Skip to main content

Here's what a VPN can't protect you from (but you need to use it)

The abbreviation " VPN " has slowly become established among average Internet users, which is certainly good, but the problem is that people have started to see VPN as the ultimate solution to all problems.

How to protect yourself from the Ransomware WannaCry virus that has shaken the world ?!

How to protect yourself from the Ransomware WannaCry virus that has shaken the world ?!

Ransomware Wana Decryp0r, also known as WCry, WannaCry, and WannaCrypt, is a virus that has traveled the world and infected hundreds of thousands of computers in 99 countries.

This virus is known to us before, but it was not so widespread. During the weekend, the virus broke out and infected many computers, including the computers of health institutions in the UK, which made it impossible for their systems to function properly.

But the virus does not choose, so it attacks computers from average users to the Russian Ministry of Internal Affairs. However, they protected themselves in time and thus infected "only" 1,000 computers, which is less than one percent of the computers they use.

How to protect yourself from the Ransomware WannaCry virus that has shaken the world ?!

WannaCry has spread so rapidly thanks to a tool created by the National Security Agency (NSA) that was released last month by the public hacker group Shadow Brokers. This tool works by providing access to a computer via the SMBv1 protocol.

The virus first downloads the TOR client and places it in the TaskData folder. It communicates with the management server using the client's TOR. Then, it encrypts the files on the computer and adds the.WNCRY extension to them, and in the encrypted folder creates the file @ Please_Read_Me @ .txt which contains questions and answers and the file @ WanaDecryptor @ .exe

Then, WannaCry deletes Shadow Volume Copies and disables Windows startup recovery, and clears Windows Server backup history. Finally, Wana Decryptor 2.0 is displayed with information on how to pay the ransom. The victim is promised that the files will be returned if he pays $ 300 in bitcoins. If you do not pay on time, the amount increases.

How to protect yourself?

Because of the way WannaCry is expanding, Microsoft has released patch updates for older versions of Windows, including Windows XP, Windows 8, and Windows Server 2003. A month ago, MS released an update (MS17-010) for current versions of Windows, ie. Windows Vista, Windows 7, Windows 8.1, Windows 10, and Windows Server 2008/2012/2016.

If you are using an older version of Windows and you are not sure if you have received a security update for this virus, you can download and install it manually from THIS link.

Manually disable SMBv1:

  1. Control panel \ Programs \ Programs and functions
  2. Turn Windows features on or off
  3. Disable "SMB 1.0" in the list
  4. Save and restart your computer
Manually disable SMBv1:

To check if SMBv1 is disabled, open CMD (win + r> cmd> enter), copy this code and type enter:

Get-SmbServerConfiguration | Select EnableSMB1Protocol, EnableSMB2Protocol

To check if SMBv1 is disabled, open CMD (win + r> cmd> enter), copy this code and type enter:

The first item should be "False" and the second "True". This means that v1 is disabled and v2 is enabled. If v2 is not enabled, run this command:

Set-SmbServerConfiguration -EnableSMB2Protocol $ true

More detailed instructions on the Microsoft site - link.

WannaCry is currently being stopped by a person signing up online as  MalwareTech. How? He looked at the virus and found an interesting domain iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com which registered for ten dollars and thus extinguished this virus.

The way this "switch" work is simple: WannaCry checks every time it starts to see if the domain is registered, if not - it continues to run. When MalwareTech registered the domain, the virus stopped spreading and thus permanently disabled the spread of this version of the virus. But, he warns that this solution is only for that version, hackers only need to change a piece of code and run the virus again.

Therefore, the best solution is to update your system regularly and use an updated Antivirus. Avast says that their anti-virus has a "software behavior" protection module and can detect this virus in time, and the module is available in all versions, even free.

You can view the current map of infected computers at this link:

https://intel.malwaretech.com/botnet/wcrypt

Comments

Popular this month

How to download the complete FB profile

UPDATE: The article has been updated. Click here. You have probably heard these days that the hacker group "Anonymous" will crash Facebook on November 5, 2011, maybe it will, maybe it won't. If you want to save all your pictures and videos, etc. you can do it in a few steps.

Five wishes from Google

Google is under investigation for allegedly abusing its strong position as a leader in the field of Internet search, and competing companies are suing Google and their partners, as this giant company is increasingly expanding into markets where it is already competitive.

This premium VPN gives free 17+ GB of bandwidth per month!

As you surf the internet your location is available on every site you visit. Basically, every site you visit knows your IP address, location, region, country . .. and much more. You don't believe it? Just look at this link and you will see your details: https://www.find-ip.net/ip-script If you don't already use a VPN, you can see your IP address, country, city, and region in the box above. Worrying?

Speccy - Get to know your computer in detail

The average user usually only knows what the CPU speed is, how much RAM it has, what the label is on the graphics card, and how much the HDD is… But he doesn't know some perhaps more important details. Speccy is a program that will reveal these details and you will have a complete insight into all the components that are inside your machine.

Look at historical objects in three dimensions

Google has launched a new Cultural Institute service where you can view some 3-dimensional historical objects on your computer in your favorite web browser. The items are detailed and you can enlarge them to see even the smallest parts. Of course, they are not perfect, there are some irregularities somewhere, but they were not noticed.