For those of you who were infected with WannaCry, very good news. If you see the WannaCry ransom screen: DON’T REBOOT. Matt Suiche has confirmed that
[See the full post at: Breaking: WannaCry has been decrypted, if you follow the rules]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Breaking: WannaCry has been decrypted, if you follow the rules
Home » Forums » Newsletter and Homepage topics » Breaking: WannaCry has been decrypted, if you follow the rules
- This topic has 12 replies, 4 voices, and was last updated 7 years, 11 months ago.
AuthorTopicViewing 5 reply threadsAuthorReplies-
anonymous
Guest -
anonymous
GuestMay 19, 2017 at 2:59 pm #116545I believe the regulars are busy, and may not respond. So I’ll give a go.
If you have been a faithful Group B and understand what you have been doing for more than 60ish days; then please, relax.
At least on this issue currently at hand. No matter what WinOS (you did not say), the green light (DEFCON3) after March 2017, had you install at least one patch to prevent this breach. Stand down, and wait for word.
If you are still concerned, more information about your situation from your chair is needed. Inviting correction from any regular…
Paul
1 user thanked author for this post.
-
woody
Manager
-
-
anonymous
Guest-
anonymous
GuestMay 19, 2017 at 5:28 pm #116550I’m glad to read you as more comfortable already. That is good.
You are not foolish to worry, and you are at the right place. You simply have misread a very confusing, fast developing threat that has already passed. The fact that you are reading this is proof you were not hit 7 days ago with the first strike.
Any new threats are very vague at this point, the only known point of failure was already addressed by Microsoft for Win7 (that’s you) in the March 2nd Tues cycle. As Group B, you followed special directions, and were already protected by the AskWoody team several weeks in advance.
I know it was scary, when all the announcements of impending doom named *every* OS patch under the sun, *except* yours. But that is because you already had it weeks ago.
AskWoody cannot see the future, but they are some of the best minds involved in the present. Stick with it. You’re doing it right.
Paul
anonymous
GuestMay 19, 2017 at 5:24 pm #116553I had responded, but failed moderation. Possibly because I assumed you are the same anonymous as above, without verification. And though I sign my posts, I have not joined.
I withdraw and hope you are addressed. What I do know, is if you can read this, your machine has not been encrypted.
Someone credentialed may come by soon.
Paul
-
PKCano
ManagerMay 19, 2017 at 5:29 pm #116564I had responded, but failed moderation.
Paul,
Your post did not fail moderation. Anonymous posters have to be moderated EVERY time they post. It is not instantaneous, and sometimes may take a good while.
On the other hand, registered posters do not have to be moderated so their posts are immediately available. (That’s an invitation to register). -
anonymous
GuestMay 19, 2017 at 6:30 pm #116565Thanks again, PKCano. I get it. I guess I’m just not there yet. I do not expect immediate, but it had been some time. And regret that even this adds to the load in your stack. You have a special skill for patience. Since I have already troubled you — engage humour:
What do you mean your elapsed time is different than mine?
I will reconsider joining before troubling you again.
Paul
1 user thanked author for this post.
-
woody
Manager
-
-
anonymous
GuestMay 20, 2017 at 8:17 pm #117059Oh, thank you, Woody. I was just coming back by here, to this thread, because I wanted to note the possible change a day makes. And to raise attention that my reassurances above *might* be outdated already. I defer to people who know better the protections offered by the May2017 cycle for this latest information on threats that occurred more than 9days ago.
Annon #116553 may have a point, and I lack information.
Concerned but not Worried,
PaulGoneToPlaid
AskWoody LoungerMay 20, 2017 at 10:48 pm #117079I am on Group B. Following, I am only talking about the Security Only updates. Installed on my Win7 machines are the March and May updates. I uninstalled the April update after first testing it on one of my machines and encountering many issues — including breaking the ability of Windows Update to download any new updates. Thus I skipped the April update for my other Win7 machines. So far the May update seems to be okay on all of my Win7 computers.
For Group B users, I would recommend that they install the May update in addition to the March update since the May update includes additional security fixes. Note that new malware has recently been discovered which not only uses over a half dozen stolen NSA tools, but also appears to be a “test run” for future malware which could easily be fully weaponized.
In addition to making sure that you have installed the March and May updates, you need to also make sure not only that your antivirus (AV) product is up-to-date, but also that your AV product is even capable of performing behavioral analysis in order to detect malware such as WannyCry and similar ransomware. Some AV products detect and immediately stop the ransomware. Other AV products currently only detect additional dropped files after the ransomware has already infected the computer. And of course some AV products detect nothing at all.
