Jump to content

Wanna Cry ramsomware

So i just watched the Wan Show, and i didn't quite understand it, to be safe i don't have to download the latest windows update? Luke said that most people doesn't have their windows update activated, or do i need to have the latest update?

CPU: Ryzen 5 5600x | MB: Asus TUF Gaming B550-Plus | RAM: Crucial Ballistix RGB 16Gb 3200Mhz | GPU: Gigabyte GTX 1080 Windforce | Cooler: Scythe Fuma 2 | PSU: EVGA SuperNOVA 650 G2 | SSD: Crucial MX300 275Gb | HDD: WD Black 2Tb | Monitor: LG 27GL83A

Link to comment
Share on other sites

Link to post
Share on other sites

You should update just in case. The update that patched the EternalBlue exploit was released back in March, so if you updated from April to now you should be okay, but it won't hurt to update anyway. 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Oshino Shinobu said:

You should update just in case. The update that patched the EternalBlue exploit was released back in March, so if you updated from April to now you should be okay, but it won't hurt to update anyway. 

Alright thanks.

CPU: Ryzen 5 5600x | MB: Asus TUF Gaming B550-Plus | RAM: Crucial Ballistix RGB 16Gb 3200Mhz | GPU: Gigabyte GTX 1080 Windforce | Cooler: Scythe Fuma 2 | PSU: EVGA SuperNOVA 650 G2 | SSD: Crucial MX300 275Gb | HDD: WD Black 2Tb | Monitor: LG 27GL83A

Link to comment
Share on other sites

Link to post
Share on other sites

I have not watched it yet but he probably meant that most people have disabled the W10 update service cuz of the forced update thing.

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, TAHIRMIA said:

I have not watched it yet but he probably meant that most people have disabled the W10 update service cuz of the forced update thing.

Yeah all the dumb people who can't be bothered for a few minutes a month and think disabling updates is good xD

NEW PC build: Blank Heaven   minimalist white and black PC     Old S340 build log "White Heaven"        The "LIGHTCANON" flashlight build log        Project AntiRoll (prototype)        Custom speaker project

Spoiler

Ryzen 3950X | AMD Vega Frontier Edition | ASUS X570 Pro WS | Corsair Vengeance LPX 64GB | NZXT H500 | Seasonic Prime Fanless TX-700 | Custom loop | Coolermaster SK630 White | Logitech MX Master 2S | Samsung 980 Pro 1TB + 970 Pro 512GB | Samsung 58" 4k TV | Scarlett 2i4 | 2x AT2020

 

Link to comment
Share on other sites

Link to post
Share on other sites

you should update or pay for malwarebytes both solve that problem. I just updated because of this exploit, I would really recommend it

Project Iridium:   CPU: Intel 4820K   CPU Cooler: Custom Loop  Motherboard: Asus Rampage IV Black Edition   RAM: Avexir Blitz  Storage: Samsung 840 EVO 250GB SSD and Seagate Barracuda 3TB HDD   GPU: Asus 780 6GB Strix   Case: IN WIN 909   PSU: Corsair RM1000      Project Iridium build log http://linustechtips.com/main/topic/451088-project-iridium-build-log/

 

Link to comment
Share on other sites

Link to post
Share on other sites

1703 build boois.

|EVGA 850 P2| |1440p PG279Q| |X570 Aorus Extreme| |Ryzen 9 3950x WC| |FE 2080Ti WC|TridentZ Neo 64GB| |Samsung 970 EVO M.2 1TB x3

 |Logitech G900|K70 Cherry MX Speed|  |Logitech Z906 |  |HD650|  |CaseLabs SMA8 (one of the last ones made)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Enderman said:

Yeah all the dumb people who can't be bothered for a few minutes a month and think disabling updates is good xD

I've been tempted to cuz it takes a really long time but then they started to allow scheduling so I left it on.

1 minute ago, Maybach123 said:

you should update or pay for malwarebytes both solve that problem. I just updated because of this exploit, I would really recommend it

If updating fixes it why would people pay for Malwarebytes Pro

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

I disabled windows updates. If Microsoft was nice enough to have:

Forced: Strictly Security Updates

Optional: OS optimization and menu changes

I'd just disable the optimization and menu changes but no. It's one giant bundle package to Microsoft and they don't care if you like your OS exactly the way it is. So I take the risks so my machine doesn't change without my permission.

 

Not to mention updates that change things other than security are more likely to make your applications stop working.

non-windows example: Java updated to V8U131 recently. Their update made my IPMI remote desktop sessions stop working. Telling me the connection to A LOCAL SERVER ON A PRIVATE NETWORK was no longer acceptable due to a weak signature key. Nothing I tried fixed it except rolling back the driver and disabling updates.

Link to comment
Share on other sites

Link to post
Share on other sites

Some places (in fact most of the sites i managed before), have a very low internet bandwidth. Most of them is only 1 Mbps - 2 Mbps at best, so any application that uses so much bandwidth needs to be disabled or blocked at firewall level.

 

I always block all windows update domains and windows store on router level, so updates will never be downloaded.

