Windows 10: WannaCry

Discus and support WannaCry in AntiVirus, Firewalls and System Security to solve the problem; I saw on TV that the WannaCry Ransom Virus will be blocked if your Windows Updates are up-to-date. Which upgrade do I need stop the latest ransom... Discussion in 'AntiVirus, Firewalls and System Security' started by doncole, May 15, 2017.

  1. doncole Win User

    WannaCry


    I saw on TV that the WannaCry Ransom Virus will be blocked if your Windows Updates are up-to-date.

    Which upgrade do I need stop the latest ransom from England or where ever?

    I just received my last Update around 5/11/2017. The only thing different, that I see, is that the border around the Windows was black now it's no color (flat).

    Is this the one with ransom update?

    I had this virus before. It's easy to get out with Kaspersky. But you will loose all your document if you haven't backed them up.

    Don Cole

    :)
     
    doncole, May 15, 2017
    #1
  2. Jsssssssss, May 15, 2017
    #2
  3. Does Wannacry virus work on all drives

    WannaCry is a worm that spreads by exploit in a weakness found in Microsoft Windows
    which was formerly exploited by the US National Security Agency (NSA) and targets unpatched systems. The WannaCry worm speads via an operation targeting vulnerable SMB ports and then uses the NSA-leaked exploit to infect a network.


    According to
    Cisco Talos
    , WannaCry encrypts everything in terms of connected or networked devices..."it checks for disk drives, including network shares and removable storage devices mapped to a letter, such as 'C:/', 'D:/' etc."

    Microsoft Customer Guidance for WannaCrypt attacks

    How to Protect yourself from the WannaCry or Wana Decryptor Ransomware

    How to protect yourself from WannaCry ransomware
     
    quietman7 - MVP, May 15, 2017
    #3
  4. Bree New Member

    WannaCry

    I think the previous month's update was the first to have the fix in it. If Windows Update says you are up to date then you're protected.
     
  5. That is partially true. Windows updates prevent you from being infected by this without your intervention.
    But you could still get infected, if you would run it by yourself, like by running an unknown email attachment.

    That is why, you always need to do regular backups. AV will usually not detect it, until after it is too late.
     
    TairikuOkami, May 15, 2017
    #5
  6. simrick Win User
    Hi Don,
    Just to be clear:
    The WCry ransomware does 2 things:
    1. it encrypts your data for a ransom
    2. it spreads via a worm which exploits an SMB1 vulnerability
    So, updating your system closes the SMB1 vulnerability and prevents the thing from spreading, but it can still infect your system.

    See this post for the link to the Security Bulletin:
    Privacy and Security – How do I Protect Myself ? - Page 4 - Windows 10 Forums

    You want to make sure the particular KB is installed for your OS.
    .
     
    simrick, May 16, 2017
    #6
  7. simrick Win User
    Another option is to simply disable SMB1 in Windows, to prevent spreading.


    WannaCry [​IMG]


    This will not, however, prevent encryption.
     
    simrick, May 16, 2017
    #7
  8. Steve C Win User

    WannaCry

    Do any essential programs / services need SMB 1.0 support?
     
    Steve C, May 16, 2017
    #8
  9. simrick Win User
    I can't remember exactly, but seems someone said you might lose access to a NAS if it's setup that way (which supposedly it shouldn't be?) Not too sure - would have to google that myself. *Wink
     
    simrick, May 16, 2017
    #9
  10. OldMike65 Win User
    Here is some information on SMB 1.0 Hope this explains it a little more.

    If you don’t need to support an older SMB version for computers running Windows XP or Windows Server 2003, you can disable this function to reduce the system load and improve security

    The original SMB1 protocol is nearly 30 years old, and like much of the software made in the 80’s, it was designed for a world that no longer exists. A world without malicious actors, without vast sets of important data, without near-universal computer usage.

    When you use SMB1, you lose key protections offered by later SMB protocol versions:

    Pre-authentication Integrity (SMB 3.1.1+). Protects against security downgrade attacks.
    Secure Dialect Negotiation (SMB 3.0, 3.02). Protects against security downgrade attacks.
    Encryption (SMB 3.0+). Prevents inspection of data on the wire, MiTM attacks. In SMB 3.1.1 encryption performance is even better than signing!
    Insecure guest auth blocking (SMB 3.0+ on Windows 10+) . Protects against MiTM attacks.
    Better message signing (SMB 2.02+). HMAC SHA-256 replaces MD5 as the hashing algorithm in SMB 2.02, SMB 2.1 and AES-CMAC replaces that in SMB 3.0+. Signing performance increases in SMB2 and 3.

    Bottom line is SMB 1.0 should be Disabled, just like simrick has posted.
     
