Trojan.Ransom.WannaCrypt (WanaCrypt0r 2.0/WannaCry, NHS Ransomware)

Поділитися
Вставка
  • Опубліковано 7 лис 2024
  • / danooct1
    / danooct1
    a few links for further (and interesting) reading: www.malwaretec...
    www.theguardia...
    major thanks to malwaretech team for stopping the ransomware in its tracks, xylitol for the hookup once again, and all of you who took the time to message me about the ransomware.
    Thanks to the following $5+ patrons!
    John Kizer
    Numou
    crymera
    handsome jack
    Thomas H Khoury
    Joshua Mack
    Mister Sparkly
    Jade
    squigly-kip
    Matthew K
    Alice J
    Renaud Bedard
    Blaise
    Sleepy Owl
    Rosenator
    Robert G
    Si Mellor
    BluePolar Bearz

КОМЕНТАРІ • 1,6 тис.

  • @AwesumIndustrys
    @AwesumIndustrys 7 років тому +3209

    You know it's serious shit when obsolete software gets patched.

    • @DMack6464
      @DMack6464 7 років тому +41

      Are they gonna release a patch for Windows 95?

    • @cam6656
      @cam6656 7 років тому +74

      microsoft still cares about xp, so you can still use it :)

    • @b_28282
      @b_28282 7 років тому +92

      Cam No they don't

    • @CWINDOWSsystem32
      @CWINDOWSsystem32 7 років тому +2

      +InfernoDukem It's pretty much a fact that Windows XP is obsolete by now...

    • @johnl.38
      @johnl.38 7 років тому +16

      pretty sure gas stations still run XP on pumps and ATMs may also do the same

  • @DrachenYT
    @DrachenYT 7 років тому +3174

    When you hit that point in your life where it wouldn't even matter if you got hit by this because worst case scenario you just lose your memes.

    • @b_28282
      @b_28282 7 років тому +169

      But my Minecraft worlds would be gone too!!!
      *_*pays 0.17 BTC_**

    • @chcikety
      @chcikety 7 років тому +70

      I actually did lose my memes to ransomeware :( It was devestating... I hate those boogerheads >:(

    • @bitelaserkhalif
      @bitelaserkhalif 7 років тому +2

      Drachen you lose the moddig projects

    • @BigOlSmellyFlashlight
      @BigOlSmellyFlashlight 7 років тому +9

      Drachen I lose all my animations and backups from 2013

    • @w4str
      @w4str 7 років тому +2

      true my friend

  • @Leurak
    @Leurak 7 років тому +1990

    If it works without the network connected, where is the decryption key saved?

    • @mrdaxtercrane
      @mrdaxtercrane 7 років тому +296

      It's so early into investigation, I would assume they didn't know.

    • @realcomputerdude100
      @realcomputerdude100 7 років тому +493

      I would imagine that it attempts to send it, fails, and continues to delete the key.

    • @OGZClanChannel
      @OGZClanChannel 7 років тому +180

      that's a really good question lmao

    • @LiEnby
      @LiEnby 7 років тому +93

      run it in sandboxie and check?

    • @abcddd32123
      @abcddd32123 7 років тому +47

      @thecomputerman100 ^this

  • @itsdustyy598
    @itsdustyy598 7 років тому +2179

    You have a girlfriend?
    Me- I used to have one, but she Ransomewhere.

    • @PsychoFizz
      @PsychoFizz 7 років тому +85

      ItsDustyy I laughed harder than necessary at this.

    • @FrigidBirostrixRay
      @FrigidBirostrixRay 7 років тому +10

      ItsDustyy
      LMAO

    • @WhoLetTheDogOut
      @WhoLetTheDogOut 7 років тому +14

      ItsDustyy
      Really? Only 10 Likes? That was freaking clever and funny!

    • @goodbyetothemaskedme
      @goodbyetothemaskedme 7 років тому +6

      ItsDustyy I'm laughing harder than I should be 😂😂

    • @manaralameri1650
      @manaralameri1650 6 років тому +26

      ItsDustyy it’s true, she ran some where, and you have to pay her or else she leaves you.