 

However, every sites is instructed to use wsusoffline tool to download the updates on one computer and install it on every computer. This method is not perfect, as you should use proper Windows provided tool (local windows update server).

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, TAHIRMIA said:

If updating fixes it why would people pay for Malwarebytes Pro

I dont know just giving a second option. 

Project Iridium:   CPU: Intel 4820K   CPU Cooler: Custom Loop  Motherboard: Asus Rampage IV Black Edition   RAM: Avexir Blitz  Storage: Samsung 840 EVO 250GB SSD and Seagate Barracuda 3TB HDD   GPU: Asus 780 6GB Strix   Case: IN WIN 909   PSU: Corsair RM1000      Project Iridium build log http://linustechtips.com/main/topic/451088-project-iridium-build-log/

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, TAHIRMIA said:

I've been tempted to cuz it takes a really long time but then they started to allow scheduling so I left it on.

If updating fixes it why would people pay for Malwarebytes Pro

Because some people absolutely refuse to let Windows 10 update.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, TAHIRMIA said:

I have not watched it yet but he probably meant that most people have disabled the W10 update service cuz of the forced update thing.

My take from the discussion is that on a corporate or business level, updates are disabled in order to allow for system admins to validate the update prior to mass deployment.  They also do this as well to prevent the updates from installing en mass at an inconvenient time, like when there is a high volume of access requests to a server.  

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, WMGroomAK said:

My take from the discussion is that on a corporate or business level, updates are disabled in order to allow for system admins to validate the update prior to mass deployment.  They also do this as well to prevent the updates from installing en mass at an inconvenient time, like when there is a high volume of access requests to a server.  

 

Yh, it's more of a convenience sort of thing, But I think after this the validation is going to be done a lot quicker for most companies

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, TAHIRMIA said:

most people have disabled the W10 update service

This is a lie

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

Just now, DrMacintosh said:

This is a lie

Some then! xD

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

26 minutes ago, khazad said:

So i just watched the Wan Show, and i didn't quite understand it, to be safe i don't have to download the latest windows update? Luke said that most people doesn't have their windows update activated, or do i need to have the latest update?

You should. Doesn't take that long. The risks are just way too serious to ignore Windows Update. While you're at it, you may want to consider switching to some other third party AVs. Only 30% of the AVs out there detected and blocked WannaCry even before the news broke.

Quote

Security experts point out that some antivirus software is capable of catching the Wanna Decryptor virus.

 

"This particular ransomware is correctly identified and blocked by 30% of the AV vendors using current virus definitions. It is correctly handled by both Kaspersky and BitDefender," said Phil Richards, the CISO at Ivanti.

 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, hey_yo_ said:

You should. Doesn't take that long. The risks are just way too serious to ignore Windows Update. While you're at it, you may want to consider switching to some other third party AVs. Only 30% of the AVs out there detected and blocked WannaCry even before the news broke.

 

Yeah, i have malwarebytes pro.

CPU: Ryzen 5 5600x | MB: Asus TUF Gaming B550-Plus | RAM: Crucial Ballistix RGB 16Gb 3200Mhz | GPU: Gigabyte GTX 1080 Windforce | Cooler: Scythe Fuma 2 | PSU: EVGA SuperNOVA 650 G2 | SSD: Crucial MX300 275Gb | HDD: WD Black 2Tb | Monitor: LG 27GL83A

Link to comment
Share on other sites

Link to post
Share on other sites

35 minutes ago, Windows7ge said:

I disabled windows updates. If Microsoft was nice enough to have:

Forced: Strictly Security Updates

Optional: OS optimization and menu changes

I'd just disable the optimization and menu changes but no. It's one giant bundle package to Microsoft and they don't care if you like your OS exactly the way it is. So I take the risks so my machine doesn't change without my permission.

 

Not to mention updates that change things other than security are more likely to make your applications stop working.

non-windows example: Java updated to V8U131 recently. Their update made my IPMI remote desktop sessions stop working. Telling me the connection to A LOCAL SERVER ON A PRIVATE NETWORK was no longer acceptable due to a weak signature key. Nothing I tried fixed it except rolling back the driver and disabling updates.

Microsoft need to split their upgrades from security. Security updates should be forced, upgrades optional.

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, khazad said:

Yeah, i have malwarebytes pro.

I have Linux lol

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, vorticalbox said:

I have Linux lol

k7X8hlu.jpg

CPU: Ryzen 5 5600x | MB: Asus TUF Gaming B550-Plus | RAM: Crucial Ballistix RGB 16Gb 3200Mhz | GPU: Gigabyte GTX 1080 Windforce | Cooler: Scythe Fuma 2 | PSU: EVGA SuperNOVA 650 G2 | SSD: Crucial MX300 275Gb | HDD: WD Black 2Tb | Monitor: LG 27GL83A

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, khazad said:

-SNIP-

 

As long as its safe from Wana Cry:P

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

Does this Ransomware affect Windows 7 ?

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, elis said:

Does this Ransomware affect Windows 7 ?

Yes, Unless you are all updated!

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

Does it affect all local disks or only the one with the system ?

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×