@Name: CCN-CERT NoMoreCry Tool

@Version: 0.3

@md5 hash: 128bbd165a29cee84df352065271f514

@sha1 hash: f4959807118866e9f6150a7f9931ca8a55d5d78c

@Author: CCN-CERT

@E-mail: info@ccn-cert.cni.es

@Website: www.ccn-cert.cni.es



La presente herramienta crea en el equipo los objetos de exclusin mutua que impiden la ejecucin del malware WannaCry 2.0. Esta nueva versin de la herramienta consta tambin de un fichero de texto que obligatoriamente debe acompaar al ejecutable en la misma ruta. Dentro de este fichero se encuentran los nombres de los objetos de exclusin mutua que la herramienta crear. Esta nueva versin admite la ejecucin en modo silencioso mediante su ejecucin desde linea de comandos mediante la opcin "-s". Ej.: c:\NoMoreCry.exe -s


En el caso de mquinas infectadas, la ejecucin de esta herramienta no es de aplicacin.

Es importante tener en cuenta que la presente herramienta no presenta persistencia en el equipo, por lo que para la correcta proteccin frente a esta amenaza deber ejecutarse tras cada reinicio. Esto se puede automatizar mediante la modificacin del registro de Windows o mediante la aplicacin de polticas de grupo en el dominio.



La herramienta funciona en sistemas operativos Windows XP y superiores.




-------------------------



The following tool creates the mutexes which prevent the execution of the malware WannaCry 2.0. This new version includes a text file that must be saved to the same folder as the executable. Within it, there is a list with the names of the mutexes to be created. This new version can be run in silent mode by executing it from the command prompt with the "-s" argument. eg.: c:\NoMoreCry.exe -s

This tool is not intended for already infected machines.



It is worth noting that since this tool does not have any kind of persistence mechanism it should be run after every reboot for the successful prevention of the threat. This can be performed by the modification of the Windows registry or by the application of group policies in the domain.



The tool runs in operating systems Windows XP and above.