  • @EthanBB
    @EthanBB 7 років тому +937

    Actually, there is absolutely no point to pay the ransom. It has only 3 bitcoin addresses hardcoded into program (shown randomly) and there is no way attacker could recognize the payment was from you. Meaning there was never any intention to be able to decrypt the files.

    • @White_Tiger93
      @White_Tiger93 6 років тому +9

      so how do you solve this problem without resort to pay them??

    • @stedmangg
      @stedmangg 6 років тому +250

      *you don't*

    • @karlkastor
      @karlkastor 6 років тому +111

      @@White_Tiger93 wait till someone writes a decryption program and/or the decryption keys leak. I believe there is already free decryption software for WannaCry out there. Sometimes the keys needed for decryption are still in the RAM of the computer, so there might be software that can get the keys, but it only works a short time after the malware was started.

    • @GRBtutorials
      @GRBtutorials 6 років тому +91

      @@White_Tiger93 Restore from backup. Because you have a backup, don't you?

    • @patriotapatriotski4809
      @patriotapatriotski4809 6 років тому +4

      I was wondering can u use safe mode in this situation ???

  • @austyn.l6289
    @austyn.l6289 7 років тому +2026

    Ooops, this comment has been encrypted!

    • @b_28282
      @b_28282 7 років тому +136

      WHERE DO I SEND MY BITCOINS?!

    • @andy56duky
      @andy56duky 7 років тому +49

      /b/ 28282 ah shit. my ass got encrypted as well.

    • @adamwilderspin7854
      @adamwilderspin7854 7 років тому +14

      Austyn LeDrew How many bit coins to decrypt it...?

    • @Komeiji0401
      @Komeiji0401 7 років тому +19

      Here is a key to decrypt your comment:
      hssianaizbwhu72!*hwnai;#!isn8#!@62;#8$;

    • @michaelbaterna8386
      @michaelbaterna8386 7 років тому +11

      Error: File not found

  • @Wozobb
    @Wozobb 7 років тому +191

    The interesting thing about the kill-switch is that it's actually a poorly implemented sandbox test.
    Malware authors want to thwart security researchers for as long as possible to delay any attempt at a countermeasure, and one technique for doing so is refusing to run in any sandboxed virtual machine environment. Sandboxes for malware often give it everything they want in order to analyze it to the fullest extent possible: for instance, if something wants to access a domain, the sandbox will give it something to connect to, whether or not it exists on the real Internet. Thus, if WannaCrypt manages to connect to a domain that it thinks doesn't exist, it'll conclude that it's being monitored and self-terminate.
    Normally, malware of this kind randomly generates the domains to be checked, but the author of WannaCrypt hard-coded it into the program instead, meaning that since someone registered the domain in the real world, it always mistakenly thinks that it's being run in a VM, whether or not it actually is.

    • @aamyushh
      @aamyushh Рік тому +7

      thank you for this i have been wondering for hours now and its 4am and am deep down a rabbithole

    • @smashi4088
      @smashi4088 Рік тому +5

      that's a super clever strategy, good thing whoever made this didn't think of that

  • @CWINDOWSsystem32
    @CWINDOWSsystem32 7 років тому +361

    Hey, props to Microsoft for actually releasing a patch for XP for this. Pretty ridiculous that some government systems are still running a 16 year-old unsupported OS though...

    • @QuantumEcho7
      @QuantumEcho7 7 років тому +1

      CWINDOWSsystem32 I guess it's cheaper for our stupid government

    • @CWINDOWSsystem32
      @CWINDOWSsystem32 7 років тому +8

      +QEproductions7 I hope they learned their lesson from this and actually hire some decent IT people and upgrade the systems to at least Windows 7...

    • @QuantumEcho7
      @QuantumEcho7 7 років тому +2

      CWINDOWSsystem32 I suppose they're too busy sitting back and waiting for their victory in the election to care about the country lol

    • @danem2215
      @danem2215 4 роки тому +22

      The United States ran its entire nuclear missile command from 50 year old 8" floppy drives until like 6 months ago

    • @notgray88
      @notgray88 4 роки тому +1

      My high school was still running windows 98 just 3 years ago lmao.