    OldMike65, May 16, 2017
    #10
  11. Steve C Win User
    Thanks. I'm going to disable this since I only use Windows 10 for home use. Is there any other legacy stuff enabled by default we can safely disable for improved security?
     
    Steve C, May 16, 2017
    #11
  12. OldMike65 Win User
    As long as you keep your Windows 10 Home updated with the latest updates, you should be just fine. Windows released some security fixes for this just a few days ago.
     
    OldMike65, May 16, 2017
    #12
  13. Mystere Win User

    WannaCry

    As others have mentioned, you can still get infected, just not by someone else on your network.

    There is no way to prevent infections where you deliberately run a program. That program will have access to any files you have access to (one of the reasons for UAC is to prevent a virus from infecting system files, or files for other users who also use that PC).
     
    Mystere, May 16, 2017
    #13
  14. Tonyb Win User
    what are disadvantages of turning this feature off as i don't no if i even use it windows 10 Pro here??
     
    Tonyb, May 17, 2017
    #14
  15. I have just checked my PC and found that SMB 1/CFIS is ticked by default. Why is this the case? Sould it not be a feature that is normally disabled instead?
     
    Geoff Daniell, May 17, 2017
    #15
Thema:

WannaCry

Loading...
  1. WannaCry - Similar Threads - WannaCry

  2. Bluekeep and wannacry patches failed to install windows server 2008 R2

    in Windows 10 Gaming
    Bluekeep and wannacry patches failed to install windows server 2008 R2: Hello All, Please anyone help I have HP Server Gen7 with AMD processor running windows server 2008 SP1 R2, I want to install Bluekeep and wannacry security patches, to resolve vulnerability issue raised by audit team, I have downloaded the patches for that OS but when i...
  3. Bluekeep and wannacry patches failed to install windows server 2008 R2

    in Windows 10 Software and Apps
    Bluekeep and wannacry patches failed to install windows server 2008 R2: Hello All, Please anyone help I have HP Server Gen7 with AMD processor running windows server 2008 SP1 R2, I want to install Bluekeep and wannacry security patches, to resolve vulnerability issue raised by audit team, I have downloaded the patches for that OS but when i...
  4. My Computer affected with WannaCry Ransomware URGENT HELP!!

    in AntiVirus, Firewalls and System Security
    My Computer affected with WannaCry Ransomware URGENT HELP!!: How do i remove this ransomware safely without removing data? URGENT HELP!!! im need to finish my work project!!!! my works files is inaccessible!!!!...
  5. About ransomware_reqg . wetransfer virus . and wannacry story .

    in AntiVirus, Firewalls and System Security
    About ransomware_reqg . wetransfer virus . and wannacry story .: hello guys in this day I want to share my experiences .Read this to the end . in 2017 or 2018 people they easily used their computers . microsoft in the 2017 and 2018 has not given a new update . hackers teams they have seen the situation . and started create new virus for...
  6. Is it safe to run viruses such as WannaCry and Memz within Windows Sandbox?

    in Windows 10 Ask Insider
    Is it safe to run viruses such as WannaCry and Memz within Windows Sandbox?: Would there be any damage to my host PC? submitted by /u/BigmansFacilities [link] [comments] https://www.reddit.com/r/Windows10/comments/jv4prv/is_it_safe_to_run_viruses_such_as_wannacry_and/
  7. HELP MY FRIEND!!! WANNACRY IS BACK!

    in AntiVirus, Firewalls and System Security
    HELP MY FRIEND!!! WANNACRY IS BACK!: Hello Microsoft, can you help my Friend? In my Facebook group, I have a member whose laptop is infected with the "Wannacry" ransomware. I don't know whether he actually downloaded the ransomware on purpose, or not. But I think the "Wannacry" Ransomware is back. Can you guys...
  8. Still vulnerable to WannaCry

    in AntiVirus, Firewalls and System Security
    Still vulnerable to WannaCry: I am currently on Windows 10 N version 1803 (OS Build 17134.191) I've run the windows updater and installed all updates that were offered, but when using the EternalBlues tool that checks for vulnerabilities it still shows that I am vulnerable. Is there a specific patch that...
  9. Wannacry

    in Windows 10 Installation and Upgrade
    Wannacry: Is wannacry still active and what to do if you get infected https://answers.microsoft.com/en-us/windows/forum/windows_10-update/wannacry/05152dfd-e08d-4e70-a206-bd0ccf1e4626
  10. Wannacry 2.0 eternalrocks author may have called it quits

    in AntiVirus, Firewalls and System Security
    Wannacry 2.0 eternalrocks author may have called it quits: Over on the Inquirer an interesting read: https://www.theinquirer.net/inquirer...calls-it-quits Looks like the witch hunt may have made him a little nervous. Reminds me of Matthew Broderick in the movie War Games. 85620