• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

A utility to decrypt WannaCry ransomware

Joined
Nov 2, 2008
Messages
887 (0.16/day)
Processor Intel Core i3-8100
Motherboard ASRock H370 Pro4
Cooling Cryorig M9i
Memory 16GB G.Skill Aegis DDR4-2400
Video Card(s) Gigabyte GeForce GTX 1060 WindForce OC 3GB
Storage Crucial MX500 512GB SSD
Display(s) Dell S2316M LCD
Case Fractal Design Define R4 Black Pearl
Audio Device(s) Realtek ALC892
Power Supply Corsair CX600M
Mouse Logitech M500
Keyboard Lenovo KB1021 USB
Software Windows 10 Professional x64
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
In other words, if infected the number one thing you can do is NOT SHUTDOWN OR REBOOT.
 
Joined
Nov 2, 2008
Messages
887 (0.16/day)
Processor Intel Core i3-8100
Motherboard ASRock H370 Pro4
Cooling Cryorig M9i
Memory 16GB G.Skill Aegis DDR4-2400
Video Card(s) Gigabyte GeForce GTX 1060 WindForce OC 3GB
Storage Crucial MX500 512GB SSD
Display(s) Dell S2316M LCD
Case Fractal Design Define R4 Black Pearl
Audio Device(s) Realtek ALC892
Power Supply Corsair CX600M
Mouse Logitech M500
Keyboard Lenovo KB1021 USB
Software Windows 10 Professional x64
I was just coming back to update my post with that info. If you reboot the infected PC before running the utility, then the information needed to reconstruct the decryption key is gone.
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,673 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
I read that article earlier today and intended on sharing it, thanks for doing so! This is something critical for those that do get hit by this. :toast:
 

fullinfusion

Vanguard Beta Tester
Joined
Jan 11, 2008
Messages
9,909 (1.67/day)
How is this ransomware infecting PC's?

Going to bad sites or...?
 
Joined
Oct 18, 2007
Messages
1,288 (0.21/day)
System Name Firebird
Processor Intel i7 2600K @5.0'ish 24/7 stock core Voltage {5.2 w/102 bCLK}
Motherboard Intel Extreme DZ68BC SkullTrail Z68 Cougerpoint, Excellent MCH !
Cooling Scythe NINJA PLUS Rev.B[skt478] Modded to 1155 Scythe SH12 fan
Memory Samsung 32nm 16Gb 4x4 (@19xxmhz} low profile[ better than 2133 banwidth]
Video Card(s) Gigabyte Aurosus 1080Ti
Storage Intel 512 SSD,Samsung 9701Tb, Toshiba 3Tbx2,Hitachi 320,1TBx2,'Cuda 400 7200.10, WD1TBUSB,to SATA
Display(s) Acer K272HUL 1440 27" WQHD, Samsung 226W, Vizio M60C3 4K 60",Vizio XVT3D554SV
Case CoolerMaster HAF 932
Audio Device(s) Intel 10ch[9+1] HD Audio X540> Pioneer VSX39TX[copper chasis,Rosewood sides 5x6LCD remote
Power Supply Seasonic X750 @ 24/7
Mouse Logictech G300s
Keyboard Saitek Cyborg v7
Software Windows 7 ROG E3 X64 by Neuropass/tweakscene
Benchmark Scores 4642@665/1600 220/GAT F1 4544 220/667strap 2.5/3/2/6 Bliss 650/1500 6490 Q6700 Bliss 690/1500
How is this ransomware infecting PC's?

Going to bad sites or...?
I asked pretty much the same a couple days ago,........no responses and unsure from reading on the web, but it still has the ability to just scour the web looking for some SMB holes for sure.
So not clear if any website like that other TecH site with shit tons of ad's can carry an infection in it.
 
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I asked pretty much the same a couple days ago,........no responses and unsure from reading on the web, but it still has the ability to just scour the web looking for some SMB holes for sure.
So not clear if any website like that other TecH site with shit tons of ad's can carry an infection in it.

As I said earlier, it's really not hard to scour the complete IPv4 range for open ports given a little time and effort.

So your basic answer is open ports + not patched = probably infected.
 
