Bitcoin virus transmission means
with this tool, your computer won't have to worry about the virus problem
2. This kind of blackmail virus mainly infects windows system. It will use encryption technology to lock files, forbid users to access, and blackmail users
3. The attacker claimed that he could only unlock the file after asking for more than $300 worth of bitcoin. In fact, even if the ransom is paid, it may not be able to unlock the file
Why are they infected
once the blackmail worm attacks a user machine that can connect to the public network, it will scan the IP of the intranet and the public network. If the scanned IP has opened port 445, it will use the "enternal blue" vulnerability to install the back door. Once the backdoor is executed, a blackmailer virus named wana crypt0r will be released to encrypt all documents and files on the user's machine for blackmail
why use bitcoin
bitcoin is a kind of point-to-point network payment system and virtual pricing tool, commonly known as digital currency. Bitcoin is popular among cyber criminals because it is decentralized, unregulated and almost untraceable< Background of transmission and infection
this round of blackmailer worm virus mainly includes two family variants onion and wncry, which first broke out in Britain, Russia and other countries, and many enterprises and medical institutions were recruited in the system, resulting in heavy losses
global monitoring of security agencies has found that as many as 74 countries have suffered this blackmailer worm attack
since May 12, the spread of infection in China has also begun to increase sharply, and the outbreak has been intensified in many universities and enterprises
wannacry blackmail virus prevention method:
1. Install the latest security patch for the computer. Microsoft has released patch ms17-010 to fix the system vulnerability of "eternal blue" attack. Please install this security patch as soon as possible; For Windows XP, 2003 and other machines that Microsoft no longer provides security updates, we can use 360 "NSA Arsenal immunity tool" to detect whether there are vulnerabilities in the system, and close the ports affected by the vulnerabilities, so as to avoid being infringed by blackmail software and other viruses
2. Close ports 445, 135, 137, 138 and 139, and close network sharing
3. Strengthen the awareness of network security: don't click the unknown link, don't download the unknown file, don't open the unknown email...
4. Back up the important files in your computer to the mobile hard disk and U disk as soon as possible (regularly in the future), and save the disk offline after the backup
5. It is recommended that users who are still using Windows XP and windows 2003 should upgrade to Windows 7 / windows 10 or windows 2008 / 2012 / 2016 as soon as possible.
. This virus uses a variety of encryption algorithms to encrypt the file, the infected person is generally unable to decrypt, must get the private key to decrypt it is possible to crack
attack target: blackmail viruses generally do not attack anyone, but some of them are targeted at enterprise users (such as xtbl, wallet) and some of them are targeted at all users
this type of virus is highly targeted and mainly spread by e-mail
once the blackmail virus file is opened by the user, it will use the C & amp; Then upload the local information and download the encrypted public key and private key. Then, the encrypted public key and private key are written into the registry, and the office documents, pictures and other files in all local disks are traversed, and the format of these files is tampered and encrypted; After encryption is completed, blackmail prompt files will be generated at obvious locations such as the desktop to guide users to pay ransom
this type of virus can cause important files to be unreadable and key data to be damaged, which has a very serious impact on the normal work of users
preventive measures:
1. Start the firewall built in Windows first
2. Right click the network icon in the lower right corner - Sharing Center - Windows Firewall - Advanced Settings - inbound rules on the left - new port on the right - TCP - input these ports - deny access
this can be prevented (however, closing port 445 will make it impossible to share files)
bus line: No.8 holiday bus line, the whole journey is about 29.2km
1. Walk about 500m from Guangzhou Science and Technology Vocational and technical college to Guangdong instry and Trade Vocational and Technical College Station
< P > 2. Take No.8 holiday bus line, pass 5 stops, reach Huaying Road Station (subway Jiahe Wanggang station)3. Walk about 350m to Jiahe Wanggang station