  • @Zyzzywyz
    @Zyzzywyz 7 років тому +185

    Lol, "It's rich af" in the Rich Text document.

    • @astonio9693
      @astonio9693 5 років тому

      @@potato_x69 "it's poor af"

  • @rougeamp1
    @rougeamp1 7 років тому +258

    this is how the civil war started

  • @omni9030
    @omni9030 6 років тому +60

    The memories of WannaCrypt for me are amazing! Being only a child at the time and seeing a red screen of death, I was terrified. We subsequently had a friend come over to fix this supposed virus, but I never touched that same computer again >:c

    • @Belchmaster41
      @Belchmaster41 Рік тому +2

      this is what happens when you don't have Norton's Smart Firewall engaged

  • @jadegecko
    @jadegecko 7 років тому +23

    Here I was, thinking of you as a retro '90s-virus connoisseur. And here you are on the bleeding edge of world news.
    Albeit world news that affects people with badly out of date systems...
    Anyway, you're awesome. It's really neat to get to see this stuff in a context that's not dangerous or malicious in nature.

  • @baradragonsftw9310
    @baradragonsftw9310 7 років тому +362

    *viruses, years ago: haha i wrecked your computer, lol, you lost everything*
    *viruses now: pls give me money*

    • @AWISECROW
      @AWISECROW 6 років тому +30

      NotPetya: pls give me money (wrecked your computer, lol, you lost everything anyway)

    • @daniloaltamera8385
      @daniloaltamera8385 6 років тому

      PandoTech:Hold my beer

    • @OiranDaki
      @OiranDaki 5 років тому +4

      @Floppy 6022 ???

    • @ABC-in2le
      @ABC-in2le 4 роки тому +5

      Viruses now: MEEEEEEEMZ

    • @GodzillaKaijuGK
      @GodzillaKaijuGK 2 роки тому +1

      @@ABC-in2le there should be a MEMZ computer epidemic

  • @SirajRaval
    @SirajRaval 7 років тому +210

    bro 200K views in 2 days god status

  • @pcsecuritychannel
    @pcsecuritychannel 7 років тому +62

    They have come up with a newer version that doesn't have the killswitch. Another wave may be coming soon. Hopefully people are patched up.

    • @bruhblox_
      @bruhblox_ 15 днів тому

      7 years later lol

  • @rcollosi
    @rcollosi 2 роки тому +21

    i remember when this was the biggest threat to your computer. feels just like yesterday, even though it was 4 years ago

    • @Solaceon
      @Solaceon 2 роки тому +3

      Don't worry, ransomware is still going strong.

  • @unsatisfiedfans7422
    @unsatisfiedfans7422 8 місяців тому +6

    I just want to thank you because your computer virus highlight videos (especially on ransomwares) are the inspiration for my thesis on computer virus

  • @burrito64burrito64
    @burrito64burrito64 7 років тому +338

    Hey Danooct1 you should have put the blog post Microsoft put on their webpage. It's almost like a middle finger to the NSA

    • @SimplyChem32
      @SimplyChem32 7 років тому +13

      blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/#sm.0000otkst81x2dg2rb51g3fgd0f6k There's the full blog post from their site, 8th paragraph down talks about the NSA.

    • @userPrehistoricman
      @userPrehistoricman 7 років тому +1

      Then why don't you link it???

    • @Scootaloose
      @Scootaloose 7 років тому +7

      That kind of comment is the same kind of crap you see on support forums when someone goes "found the problem it's fixed now" but never posts the solution.
      Link in question:
      blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/

    • @burrito64burrito64
      @burrito64burrito64 7 років тому +13

      Prehistoricman
      I posted a reply with a link to it, but I think it get deleted as spam. The link appears on my screen right below my comment.
      Can you see it?

    • @Werwa_
      @Werwa_ 7 років тому

      burrito64burrito64 nope. Try adding a space in between the link and the ".com" or something

  • @ShiningLuma90
    @ShiningLuma90 7 років тому +194

    TempleOS doesn't have this problem

    • @kutsuro3901
      @kutsuro3901 5 років тому +1

      too soon?

    • @badcop9604
      @badcop9604 5 років тому +4

      MS-DOS doesn't have this problem

    • @ggffd3704
      @ggffd3704 4 роки тому +1

      templeos has the problem of being able to rewrite mbr in a line

    • @SandboxerSandy
      @SandboxerSandy 4 роки тому +4

      @@potato_x69 bruh why the fuck do you hate weebs

    • @quizzys7106
      @quizzys7106 4 роки тому

      @@potato_x69 lmao

  • @sewertendo
    @sewertendo 7 років тому +41

    Just a tidbit on why XP was patched. It's because of companies that still use XP tend despite the vulnerabilities. They usually set up individual contracts with Microsoft for this type of thing so that they can have some kind of extended support, although usually they have some kind of endpoint based security that filters most of the uninvited stuff. Part of it is to cut costs, or because certain applications simply won't work with newer OSes (so it's not just the OS you would be changing). There have obviously been ransomware in the past, but normally the network layers of security would be sufficient for it. This is why XP got patched despite the lack of support.
    Unless you're one of these organizations, don't freakin' use XP.

    • @MaximilienNoal
      @MaximilienNoal 7 років тому +5

      Biggerboot I use XP from time to time on a dedicated retro computer. I even use Windows 98SE. It's the bomb for 3dfx games. And of course both have network shares 'cause it's convenient. The key here is that there is nothing important on it and it's offline most of the time, with Wake On Lan disabled. :p

    • @sewertendo
      @sewertendo 7 років тому +5

      Absolutely. If you're using it in those capacities then you obviously know what you're doing. I'm just a little worried when I see comments like "DOZ THIS MEEN XPEE IZ SPPRTD AGIN?" I mean I guess it's youtube comments and it could be sarcastic, but ultimately misinforming. :P

  • @burgerdiverbanandodansparc9154
    @burgerdiverbanandodansparc9154 7 років тому +346

    I actually wanna know that Mushroom Chicken recipe, if you're okay with that.

  • @BlinkLed
    @BlinkLed 7 років тому +106

    It's the new Captain Crunch cereal, "Oops, All Ransomware"

    • @radioactivian
      @radioactivian 4 роки тому

      jokes on you I speak enchantment table

    • @ChaseMC215
      @ChaseMC215 3 роки тому

      That's nice, Captain. But oh that time you fucked up and your cereal was just All Berries?

  • @Jamesthe1
    @Jamesthe1 7 років тому +7

    I never knew it had a killswitch. Very good; this thing actually put cancer patients' lives in danger.

  • @InterstellarVulpine
    @InterstellarVulpine 7 років тому +229

    Any virus that wants to get between me and my lego memes is going to get what's coming to it.

  • @vwestlife
    @vwestlife 7 років тому +38

    People on MSFN are saying that it is impossible for WannaCry to infect a system running from a FAT32 partition, because it relies upon NTFS to encrypt the files. Can you verify this?

  • @Leurak
    @Leurak 7 років тому +349

    yes

    • @PanPakaPanKancolleisgud
      @PanPakaPanKancolleisgud 7 років тому +11

      Hey it's memz guy, when did you start watching Danooct?

    • @byRKZY
      @byRKZY 7 років тому +7

      Jack He is he's number one fan. :p

    • @plushifoxed
      @plushifoxed 7 років тому +22

      danooct literally did the first video out there on memz you dingdong

    • @ThatLinuxDude
      @ThatLinuxDude 7 років тому +4

      Hey man

    • @michaelbaterna8386
      @michaelbaterna8386 7 років тому

      CONFURMED: teh memz guyy is the cRator off waanay cripty ransomwore

  • @AllHailNannerpuss
    @AllHailNannerpuss 7 років тому +205

    #18 on Trending. My nigga Dan made it

    • @poke548
      @poke548 7 років тому +8

      I know, I felt so proud when I saw it.

    • @CWINDOWSsystem32
      @CWINDOWSsystem32 7 років тому +1

      +Tornexted No, but Matt is...