Joined
Nov 2, 2008
Messages
887 (0.16/day)
Processor Intel Core i3-8100
Motherboard ASRock H370 Pro4
Cooling Cryorig M9i
Memory 16GB G.Skill Aegis DDR4-2400
Video Card(s) Gigabyte GeForce GTX 1060 WindForce OC 3GB
Storage Crucial MX500 512GB SSD
Display(s) Dell S2316M LCD
Case Fractal Design Define R4 Black Pearl
Audio Device(s) Realtek ALC892
Power Supply Corsair CX600M
Mouse Logitech M500
Keyboard Lenovo KB1021 USB
Software Windows 10 Professional x64
There is a nasty flaw in the SMB (Server Message Block) v1 code found in all versions of Windows from XP to 10, including Server 2003 to 2016. SMB is the network file sharing protocol, and it is enabled by default in Windows. No one in their right mind would allow SMB access from the Internet, but you'd be surprised by how many Windows machines do this.

The "seed" machines scanned for open SMB ports on Internet-connected machines. When they found one, they exploited the security flaw to upload the WannaCry code and launch it. The malware then encrypted a large number of file types on the local drives and file shares. It also scanned for and infected other vulnerable machines on the local network. Based on this behavior, WannaCry is actually a worm, not a virus. You don't have to launch an infected program or open an infected document; the malware seeks out vulnerable machines on its own. If you want the technical details, Malwarebytes Labs has a write-up here.
 
Joined
Oct 17, 2012
Messages
9,781 (2.33/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
I noticed today that my Malwarebytes began to act odd. Showing notifications that certain protections were disabled(web protection & i couldnt re-enable the service either), and when I would run a scan it would only go for a second and then end showing successful without a virus. I double checked to verify that I wasn't infected and I also disabled SMBV1 A while ago ,but I was still concerned. The reason Im mentioning this is because I ended up looking at another one of my computers and it was also behaving the same on that PC too,& different operating system though(just in case someone else might benefit from checking/finding a similar issue). The only solution I could find was to uninstall malwarebites, restart, run the Malwarebytes clean removal tool, restart again and then install anew. That fixed it on both computers,& The issue has not manifested again , hopefully it was just an issue with malwarebites, but all this talk about worms and viruses got me nervous and paranoid :fear:
 
Joined
Aug 20, 2007
Messages
20,759 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I noticed today that my Malwarebytes began to act odd. Showing notifications that certain protections were disabled(web protection & i couldnt re-enable the service either), and when I would run a scan it would only go for a second and then end showing successful without a virus. I double checked to verify that I wasn't infected and I also disabled SMBV1 A while ago ,but I was still concerned. The reason Im mentioning this is because I ended up looking at another one of my computers and it was also behaving the same on that PC too,& different operating system though(just in case someone else might benefit from checking/finding a similar issue). The only solution I could find was to uninstall malwarebites, restart, run the Malwarebytes clean removal tool, restart again and then install anew. That fixed it on both computers,& The issue has not manifested again , hopefully it was just an issue with malwarebites, but all this talk about worms and viruses got me nervous and paranoid :fear:

@Bill_Bright mentioned that MB has been having issues like that lately. I wouldn't lose sleep over it.
 
Joined
Oct 17, 2012
Messages
9,781 (2.33/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
@Bill_Bright mentioned that MB has been having issues like that lately. I wouldn't lose sleep over it.

I've actually experienced it several times in the past as well but I'm aware that it's irrational to worry :rolleyes:I've taken the steps before this worm was released to disable the exploit it uses. The steps that I used to fix malwarebites are the recommended steps by their support team ,if anyone's reading this and counters a similar issue , use the steps in post #9
 
Joined
Apr 2, 2009
Messages
3,505 (0.64/day)
It's called port scanning (also probing) and usually done by cheap VPS (Virtual private server). If you hang around web hosting forums, you will see countless people wanting two things.

1. Cheap VPS
2. Anonymity

They are usually the ones that do port scanning and plan their next move. Unfortunately, web hosting market is too competitive and new web hosting companies (usually one-man op) have to take every customers they can get, so they take in those shady people.
 
Top