my pc is hacked. please help me

HSW

Well-known member
  • Nov 18, 2016
    3,475
    1
    519
    113
    දැන් හිරු news වලටත් කිව්වා ransomeware attack එක ගැන.
     

    D_Mad

    Well-known member
  • Jun 11, 2013
    25,606
    42,097
    113
    Deniyaya
    හරි හරි උබ කියන්නෙ දැන් උබෙ ලැපටත් රැන්සම්වෙයා එක එෆ්ෆෙcට් උනා කියලනේ...

    මම දැක්කා උබ උදෙත් ත්‍රේඩ්1ක් දාගෙන දගලනවා..
     

    HSW

    Well-known member
  • Nov 18, 2016
    3,475
    1
    519
    113
    okata kiyanne ransomware attack kiyala. kerima kattak kapu ekek thama man oya huttappara seen eka nisa. qatar wala kalin weda karapu company eke finance department ekama encrypt una oya ransomware ekakin. 1500kage payroll hitan thibba. :dull: ransomware stop karanna denata hodama guard eka malwarebytes kiyana eka
    encrypt උනහම recover කරන්ඩ පුලුවන්ද ? අහලා තියෙන විදියට hacker ගාව තියෙන key එක නැතුව බෑ..
     

    dileeshakr

    Well-known member
  • Jan 9, 2009
    3,600
    656
    113
    127.0.0.1
    okata kiyanne ransomware attack kiyala. kerima kattak kapu ekek thama man oya huttappara seen eka nisa. qatar wala kalin weda karapu company eke finance department ekama encrypt una oya ransomware ekakin. 1500kage payroll hitan thibba. :dull: ransomware stop karanna denata hodama guard eka malwarebytes kiyana eka

    kohomada PC ekata meka enne?
     

    BlueBat

    Member
    Aug 14, 2011
    15,181
    1,092
    0
    encrypt උනහම recover කරන්ඩ පුලුවන්ද ? අහලා තියෙන විදියට hacker ගාව තියෙන key එක නැතුව බෑ..

    be ban format kala PC okkoma. effect wenna kalin dawase re beckup gahana hinda edata wenakan data thibba. effect una dawase ude waruwe weda karapu details thama lost une. lost una tiketh oya data recovery software dala 70% wage apahu gaththa. :(
     

    genius_EK

    Well-known member
  • Jan 8, 2011
    3,794
    457
    83
    ۩ Apocrypha ۩
    SL CERT Alert!


    Systems Affected

    Al versions of Windows including Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 10.


    Threat Level

    High


    Overview

    Malicious software or "ransomware" has been used in a massive hacking attack, affecting tens of thousands of computers worldwide.

    Software security companies said a ransomware worm called "WannaCry" infected about 57,000 computer systems in 99 countries on Friday, with Russia, Ukraine, and Taiwan being the top targets.
    The hack forced British hospitals to turn away patients, affected Spanish companies such as Telefonica, and threw other government agencies and businesses into chaos.


    Description

    WannaCry is a form of ransomware that locks up files on your computer and encrypts them in a way that you cannot access them anymore.
    It targets Microsoft's widely used Windows operating system.
    When a system is infected, a pop-up window appears with instructions on how to pay a ransom amount of $300.
    The pop-up also features two countdown clocks; one showing a three-day deadline before the ransom amount doubles to $600; another showing a deadline of when the target will lose its data forever.
    Payment is only accepted in bitcoin.
    The ransomware's name is WCry, but analysts are also using variants such as WannaCry.
    A hacking group called Shadow Brokers released the malware in April claiming to have discovered the flaw from the US' National Security Agency (NSA), according cyber-security providers.


    Impact

    WannaCry is a form of ransomware that locks up files on your computer and encrypts them in a way that you cannot access them anymore.

    It targets Microsoft's widely used Windows operating system.

    When a system is infected, a pop-up window appears with instructions on how to pay a ransom amount of $300.

    The pop-up also features two countdown clocks; one showing a three-day deadline before the ransom amount doubles to $600; another showing a deadline of when the target will lose its data forever.

    Payment is only accepted in bitcoin.

    The ransomware's name is WCry, but analysts are also using variants such as WannaCry.

    A hacking group called Shadow Brokers released the malware in April claiming to have discovered the flaw from the US' National Security Agency (NSA), according cyber-security providers.


    Solution/ Workarounds

    The effected PCs should be immediately disconnected from the network.

    Contact your virus guard providers/ Security Vendors for necessary actions.

    As an immediate action, email attachments should be blocked relating to following files but not limited to .pdf (encapsulating a .js– javascript)/*.hta/.doc macro based Microsoft word) or related executables.


    Prevention:
    • Have all files backed up in a completely separate system.
    • This ransomware targets all versions of Windows including Windows XP, Windows Vista, Windows 7, Windows 8 and Windows 10.
    • Clients should ensure that they are patched on MS17-010.
    • Disable the outdated protocol SMBv1.
    • Isolate unpatched systems from the larger network Recovery:
    • As of now, there are no know recovery methods available.
    • Do not try to pay the ransom
    • Ensure you have smart screen (in Internet Explorer) turned on, which helps identify reported phishing and malware websites and helps you make informed decisions about downloads
    • Have a pop-up blocker running on your web browser
    • Regularly backup your important files


    References

    FinCSIRT Sri Lanka
    http://www.aljazeera.com/news/2017/05/ransomware-avoid-170513041345145.html



    Disclaimer


    The information provided here in is on "as is" basis, without warranty of any kind.
     

    BlueBat

    Member
    Aug 14, 2011
    15,181
    1,092
    0
    kohomada PC ekata meka enne?

    godak welawata enne target karala mail ehekin. ape company ekata awe purchase order ekak vidihata wena company ehekin apu. mail eke enawa attachment ekak. podi KB ganaka ekak. eka open kaloth baduma thama. eka open karala welawe oya thawa mona hari document open karala thibboth e tika erenna anith okkoma encrypt wena including software ekka. oya KB gana file eka onama vidihakin enna puluwan. unknown software ekak danawanam oya script eka run wenna dennath puluwan setup file ekath ekka. oya crack wage ewath ekkath bunddle karala ransomeware dan enawa kiyala man dakka dala thibba. :dull: