Microsoft - Customer Guidance for WannaCrypt attacks

Brink

Administrator
Staff member
Local time
3:16 AM
Messages
74,810
Location
Oklahoma
Microsoft solution available to protect additional productsToday many of our customers around the world and the critical systems they depend on were victims of malicious “WannaCrypt” software. Seeing businesses and individuals affected by cyberattacks, such as the ones reported today, was painful. Microsoft worked throughout the day to ensure we understood the attack and were taking all possible actions to protect our customers. This blog spells out the steps every individual and business should take to stay protected. Additionally, we are taking the highly unusual step of providing a security update for all customers to protect Windows platforms that are in custom support only, including Windows XP, Windows 8, and Windows Server 2003. Customers running Windows 10 were not targeted by the attack today.

Details are below.

  • In March, we released a security update which addresses the vulnerability that these attacks are exploiting. Those who have Windows Update enabled are protected against attacks on this vulnerability. For those organizations who have not yet applied the security update, we suggest you immediately deploy Microsoft Security Bulletin MS17-010.
  • For customers using Windows Defender, we released an update earlier today which detects this threat as Ransom:Win32/WannaCrypt. As an additional “defense-in-depth” measure, keep up-to-date anti-malware software installed on your machines. Customers running anti-malware software from any number of security companies can confirm with their provider, that they are protected.
  • This attack type may evolve over time, so any additional defense-in-depth strategies will provide additional protections. (For example, to further protect against SMBv1 attacks, customers should consider blocking legacy protocols on their networks).
We also know that some of our customers are running versions of Windows that no longer receive mainstream support. That means those customers will not have received the above mentioned Security Update released in March. Given the potential impact to customers and their businesses, we made the decision to make the Security Update for platforms in custom support only, Windows XP, Windows 8, and Windows Server 2003, broadly available for download (see links below).

Customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March. If customers have automatic updates enabled or have installed the update, they are protected. For other customers, we encourage them to install the update as soon as possible.

This decision was made based on an assessment of this situation, with the principle of protecting our customer ecosystem overall, firmly in mind.

Some of the observed attacks use common phishing tactics including malicious attachments. Customers should use vigilance when opening documents from untrusted or unknown sources. For Office 365 customers we are continually monitoring and updating to protect against these kinds of threats including Ransom:Win32/WannaCrypt. More information on the malware itself is available from the Microsoft Malware Protection Center on the Windows Security blog. For those new to the Microsoft Malware Protection Center, this is a technical discussion focused on providing the IT Security Professional with information to help further protect systems.

We are working with customers to provide additional assistance as this situation evolves, and will update this blog with details as appropriate.

Update 5/22/2017: Today, we released an update to the Microsoft Malicious Software Removal Tool (MSRT) to detect and remove WannaCrypt malware. For customers that run Windows Update, the tool will detect and remove WannaCrypt and other prevalent malware infections. Customers can also manually download and run the tool by following the guidance here. The MSRT tool runs on all supported Windows machines where automatic updates are enabled, including those that aren’t running other Microsoft security products.

See: KB890830 Windows Malicious Software Removal Tool 5.48 - May 2017 - Windows 7 Help Forums

Phillip Misner, Principal Security Group Manager Microsoft Security Response Center

Further resources:
Download English language security updates: Windows Server 2003 SP2 x64, Windows Server 2003 SP2 x86, Windows XP SP2 x64, Windows XP SP3 x86, Windows XP Embedded SP3 x86, Windows 8 x86, Windows 8 x64

Download localized language security updates: Windows Server 2003 SP2 x64, Windows Server 2003 SP2 x86, Windows XP SP2 x64, Windows XP SP3 x86, Windows XP Embedded SP3 x86, Windows 8 x86, Windows 8 x64

General information on ransomware: https://www.microsoft.com/en-us/security/portal/mmpc/shared/ransomware.aspx

MS17-010 Security Update: https://technet.microsoft.com/en-us/library/security/ms17-010.aspx


Source: Customer Guidance for WannaCrypt attacks MSRC


See also: WannaCrypt ransomware worm targets out-of-date systems Windows Security
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Hi Brink
I dont see one for WIN7 in the above list - was it included in the security only KB4012212 for March 2017?
Antioch
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Professional SPI 64bit
CPU
Intel Core i5 Quad i5-6600 3.3Ghz
Motherboard
ASUS H110M-R
Memory
16GB Hyper X Fury
Graphics Card(s)
3GB Geforce GTX1060
Hard Drives
1TB SATA-III
1TB WD MyPassport Ultra
PSU
Corsair 550 VS Series
Case
Corsair 100R
Cooling
Noctua NH-U14S
Mouse
Microsoft wireless - plus cheap wired mouse for ext HD
Internet Speed
150MB
Antivirus
Avast Free
Browser
Firefox
Hi Brink
I dont see one for WIN7 in the above list - was it included in the security only KB4012212 for March 2017?
Antioch

Hi Antioch,
if you installed either the March quality rollup or the March Security-only update then you're patched against that variant of Wannacrypt. I'm sure there will be more variations of it popping up in future though.

