Three years ago my friend's laptop attacked by Malware Ransomware. That malware encrypted all data in local disk D and local disk E except local disk C because all program in here.
Then I try to reinstalling operating system microsoft windows 7, i think success, but it doesn't work.
but don't wanna cry because there are solve the problem to fix it.
Here are some precautions to minimize infected Malware Ransomware Wannacrypt:
1. Do not connect on LAN / WIFI, Do Back Up Data
LAN AND WIFI is a network that can exchange data between computers connected to the network. The latest prevention to save your files is to
backup first, make sure when you do backup do not connect with LAN and WIFI first. This is to prevent malware from getting into your computer
system
2. Update AntiVirus
With this attack, of course, various Anti-Virus update to overcome the occurrence of Malware Ransomware Wannacrypt attacks. Make sure you use
trusted Antivirus to improve the security of your PC using Windows OS.
3. Update MS17-010 Patch Update on Windows OS
MS17-010 security patch released by Microsoft has actually been announced since last March. But it seems most of the computers in the world have
not installed them yet. So this laxity is exploited massively by WannaCrypt.Update security spreader on your windows by install Patch MS17-010
issued by microsoct. See:
https://technet.microsoft.com/en-us/library/security/ms17-010.aspx4. Non Enable SMB function v1
Microsoft took an unusual step to protect its customers with unsupported versions of Windows - including Windows XP, Vista, Windows 8, Server
2003 and 2008 - with the release of security patches fixing the SMB flaws currently exploited by WannaCry ransomware. After patch update
MS17- 010 on your Windows OS, do Disable on your computer's SMBv1 feature. Follow These Steps:
Log in to the .wcry virus (check image)
1. Go to safe mode
2. Click safe boot -> minimal, click ok and restart
3. Once restarted go to control panel -> folder options-> show hidden file then click apply
4. Go to msconfig -.startup -> Disable Program is suspicious or unknown, click ok and click "Exit without Restart"
5. Delete the malicious files
6. Check the next folder to find suspicious files:
% TEMP%
% APPDATA%
% Program Data%
(If there is a folder / File Wanna Cry delete directly)
7. Check the host file, Because it is biased with the same virus.
Locate local host
C: \ windows \ System32 \ driver \ etc
After that there is a file host then open with notepad
(There if there is an unknown site, then delete it directly)
8. After that go back to msconfig continue disable Safe Mode click OK then Restart
9. After restarted, there is no "Decryption Tool" now, but you can restore files from backup or restore a separate folder
10. Now you can see the old version of the encrypted file
11. Delete the file named:
A. Readme.txt.WCRY
B. License.txt.WCRY
C. History.txt.WCRY
D. ! Please Read Me! .txt
E. ! WantDecryptor1.exe
Good Luck!