French Researchers Find Last-ditch Cure To Unlock WannaCry Files (reuters.com)
French researchers said on Friday they had found a last-chance way for technicians to save Windows files encrypted by WannaCry, racing against a deadline as the ransomware threatens to start locking up victims' computers first infected a week ago. From a report: WannaCry, which started to sweep round the globe last Friday and has infected more than 300,000 computers in 150 nations, threatens to lock out victims who have not paid a sum of $300 to $600 within one week of infection. A loose-knit team of security researchers scattered across the globe said they had collaborated to develop a workaround to unlock the encryption key for files hit in the global attack, which several independent security researchers have confirmed. The researchers warned that their solution would only work in certain conditions, namely if computers had not been rebooted since becoming infected and if victims applied the fix before WannaCry carried out its threat to lock their files permanently. Also see: Windows XP PCs Infected By WannaCry Can Be Decrypted Without Paying Ransom.
what about this one? https://yro.slashdot.org/story...
http://www.geoffreylandis.com
I am so happy, I wanna cry.
So they surrendered and waited for the americans?
american pig dog
From TFA:
"This is not a perfect solution," Suiche said. "But this is so far the only workable solution to help enterprises to recover their files if they have been infected and have no back-ups"
If an "enterprise" didn't already have a backup solution in place, their CIO - and relevant members of their IT staff - should be fired.
#DeleteChrome
"If computers had not been rebooted since becoming infected" -- It's a Windows computer. It's been rebooted LOTS of times, if just to install the Windows Updates pushed out by Microsoft.
They are toast.
what about this one? https://yro.slashdot.org/story...
This one is a backup in case the first one gets encrypted!
More to point: the old method worked only for WinXP, this one also for Win7.
Video of some good progressive thrash music
From MS - SMB Ports 445/139 (TCP) & 137/138 (UDP) protection via:
Disable SMBv1 on the SERVER, configure the following registry key:
Registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters Registry entry: SMB1
REG_DWORD: 0 = Disabled
REG_DWORD: 1 = Enabled
Default: 1 = Enabled
Enable SMBv2 on the SERVER, configure the following registry key:
Registry subkey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters Registry entry: SMB2
REG_DWORD: 0 = Disabled
REG_DWORD: 1 = Enabled
Default: 1 = Enabled
---
Disable SMBv1 on the CLIENT, run the following commands:
sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi
sc.exe config mrxsmb10 start= disabled
Enable SMBv2 & SMBv3 on the CLIENT, run the following commands:
sc.exe config lanmanworkstation depend= bowser/mrxsmb10/mrxsmb20/nsi
sc.exe config mrxsmb20 start= auto
---
* The above is per https://support.microsoft.com/en-us/help/2696547/how-to-enable-and-disable-smbv1,-smbv2,-and-smbv3-in-windows-vista,-windows-server-2008,-windows-7,-windows-server-2008-r2,-windows-8,-and-windows-server-2012/
APK
P.S.=> For a SINGLE 'standalone' non-networked PC (no home network/LAN but TCP/IP connected online) turn off Server & Workstation services.
That shuts off any "handles" (port 445) this thing propogates thru + turn off NetBIOS over TCP/IP in your internet connection & uncheck/disable Client for Microsoft Networks + File and Print Sharing. Port 139 & 445 always pop up issues over time. It also makes your packet trains smaller (no encapsulation of LanMan)
I covered all this 11++ yrs. ago in a security guide I wrote for users with a single system & apparently, its advice STILL STANDS THE "TEST OF TIME" https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&btnG=Google+Search&gbv=1/ vs. even today's threats like this one.
* This effectively makes this threat a non-issue + saves you CPU cycles/RAM & other I/O wasted on services you don't NEED as a single PC user only... & you don't. They're just wastes with a single PC really. Many services are (covered in guide above based on CIS Tool guidance (who took fixes to their ware from "yours truly" too, no less)) & again, no more encapsulated packet bulk.
AND?
Don't be STUPID & click on attachments in bogus malicious emails this thing propogates thru also (Chrome/Opera/Webkit users - BEWARE of the ShellControlFile issue that just popped up (.scf file) noted here-> http://www.theregister.co.uk/2017/05/17/chrome_on_windows_has_credential_theft_bug/ ) ... apk
'if the computer hasn't been rebooted since the infection'.
If it has been a week since infection, that has long since passed, I would say the first thing someone would do on seeing this is try to reboot. I would guess there is a flag the ransomware sets somewhere that tells it the machine has been restarted, I would say the chances of this are almost zero, knowing that most users reboot windows anyway to 'fix' most problems, or that it is the standard desktop support answer for most problems, having been on the receiving end of support occasionally.
All signs point to this being another attempt by Microsoft to get people to upgrade to Windows 10, not an actual piece of malware to produce money from the malware itself.
IN THE SUN. IN THE
Just for kicks last weekend I put a completely unpatched Windows 10 machine, installed from a June 2016 RTM, on the Internet, 100% exposed. No NAT firewall. No Windows Firewall. No AV. No anti-malware. No nothing. Public IP. I even went so far as to enable insecure RDP and install a VNC server with NO authentication on the standard port.
Almost a week later, there is nothing unusual happening on that machine. No unusual network traffic (almost none at all, actually). File checksums for all windows components are still the same. No new DLLs on the system. No record of anyone even connecting to the completely open and unprotected VNC server.
I figured after the scary story about Windows machines being infected by WannaCry in MINUTES, I could have some fun with it. But no. This machine is still sitting there perfectly fine. None of the random documents I put on it have been encrypted. No signs of infection by anything.
Sad!
... I see that /. has now added a link to that earlier /. story to the summary.
http://www.geoffreylandis.com
Unidentifiable ac stalker: Take your OWN advice & "Satan get thee behind me" - Are you Wana's creator pissed I show folks how to secure themselves vs. wannacry???
* You constantly stalk/harass/troll me - & you always fail!
(With "results" like yours, why do you bother??)
APK
P.S.=> Oh, ok - I've got it figured out - you ENJOY failure! & you have failed vs. me before constantly knowing I have it bookmarked to toss @ you under your "registered 'luser'" account which I KNOW you have (so you "hide" behind unidentifiable anonymous posts) - Hey:
Keep it up - you only make ME look GOOD & yourself? LMAO - well... "not so good"! apk
It seems there are a large number of security researches. How do they make money, for examining malware day in and day out for a majority of their time ? Take the people mentioned in the article they are spending weeks and yet they will make nothing from their public service. After all this is over who will need or hire them ?
The victims might be watching the timer, but the researchers can change the BIOS clock and create backups for their research.