Be sure to keep all your security software (Anti-Virus/Malware) up to date. Another good piece of software I use is CryptoPrevent which is specifically designed to protect against Ransomware. There are also free Anti-Ransomware programs from other vendors, such as BitDefender.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate, Win 8.1 Pro, Linux Mint 19 Cinnamon (All 64-Bit)
CPU
Intel i5 4690K
Motherboard
Gigabyte Z97X-UD3H
Memory
Corsair Vengeance LP 32GB DDR3
Graphics Card(s)
MSI GTX 1060 GAMING X 6GB
Sound Card
Onboard
Hard Drives
Samsung 850 EVO 250GB SSD (x2)
Samsung 860 EVO 1TB SSD (x2)
Crucial MX300 525GB SSD
WD Blue 2TB 5400rpm Intellipark Disabled (x2)
PSU
Corsair HX750i
Case
Phanteks Enthoo Pro
Cooling
CM Hyper 212 EVO on CPU, Noctua Redux NF-P14S 1500rpm (x6)
Keyboard
Corsair K70 RGB LUX
Mouse
Corsair Sabre RGB
Antivirus
Avast Free, MalwareBytes, SAS & CryptoPrevent
Browser
Chrome
Other Info
StarTech PEXESAT322I 2 Port PCI-E SATA Card
ASUS PCE-AC56 Dual-band AC1300 Wireless Card
Akasa FC.Six Manual Fan Controller
And a Partridge in a Pear Tree!
:ditto:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Correct me if I'm wrong, but, isn't this worm specifically (if not mainly) designed for enterprises? Not to make this less important, but seems they are more at risk than home users as far as I tell...

Anyway, just patched both my W7 machines, and installed the cumulative update for the W10 one...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Assembled Desktop PC
OS
Microsoft Windows 7 Home Premium SP1 64-bit Build 7600
CPU
AMD Athlon 64 X2 5200+ Dual Core CPU @ 2.7 Ghz (Brisbane)
Motherboard
PCChips A13G+ v3.0
Memory
2x2 GB DDR2 PC-5300 (667 Mhz) Kingston ValueRAM
Graphics Card(s)
XFX ATI Radeon HD 4350 GPU (512 MB + 512 MB HM)
Sound Card
Realtek High Definition Audio Driver ALC660 @ MCP61S
Monitor(s) Displays
HP S2031 20" LED HD Widescreen Display Monitor
Screen Resolution
1600 x 900 px
Hard Drives
Maxtor Diamond Max 10 (160 GB, 7200 RPM, SATA-II Hard Disk)
Western Digital Scorpion Blue (250 GB, 5400 RPM, SATA-II External Hard Disk - Personal Data)
Toshiba MQ01ABD050 (500 GB, 5400 RPM, SATA-II External Hard Disk - Software & ISOs)
PSU
Pixxo Transformer 850W 80+ Certification PSU
Case
Compaq 5BW353 Case
Cooling
Many solutions, see other info...
Keyboard
Green Leaf (Mitzu) Standard Keyboard
Mouse
Microsoft USB Lasser Pointing Device
Internet Speed
10 MB
Antivirus
Avast Antivirus Free
Browser
Firefox, Chrome, Internet Explorer
Other Info
Windows Experience Index Result: 3.8 of 7.9.

Cooling solutions:
- AVC @ 2000/5000 RPM Copper Heatpipes (For Athlon 64 X2 6000+ CPU used in an Athlon 64 X2 5200+)
- Rear Fan 80 mm @ 2700 RPM for heat extraction
- Manhatan Chipset Cooler @ 4700/7200 RPM (For nVidia Chipset in MoBo)
- Foxconn @ 2500 RPM (Old Pentium III heatsink fan) in XFX ATI Radeon HD 4350

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Assembled Desktop PC
OS
Microsoft Windows 7 Home Premium SP1 64-bit Build 7600
CPU
AMD Athlon 64 X2 5200+ Dual Core CPU @ 2.7 Ghz (Brisbane)
Motherboard
PCChips A13G+ v3.0
Memory
2x2 GB DDR2 PC-5300 (667 Mhz) Kingston ValueRAM
Graphics Card(s)
XFX ATI Radeon HD 4350 GPU (512 MB + 512 MB HM)
Sound Card
Realtek High Definition Audio Driver ALC660 @ MCP61S
Monitor(s) Displays
HP S2031 20" LED HD Widescreen Display Monitor
Screen Resolution
1600 x 900 px
Hard Drives
Maxtor Diamond Max 10 (160 GB, 7200 RPM, SATA-II Hard Disk)
Western Digital Scorpion Blue (250 GB, 5400 RPM, SATA-II External Hard Disk - Personal Data)
Toshiba MQ01ABD050 (500 GB, 5400 RPM, SATA-II External Hard Disk - Software & ISOs)
PSU
Pixxo Transformer 850W 80+ Certification PSU
Case
Compaq 5BW353 Case
Cooling
Many solutions, see other info...
Keyboard
Green Leaf (Mitzu) Standard Keyboard
Mouse
Microsoft USB Lasser Pointing Device
Internet Speed
10 MB
Antivirus
Avast Antivirus Free
Browser
Firefox, Chrome, Internet Explorer
Other Info
Windows Experience Index Result: 3.8 of 7.9.

Cooling solutions:
- AVC @ 2000/5000 RPM Copper Heatpipes (For Athlon 64 X2 6000+ CPU used in an Athlon 64 X2 5200+)
- Rear Fan 80 mm @ 2700 RPM for heat extraction
- Manhatan Chipset Cooler @ 4700/7200 RPM (For nVidia Chipset in MoBo)
- Foxconn @ 2500 RPM (Old Pentium III heatsink fan) in XFX ATI Radeon HD 4350
Many thanks to Brds and Brink for confirming. I have KB4012212 installed.

Antioch
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Professional SPI 64bit
CPU
Intel Core i5 Quad i5-6600 3.3Ghz
Motherboard
ASUS H110M-R
Memory
16GB Hyper X Fury
Graphics Card(s)
3GB Geforce GTX1060
Hard Drives
1TB SATA-III
1TB WD MyPassport Ultra
PSU
Corsair 550 VS Series
Case
Corsair 100R
Cooling
Noctua NH-U14S
Mouse
Microsoft wireless - plus cheap wired mouse for ext HD
Internet Speed
150MB
Antivirus
Avast Free
Browser
Firefox
Back
Top