Three departments in Beijing issued a notice: New variants of ransomware appear and it is recommended to deal with them immediately

Three departments in Beijing issued a notice: New variants of ransomware appear and it is recommended to deal with them immediately

As the ransomware continues to spread, three departments in Beijing jointly issued a notice stating that relevant departments have monitored and found that the virus has mutated into a variant that may spread even faster, and they recommend immediate attention and disposal.

According to Qianlong.com, on May 14, the Beijing Municipal Cyberspace Administration, Beijing Municipal Public Security Bureau, and Beijing Municipal Commission of Economy and Information Technology jointly issued a "Notice on the Emergence of Variants of the WannaCry Ransomware Worm and Suggestions on Disposal". The "Notice" pointed out that relevant departments have discovered that a variant of the WannaCry ransomware worm has appeared: WannaCry 2.0.

The notice stated that unlike previous versions, this variant has cancelled the so-called Kill Switch, and the spread of the variant ransomware worm cannot be stopped by registering a domain name. The spread of this variant may be faster, and the relevant disposal methods for this variant are the same as previous versions. It is recommended to pay attention to and dispose of it immediately.

Since the evening of May 12, the WannaCry ransomware worm has spread rapidly around the world, and has now caused more than 75,000 computers in 99 countries and regions to be attacked by the virus. Hackers locked the data files in the computers and demanded a payment of $300 in Bitcoin to unlock the files.

The following is the full text of the notice:

Notice on the emergence of variants of the WannaCry ransomware worm and suggestions for handling it

All relevant units:

Relevant departments have discovered that a variant of the WannaCry ransomware worm has emerged: WannaCry 2.0. Unlike previous versions, this variant has cancelled the so-called Kill Switch, and the spread of the variant ransomware worm cannot be stopped by registering a domain name. The spread of this variant may be faster. The relevant disposal methods for this variant are the same as previous versions. It is recommended to pay attention to and dispose of it immediately.

1. Please immediately organize an intranet detection to find all terminals and servers with open 445 SMB service port. Once a infected machine is found, disconnect it from the network immediately. At present, it seems that formatting the hard disk can remove the virus.

2. Microsoft has released patch MS17-010 to fix the system vulnerability of "Eternal Blue" attack. Please install this patch for your computer as soon as possible. The website address is https://technet.microsoft.com/zh-cn/library/security/MS17-010. For machines such as XP and 2003 that Microsoft no longer provides security updates, it is recommended to upgrade the operating system version or close the ports affected by the vulnerability to avoid being attacked by viruses such as ransomware.

3. Once a infected machine is found, disconnect from the Internet immediately.

4. Enable and open "Windows Firewall", enter "Advanced Settings", and disable the "File and Printer Sharing" related rules in the inbound rules. Close UDP ports 135, 445, 137, 138, and 139, and turn off network file sharing.

5. It is strictly prohibited to use USB flash drives, mobile hard disks and other devices that can perform ferry attacks.

6. Back up important files and data in your computer to a storage device as soon as possible.

7. Update the operating system and applications to the latest version in a timely manner.

8. Strengthen email security and effectively block phishing emails to eliminate many hidden dangers. 9. Install genuine operating systems, Office software, etc.

Beijing Municipal Cyberspace Administration

Beijing Municipal Public Security Bureau

Beijing Municipal Commission of Economy and Information Technology

May 14, 2017

<<:  Ransomware virus sweeps the world, Bitcoin price drops by nearly $100

>>:  5.14 Belt and Road Summit VS Bitcoin Ransomware

Recommend

A mole on the chin means wealth and honor. The meaning of a mole on the chin

Many people with fortunes of great wealth and hon...

How to read the face and the fate of women

A woman's fate is actually reflected to a lar...

What kind of palmistry indicates bad career luck

A successful career seems to mean both fame and f...

The facial features of people who always like to worry about things

Are there people like this around you? They like ...

People with these palm lines are weak and sickly

People with these palm lines are weak and sickly ...

Judging from the body shape, what kind of women are blessed

In fact, a woman's body shape can be used to ...

Understanding Bitcoin Market Participants - Miners Drive Bitcoin Prices

Many analysts believe that the minimum price of B...

Mining Network - Mining Learning Exchange Group 3

Mining Network - Mining Learning Exchange Group 3...

How to read the Sichuan hand lines

As the name suggests, the three main lines in the...

How lucky you are in love in this life can be seen from your moles

In physiognomy, the moles on different parts of a...

Is it a blessing to have hairy ears? What are the facial features?

There are many detailed features in facial featur...