa53b5d76.msu

    Windows 2008R2 http://download.windowsupdate.com/d..._2decefaa02e2058dcd965702509a992d8c4e92b3.msu

    Windows 2012
    http://download.windowsupdate.com/c..._b14951d29cb4fd880948f5204d54721e64c9942b.msu

    Windows 2012R2 http://download.windowsupdate.com/c..._5b24b9ca5a123a844ed793e0f2be974148520349.msu

    Windows Server 2016 http://download.windowsupdate.com/d..._ddc8596f88577ab739cade1d365956a74598e710.msu

    Here are the Microsoft Update Catalog pages:

    Windows 7/2008R2
    http://www.catalog.update.microsoft.com/search.aspx?q=4012212

    Windows 2012
    http://www.catalog.update.microsoft.com/Search.aspx?q=4012214

    Windows XP / Vista / 8 / 2003 / 2008
    http://www.catalog.update.microsoft.com/Search.aspx?q=4012598

    Windows 10
    http://www.catalog.update.microsoft.com/Search.aspx?q=4012606

    Windows 8.1/2012R2
    http://www.catalog.update.microsoft.com/Search.aspx?q=4012213

    Windows Server 2016
    http://www.catalog.update.microsoft.com/Search.aspx?q=4013429

    Source: (Microsoft + )

    It is said that this virus scan not be removed by tools and it is more dangerous than Jaff virus.
     
  2. Rhodes

    Rhodes Audiosexual

    Joined:
    Feb 4, 2015
    Messages:
    928
    Likes Received:
    558
    How came that the Russians were the main target ? Who doesn`t love the Russians :unsure:

    :rofl:
     
  3. Pinkman

    Pinkman Audiosexual

    Joined:
    Apr 22, 2016
    Messages:
    2,093
    Likes Received:
    1,944
    Forget what I said about M$. Pretty sure Trump ordered the whole WANNACRYPT attack as a warning to Putin. In response, Putin stated that the information Trump disclosed was NOT any kind of classified or sensitive material. Of course, Putin, not wanting to resign to the status of b!tch, still had things to say about Trump and his administration.
    The information disclosed to the Russian cabinet, in fact, ousted a number of CIA operatives, their aliases, local associates and locations.
    I love all the people but these warmongers and capitalist abusers can go to actual hell.
    Why?
    Because their actions have created hell on earth for over 95% of the world population.
     
    • Winner Winner x 2
    • Agree Agree x 1
    • Love it! Love it! x 1
    • List
  4. twoheart

    twoheart Audiosexual

    Joined:
    Nov 21, 2015
    Messages:
    2,019
    Likes Received:
    1,234
    Location:
    Share many
    Definitely not yet.
    We'll have to wait for full featured quantum computers :)
     
  5. ia

    ia Producer

    Joined:
    Apr 6, 2016
    Messages:
    431
    Likes Received:
    85
    Easiest way just to prevent this attack - close ports 139, 445 and disable SMB 1, also UPDATE your windows and your AV
     
  6. twoheart

    twoheart Audiosexual

    Joined:
    Nov 21, 2015
    Messages:
    2,019
    Likes Received:
    1,234
    Location:
    Share many
    @ai Yes sir. As a standard measure I close all ports on PCs connected to the internet and only open needed ones. And apply security patches of course. No A/V for me.

    pipotron3000s statement was, and I agree, it's not possible to decrypt already encrypted PCs. It depends on decryption type and strength, but most likely would take some 1.000 years with today's computers (even supercomputers). So the website mentioned in an earlier post offering decryption of ransomware-encrypted PC may be a fake
     
  7. Unirorm

    Unirorm Producer

    Joined:
    Jan 22, 2016
    Messages:
    145
    Likes Received:
    84
    Literally speaking you can do it with bitlocker in Windows. But that wont help in this case.
    What i meant was to use a Virtual Machine to browse the net.
    Essentially you are using an OS in your OS and if something happens you just restore it back to the previous state with all your system intact.

    I suggest Oracles VM.
     
  8. ia

    ia Producer

    Joined:
    Apr 6, 2016
    Messages:
    431
    Likes Received:
    85
    but this scheme would work very slow
     
  9. virusg

    virusg Rock Star

    Joined:
    Jan 4, 2012
    Messages:
    962
    Likes Received:
    386
    Location:
    near you
    sandboxie? anyone?
     
  10. twoheart

    twoheart Audiosexual

    Joined:
    Nov 21, 2015
    Messages:
    2,019
    Likes Received:
    1,234
    Location:
    Share many
    @virusg: I used to use Sandboxie. But I've encountered problems on my machines with Windows 10 x64. The Sandboxie kernel driver produces a BSOD at boottime. The only cure was deleting the driver at DOS prompt to boot and then removing Sandboxie. :(
    They introduce new errors every once and a while rendering a machine unusable. At this cost I don't like it anymore and instead using VM's.

    But if it works for you, great.
     
    Last edited: Jun 8, 2017
Loading...
Similar Threads - WannaCrypt ransomware Forum Date
NAS systems by QNAP & Asustor affected by Deadbolt Ransomware Computer Hardware Feb 23, 2022
ThiefQuest ransomware on Mac. Thoughts? Industry News Jul 7, 2020
Beware! New Mac Ransomware On The Scene. Live, Little Snitch, Mixed In Key. Mac / Hackintosh Jul 2, 2020
Ransomware on OSx 10.12 (sierra) Mac / Hackintosh Jun 28, 2020
arturia v collection 6 6.21 r2r ransomware false positve? Software Oct 20, 2018
Loading...