Check If Your Windows Is Vulnerable To Attack Using This EternalBlue Vulnerability Checker

With Ransomware being in the air, it is a good time to check if your Windows system is vulnerable to the EternalBlue exploit – which was being exploited by the WannaCrypt Ransomware. This malware may have been stopped for now, but you never know when another malware comes and exploits this vulnerability. Eset EternalBlue Vulnerability Checker is a free tool that checks if your Windows computer is vulnerable to EternalBlue exploit.
Check If Your Windows Is Vulnerable To Attack Using This EternalBlue Vulnerability Checker

Malware can spread using a vulnerability in implementations of Server Message Block (SMB) in Windows systems. This exploit is named as EternalBlue.
EternalBlue is a hacking weapon developed by NSA to gain access and command the computers running Microsoft Windows. It was specifically designed for the America’s military intelligence unit to get an access to the computers used by the terrorists. 

EternalBlue Vulnerability Checker

The EternalBlue Vulnerability Checker tool checks if your computer is patched against EternalBlue. If your Windows computer is installed with all the latest Windows Updates, you have nothing to worry about. When you run the tool, in such cases, you will see a message:
Your computer is safe. Microsoft security update is already installed.
But if your computer is vulnerable, the tool will display the following message:
Your computer is vulnerable !!!
In such cases, you are advised to run Windows Update and install the available updates. Or else, you may visit the Microsoft Update Catalog page and install the KB4012598 security update.
This tool is available for download at Eset.com.


Apart from these, there are other things you may want to do to secure your computer further like disabling RDP if you do not use it and disabling SMB1.




NotPetya Ransomware Kill Switch That Can Stop Ransomware In It Tracks Has Been Release

Kill Switch or Vaccination for the Petrwrap or NoPetya or NotPetya Ransomware has been found that can stop the ransomware in its tracks and save your computer from being infected. The NotPetya Ransomware has already created havoc in most parts of the world.
NotPetya Ransomware Kill Switch That Can Stop Ransomware In It Tracks Has Been Release

NotPetya uses the EternalBlue vulnerability (WannaCry technique) that infects computers using SMBv1. It also uses Windows WMIC and PSExec processes. If the WannaCry vulnerability is patched on your system, it uses PsExec or LSADUMP and the Windows Management Interface to spread. 



The ransomware is capable of attacking and infecting all Windows systems. It overwrites the Master Boot Record and on reboot, infects the computer blocking access to it. Once it hacks your computer, it demands a ransom amount of $300 in Bitcoin.
If your computer reboots and you see this ‘false check disk’ message, power off immediately!
This is the NotPetya encryption process taking place. If you power off immediately or do not power on, your data will remain safe.
If the encryption process is allowed to continue, you will lose your data to this ransomware!


There are however some basic precautions you can take, and they are:
  1. Install all Windows patches
  2. Block SMB1 across your network
  3. Disable default ADMIN$ accounts and communication to Admin$ shares
  4. Use a tool like MBR filter to block write access to the Master Boot Record
More details about how this ransomware operates can be found on Cybereason.com.

NotPetya Ransomware Vaccination

Cybereason Principal Security Researcher Amit Serper tweeted that he has discovered a vaccination that stops NotPetya ransomware in its tracks.
NotPetya Ransomware Kill Switch
To activate the vaccination mechanism you have to create a file named perfc, with no extension and place it in the C:\Windows\ folder.
When NotPetya ransomware runs, it searches for this file in the C:\Windows\ folder, and if it is found, it ceases its operation.
UPDATE: Eset recommends that you create three blank files with the following filenames and extensions:
  1. C:\Windows\perfc
  2. C:\Windows\perfc.dat
  3. C:\Windows\perfc.dll
Ransomware attacks are on the rise, and all computers users need to take some basic precautions to secure their systems. One can also consider some free anti-ransomware software like RansomFree as an additional security layer.