  • @whoismatteo3737
    @whoismatteo3737 7 років тому +6

    I hate the way that ransomware makes me feel... it's so creepy, it gives me this sort of "dark, doomed" vibe

  • @chm_mmx
    @chm_mmx 7 років тому +17

    This malware uses two critical flaws. One is MS13-010 that has been patched for every Windows since XP/2003 (because someone still has Vista for some reason). The second is the fact companies take ages to release updates on their computers. My school, for example, has hundreds of Win7 Pro computers. They all haven't been updated since November 2016 (and today I'll go look if they have MS13-010)

  • @GRBtutorials
    @GRBtutorials 6 років тому +14

    "We will decrypt your file because nobody will trust us if we cheat users" That has to be the lamest reason I've ever heard! Nobody trusts them!

  • @xylan9543
    @xylan9543 7 років тому +83

    That moment when you hack your own computer cause you want to erase your trash memes

    • @NOVA-en4ci
      @NOVA-en4ci 6 років тому +5

      The trash memes were still funnier than most new popular memes nowadays though. *cough cough ugandan knuckles cough cough*

  • @S-D-A99
    @S-D-A99 7 років тому +40

    so Windows 10 can get this Virus?.....
    Woah, technology

    • @Mykoo
      @Mykoo 7 років тому +4

      Miley Fox Im pretty sure you can get in any version of Windows if youre opening a .exe file, however, but dont quote me on this, if you have Windows 10 with your firewall enabled and anti-virus running + all the recent updates from Microsoft, you can't get infected through the network.

    • @OMspot2277
      @OMspot2277 7 років тому

      only if you didn't update windows 10 with that March update. But if you did then you were safe

    • @dirtkiller23
      @dirtkiller23 7 років тому +5

      Auto Windows Updates.This is the only case where it helps.

  • @jimbob20051
    @jimbob20051 7 років тому +9

    *opens Rich Text Document and reads* "it's rich af"
    that has killed me XD

  • @yourbuddymuddy
    @yourbuddymuddy 7 років тому +57

    holy shit this is the earliest ive ever been to a video ever

    • @ki9980
      @ki9980 7 років тому

      Muddy Bear ikr

    • @VreyIsGrey
      @VreyIsGrey 7 років тому +10

      You're not late. You're on time.

  • @vzangel
    @vzangel 7 років тому +15

    What happens with the already encrypted files if it's executed again? Does it encrypt them again or leaves them alone based on the file extension? If the latter happens, very important files could be protected by changing the file extension in anticipation.

  • @PimpMatt0
    @PimpMatt0 7 років тому +56

    Feels like the 90s again with these viruses.

  • @springer1985
    @springer1985 2 роки тому +3

    Someone I knew lost very important information worth a lot of money. They had this same virus, paid the $300 in bitcoin and got everything back and the scammers were actually very friendly to work with which was odd.

  • @zerozerito14
    @zerozerito14 7 років тому +1

    Was waiting for this video, thanks :D !!!

  • @Fnmods
    @Fnmods 3 роки тому +7

    Old days

  • @RonLaws
    @RonLaws 5 років тому +1

    what a fun year this was at work. Having Non-windows based NAS Servers with volume level snapshots was a saving grace :D

  • @ninelivesbobcat3619
    @ninelivesbobcat3619 7 років тому +269

    *hears that Microsoft patched Windows XP*
    Does this mean Windows XP is back? YAAAA--
    *realises that's it only to prevent the ransomware and that Windows XP will never be supported ever again*
    Ohhhhh. ;_;

    • @boofcario
      @boofcario 7 років тому +62

      Solution: Keep making ransomware that exploits XP. Support forever :D

    • @archived527
      @archived527 7 років тому +6

      Who knows, there is a possibility that one of the patches could be ported to XP again if another serious attack like this happens. There was another post EOL patch in May 2014.

    • @computethisinfo
      @computethisinfo 7 років тому +9

      NinelivesBobcat I ran windows XP pro in a virtual machine yesterday, and was soo shocked to find people actually playing the internet Microsoft games so frequently finding someone instantly. why was I shocked? so many people still use XP. even though the internet browser was buggered and wouldn't open any https links and not load others.

