15 May 2017

How to Protect Windows System from Ransomware Wanna Cry

Ransomware Wanna Cry

Is a type of Trojan (malware) or software program that design to harm windows system. When your system affects with this malware, it will automatically encrypt your windows system data. Your desktop automatically locked and it will display a message like this “your important file encryption produced on this computer". Alert on the window desktop of this Trojan shows that you have to pay first amount in Bitcoin to decrypt your files. It will also give you instruction if you won’t decrypt your file before time; you're unless to recover files anymore. 

Ransomware Affect System

 

How Ransomware Works?


It basically works on two encryption algorithm called as AES and RSA.

RSA (Ron Rivest, Adi Shamir) It is called asymmetric cryptographic algorithm. Asymmetric mean two different key uses by this algorithm. It is also called public key cryptography. One key available for everyone publically and a second one called private key kept by the user.

AES (Advanced Encryption Standard) also known as Rijndael, is a 128-bit block cipher algorithm. This encryption standard used by the U.S National Institute of Standards and Technology (NIST). But now hackers use this secure encryption in Trojan for harm windows system. This algorithm uses symmetric keys, which uses the same key to encrypt and decrypt information.


This Trojan used AES key to encrypt files. The AES key for decryption is written in the files encrypted by the malware. Yet, this key is encrypted with an RSA public key implanted in the malware, which means that a private key is needed to decrypt it. It means attacker only knows private key for decryption. So there is no chance for crack this encryption. The only way you can decrypt your file you need a key for decryption.

How to prevent your system from This Malware?

 

Don’t download anything from the malicious site. Always download any software from official or trusted website. Don’t open and click attached spam mail. Most of the report told that this virus comes from spam emails. You can use antivirus program in your system. It blocks that kind of malware who harms your computer. Update your antivirus security update regularly for remove any new threat. Regular make backup of your system data. If your system harm with this worm, you can get backup data which you have stored somewhere.