All Windows 7 and 8x users should disable SMB1 unless for some reason they still have some Windows XP computers on their network. If those users still have XP computers on their network, it would be far better to disable SMB1 and to immediately either replace or upgrade those XP computers.
Microsoft has published instructions for how to disable SMB1. Note that on most Windows 7 computers, the DWORD called SMB1 does not exist. You have to create it and set it to zero. This was a source of confusion for at least one person here. Microsoft’s instructions for disabling SMB1:
GoneToPlaid
AskWoody LoungerMay 21, 2017 at 12:42 am #117093Hmm…a utility which searches, in computer memory, for the prime numbers which were used to generate the encryption key, in order to regenerate the encryption key. Brilliant! Now, does anyone see a huge problem with this now publicly disclosed method since it has now been publicly shown that this can indeed be done? The road to Hell is paved with good intentions — in this case, to help people to potentially recover their files which were encrypted by WannaCry.
Matt Suiche, apparently with nothing other than good intentions, really didn’t think this through. He has now publicly shown that all encryption methods, starting on the source computer, can be defeated at the source by installing malware on the source which searches in memory and in real time for the prime numbers which are used to generate encryption keys. Such malware, from a heuristics and behavioral analysis standpoint within antivirus programs, potentially could be extremely difficult if not impossible to reliably detect.
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Download speeds only 0.3Mbps after 24H2 upgrade on WiFi and Ethernet
by
John
2 hours, 58 minutes ago -
T-Mobile 5G Wireless Internet
by
WSmmi16
1 hour, 58 minutes ago -
Clock missing above calendar in Windows 10
by
WSCape Sand
22 minutes ago -
Formula to Calculate Q1, Q2, Q3, or Q4 of the Year?
by
WSJon5
1 hour, 5 minutes ago -
The time has come for AI-generated art
by
Catherine Barrett
15 hours, 46 minutes ago -
Hackers are using two-factor authentication to infect you
by
B. Livingston
9 hours, 47 minutes ago -
23 and you
by
Max Stul Oppenheimer
15 hours, 48 minutes ago -
April’s deluge of patches
by
Susan Bradley
2 hours, 15 minutes ago -
Windows 11 Windows Updater question
by
Tex265
8 hours, 1 minute ago -
Key, Key, my kingdom for a Key!
by
RetiredGeek
1 day, 6 hours ago -
Registry Patches for Windows 10
by
Drcard:))
1 day, 11 hours ago -
Cannot get line length to NOT wrap in Outlining in Word 365
by
CWBillow
17 hours, 59 minutes ago -
DDU (Display Driver Uninstaller) updates
by
Alex5723
3 hours, 18 minutes ago -
Align objects on a OneNote page
by
CWBillow
1 day, 16 hours ago -
OneNote Send To button?
by
CWBillow
1 day, 17 hours ago -
WU help needed with “Some settings are managed by your organization”
by
Peobody
2 days, 2 hours ago -
No Newsletters since 27 January
by
rog7
6 hours, 45 minutes ago -
Linux Mint Debian Edition 7 gets OEM support, death of Ubuntu-based Mint ?
by
Alex5723
1 day, 2 hours ago -
Windows Update “Areca Technology Corporation – System – 6.20.0.41”
by
Bruce
1 day, 1 hour ago -
Google One Storage Questions
by
LHiggins
9 hours, 21 minutes ago -
Button Missing for Automatic Apps Updates
by
pmcjr6142
16 hours, 37 minutes ago -
Ancient SSD thinks it’s new
by
WSila
1 day, 7 hours ago -
Washington State lab testing provider exposed health data of 1.6 million people
by
Nibbled To Death By Ducks
2 days, 16 hours ago -
WinRE KB5057589 fake out
by
Susan Bradley
3 hours, 34 minutes ago -
The April 2025 Windows RE update might show as unsuccessful in Windows Update
by
Susan Bradley
2 days ago -
Firefox 137
by
Charlie
3 hours, 32 minutes ago -
Whisky, a popular Wine frontend for Mac gamers, is no more
by
Alex5723
3 days, 5 hours ago -
Windows 11 Insider Preview build 26120.3863 (24H2) released to BETA
by
joep517
3 days, 5 hours ago -
Windows 11 Insider Preview build 26200.5551 released to DEV
by
joep517
3 days, 5 hours ago -
New Windows 11 PC setup — can I start over in the middle to set up a local id?
by
ctRanger
2 days, 1 hour ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.