    • @anasarkawi4331
      @anasarkawi4331 7 років тому +3

      windows xp is the king os oses!

    • @TexelGuy
      @TexelGuy 7 років тому +8

      Dang crybabies, suck it up and update. You're missing out on basically everything.

  • @piloticle2445
    @piloticle2445 7 років тому +1

    DANOOCT IS ON TRENDING. never thought i'd see the day my dudes

  • @Pokycraftgamer9
    @Pokycraftgamer9 7 років тому +13

    you know when something is serious if Microsoft updated Windows XP

  • @klaasbousma7013
    @klaasbousma7013 7 років тому

    the news here in the Netherlands are just talking about this virus every time, and i was waiting for this video. now it's here. i love your content. it's really impressive and interesting to watch. keep it up

  • @TakoyakiDonuts
    @TakoyakiDonuts 7 років тому +3

    WannaCrypt actually hit my local hospital, funny how it was the only one in the Greater Toronto Area to be hit.

  • @thetrashman5381
    @thetrashman5381 7 років тому +2

    You know a ransom ware is bad when Dan's video is trending

  • @bugfriendz
    @bugfriendz 10 місяців тому +4

    i got infected with wannacrypt when i was younger, kind of terrifying!

  • @fr0sth4x0r
    @fr0sth4x0r 7 років тому +1

    Great video, been following for about 3 years and this is hilarious

  • @DMack6464
    @DMack6464 7 років тому +5

    When I saw the headlines, I instantly thought "danoct1"

  • @yannisvill6806
    @yannisvill6806 7 років тому +1

    Danooct1 is back!!! So many memories :')

  • @lordofwolve
    @lordofwolve 7 років тому +5

    Good job NSA you provided me with the stuff to make people's lives worse. Thanks again

  • @FIXTREME
    @FIXTREME 4 роки тому +1

    That Atari-esque Hava Naguila is nectar to my ears!🐱

  • @Ranged66
    @Ranged66 7 років тому +9

    There's this interesting tool called Ransomfree, cold you consider testing it at some point with this malware to see if it works? It basically places bait files all around your computer and when it detects a ransomware messing with it it will try and stop it.

  • @Dnk-fs8ks
    @Dnk-fs8ks 7 років тому

    I was looking for this video. Thanks Dan

  • @kairaus
    @kairaus 7 років тому +6

    you know shit gets real when an update for windows xp is released

  • @kieran7378
    @kieran7378 7 років тому +1

    I've been waiting for this.

  • @TheKingBJ
    @TheKingBJ 7 років тому +10

    >shows a malware that asks for money to recover your files
    >outro plays a 8bit klezmer song
    oy vey

  • @GreatJobStudio
    @GreatJobStudio 7 років тому

    You're on trending, my guy! Gratz.

  • @anentityshroudedinmystery.8037
    @anentityshroudedinmystery.8037 7 років тому +17

    mushroom_chicken.docx
    Why did I type this comment

  • @firebucket8203
    @firebucket8203 7 років тому +1

    Congrats on making it on trending Dan !!!

  • @realcomputerdude100
    @realcomputerdude100 7 років тому +5

    greetz from @danooct1 ya boi wit da malware yoooooooooooooooooooooooooooooooooooooooooooooooooooooooo

  • @sharath9893
    @sharath9893 7 років тому

    finally!
    i was eagerly waiting for this!

  • @HiyaItsHailey
    @HiyaItsHailey 7 років тому +29

    You should've pulled a rogueamp and just posted a video of you driving in your 129° car.

    • @RavenousRabbler
      @RavenousRabbler 7 років тому +4

      "What up guys, RogueAmp here, today I heard that the worst malware attack since Conficker has finally happened. Because ransomware is totally not my specialty, I'm just gonna drive in my car and blast some E U R O B E A T"

  • @XJLuxury
    @XJLuxury 7 років тому

    yes ive been waiting for this video! ive checked your profile every day since this came out

  • @connorhare9359
    @connorhare9359 7 років тому +6

    when u want kids but she not ready
    O O O P S

  • @okdev5420
    @okdev5420 7 років тому

    holy shit #20 on Trending GOOD JOB danooct!

  • @iyok050106
    @iyok050106 7 років тому +11

    my school alerted about this worm spreading and told everyone to not turn on their computer today and tomorrow, but screw it, I'm using a Mac! :p

  • @ItsKardamin
    @ItsKardamin 7 років тому

    Congrats on getting on the top video list! Thank you for showing this one

  • @DiamondTurtleGamer
    @DiamondTurtleGamer 7 років тому +5

    I just realized how you don't kill your computer every time you do these videos..
    virtual machine.

  • @cargopros8246
    @cargopros8246 6 років тому +2

    Yes I wanna crypt, thank you for asking.

  • @stevegamer68
    @stevegamer68 5 років тому +4

    Imagine if the scammers accidentally encrypted their computers

    • @ChanceOfOne344254
      @ChanceOfOne344254 Рік тому +2

      This has actually happened allegedly, but not with this ransomware
      Allegedly, the author of Rensenware, had to complete his own task (score 2 billion points on lunatic mode in TouHou) in order to decrypt his own files due to forgetting to run the program in a virtual machine.

    • @RMED24
      @RMED24 Рік тому +2

      ​@@ChanceOfOne344254that's partially false actually. What really happened is that he did encrypt his files, so he used cheat engine to force the score required to unlock the files. He then developed a tool which did all this automatically for those who were affected by rensenware

  • @ismailabdullah4556
    @ismailabdullah4556 4 роки тому +3

    My heart went-
    Oops! Your files have been encrypted!🤫

  • @Rctive
    @Rctive 7 років тому +5

    for about 2 seconds when you were typing that message
    you sounded like joel

  • @Xyaena
    @Xyaena 7 років тому

    I managed to share this video to some of my friends.

  • @cisjik
    @cisjik 7 років тому +3

    Finally, MS who abandon Windows XP upload the second update for Windows XPIt's seem Bill know a lot of people use Windows XP

  • @stupidstuff9046
    @stupidstuff9046 7 років тому

    as soon as I saw this in the news I knew I'd see a danooct video

  • @Dragnerve.
    @Dragnerve. 7 років тому +3

    the key is WNcry@2o17

  • @foofin25
    @foofin25 7 років тому

    Hell yea, danooct got trending.

  • @codex4336
    @codex4336 7 років тому +3

    Does disabling the SMB feature in Windows keeps you safe from this computer worm?

  • @xander2698
    @xander2698 7 років тому

    I've been waiting for this video

  • @nikolatesla6992
    @nikolatesla6992 7 років тому +3

    2.0 is going to be released shortly with no kill switch (Verified) The internet will be gone before the end of the year. Nokia bricks will be back in style as soon as data goes bye bye. Welcome to 1984, get comfy.

    • @xbotscythe
      @xbotscythe 6 років тому

      Hello from the future.

    • @faaznoushad1718
      @faaznoushad1718 6 років тому

      @@xbotscythe give me the overview of your world

  • @LOLMAN9538
    @LOLMAN9538 Рік тому +1

    Thank God I try to keep both of my computers updated

  • @captainmexico5483
    @captainmexico5483 7 років тому +83

    I didnt watch all the video yet but the unlock code to the virus is " WNcry@2ol7 " thumbs up to let everyone know

    • @DMack6464
      @DMack6464 7 років тому +1

      How did you find it?

    • @raymond2136
      @raymond2136 6 років тому

      fr? well shit lol

    • @the_lava_wielder6996
      @the_lava_wielder6996 6 років тому +17

      I'm pretty sure it's randomized for each user

    • @MatrixJ21
      @MatrixJ21 6 років тому +9

      It is. The key is sent from the program to an external server on execution of the payload, then removed from storage (and/or memory) on the target computer.

    • @nyanezt9636
      @nyanezt9636 6 років тому

      "WannaCryAt2017"... huh

  • @plasmididdlydoo7465
    @plasmididdlydoo7465 7 років тому

    This thing sends a chill down my spine..

  • @hippiemcfake6364
    @hippiemcfake6364 7 років тому +4

    Awwww i wished you'd demonstrate the 'decrypt' button. It says that you can decrypt some files for free.

  • @Wignut
    @Wignut 7 років тому

    Was waiting for this one.

  • @quatex.854
    @quatex.854 7 років тому +6

    lol i got "BEST FREE ANTIVIRUS" ad more like BEST TROYAN VIRUS amiright?

  • @alecday3775
    @alecday3775 7 років тому +1

    Hello there Dan (this will [or could possibly] be a text wall so you are warned, i dunno how to paragraph my sentences out):
    There is another big name that got nailed by WannaCrypt as well and that is FedEx. I remember hearing about parts of their servers got encrypted by WannaCrypt as well so they lost some of their shipping data. So it wasn't just the N.H.S. in Canada that was the only big company that got nailed in the attack. It was those 2 and one more I cant think of right now and the biggest thing about this is that the USA and 76 (that is not a typo) other countries that got nailed with this ransomware making it the biggest malware attack BY A LONG-SHOT. I am unsure of who is in second place but I think it is either Sasser, ILoveYou or Melissa. Could be either of those three or I could be wrong as well (if you could tell me that would be great). and maybe make a follow-up video to this one with some ways your viewers can protect themselves from this worm and keeping their PCs safe from this worm and any other worms that may pop up in the future.

  • @crazyfatefan
    @crazyfatefan 7 років тому +6

    It's still active. Also even though it got halted by a 21 year old in Britan people say all the hackers have to do is rewrite the code and it can hit again.
    Most likely we will see more of wannacry or more ransomeware in general because of this, not to mention both microsoft and the NSA are now fighting each other because wannacry was the NSA's cyber weapon pet and now it's gone rogue.
    Who's to blame for this really? Who knows some say it's both Microsoft and the NAS's fault others are one sided and a few of my friends are saying "well shit happens, no one is impenetrable to getting hacked. They can have the best defense and protection but if one weakness is found and it wasn't notice..well to bad, hackers win.
    We will never know who will be blamed and what will happen to prevent something like this from happening again, only time will tell.

  • @SonicAwesome-sr3wf
    @SonicAwesome-sr3wf 7 років тому +1

    Woah!! Danooct you're trending! #21 ftw

  • @zacksstuff
    @zacksstuff 7 років тому +8

    That's ballsy. Running it on your own computer. Even with a VM, that's risky.

    • @AWISECROW
      @AWISECROW 6 років тому +1

      likely running it on an expendable system.

  • @saeedo1998
    @saeedo1998 7 років тому

    Woo i was waiting for this

  • @fredfred1247
    @fredfred1247 4 роки тому +3

    Oops! This comment has been encrypted! Send a 3 replies and I will edit this comment so you can see what I wanna say.

    • @MinusNC
      @MinusNC 3 роки тому

      FRED FRED124 decryptor.exe

    • @MinusNC
      @MinusNC 3 роки тому

      FRED FRED124 backupdecrypt.exe

    • @MinusNC
      @MinusNC 3 роки тому

      FRED FRED124 Anti-Encryptor.exe

  • @erik8467
    @erik8467 7 років тому +2

    Even though what these hackers did was an asshole thing it's still amazing to see how a group of unidentified people sitting somewhere unknown, maybe even naked in their basements managed to hack 200k computers across 150 countries

  • @marioluigifun
    @marioluigifun 7 років тому +6

    12:50 AM notification squad what up

  • @Discoh
    @Discoh 7 років тому

    Congrats on making it to the trending page.

  • @patrickdunay39
    @patrickdunay39 7 років тому +6

    good to know that danooct1 has a gf 1:14

  • @ThimisB
    @ThimisB 7 років тому +2

    HOLY SHIT YOU'RE TRENDING AAA

  • @aurathedraak7909
    @aurathedraak7909 7 років тому +6

    we knew this would happen xD

  • @butth0le_inspector
    @butth0le_inspector 6 років тому +2

    Legend says he found out one more thing about the virus