WannaCryptor ransomware copies CryptoLocker’s tricks
WannaCryptor virus first emerged in February 2017[1] in the form of a ransomware dubbed Wcry file extension virus. Just like other versions, WannaCry, WanaCrypt0r and Wana Decrypt0r, this malicious virus encrypts all files on the target computer with an intention to swindle money from the computer user. During the encryption, the virus that is also known under WannaCry ransomware name appends .wcry file extensions to corrupted files. The malicious program targets Windows users mainly, and once it gets access to the target system, it corrupts all data stored there using RSA and AES cryptographic ciphers[2]. The virus immediately deletes Volume Shadow Copies from the computer to prevent easy data recovery. Then it changes desktop wallpaper with an image called !WannaCryptor!.bmp, which says:
Ooops, your important files are encrypted.
If you see this text, but don’t see the “Wanna Decryptor” window, then your antivirus removed the decrypt software, or you deleted it from your computer.”
The rest of the message consists of a suggestion to download the malicious !WannaDecryptor!.exe program once again via a provided DropBox link. This trick is known to be used by a copy of CryptoLocker ransomware[3], which advises users to download the malware once again to get instructions on how to pay the ransom and recover lost files. The ransomware also saves a ransom note dubbed !Please Read Me!.txt, which contains instructions regarding data recovery. If the victim has no antivirus, !WannaDecryptor! program is going to pop-up on the screen as well. The initial ransom price is $300, and it needs to be paid in Bitcoin currency[4]. The decryptor window has several buttons that link to information about Bitcoins, how to buy them, and also “Contact Us” page, which, most likely, provides cybercriminals’ contact details, probably an email address.
The ransomware also promises to increase the price of the ransom if the victim fails to pay it within a given time. If this ransomware compromised your files, most likely it will ask you to pay the ransom to recover them, however, we strongly suggest you not to do so. Giving criminals what they want is not a solution because they might forget to fulfill their part of the agreement, which means that you will be left with gigabytes of encrypted data and no decryption key. Therefore, we strongly recommend you remove WannaCryptor ransomware – the sooner, the better. For WannaCryptor removal, we strongly recommend using anti-malware programs like FortectIntego.

How did WanaCrypt0r virus manage to infiltrate my computer system?
There are many ways how WannaCryptor ransomware can infiltrate victim’s computer unnoticed. Typically, it is distributed via email spam[5] and can be installed onto victim’s computer system as soon as the victim opens a malicious link or an email attachment. Be aware of the fact that malicious actors tend to present themselves as employees of well-known companies and kindly suggest victims view “attached contents” in order to access some extremely relevant information. Of course, such scams simply seek to convince the victim to install malware on the system, so keep that in mind when someone attempts to talk you into opening a specific link or an email attachment. Alternatively, ransomware can be distributed via exploit kits and malvertising, but these techniques are typically used by advanced ransomware developers that work on such projects as Cerber or Spora. Middle-level cybercriminals hardly ever employ these techniques.
How can I remove WannaCryptor ransomware from the system?
If your computer has been compromised by WannaCryptor virus and your files can no longer be opened no matter what kind of software you try to use, you have to decide what is your next move going to be. You can risk losing your money and pay the ransom that cybercriminals ask for, or you can resist the pressure and refuse to pay the ransom. In the second case, you should remove WanaCrypt0r right away and start experimenting with different data decryption tools and methods. We highly suggest using anti-malware tool for WannaCryptor removal, and use data recovery methods described below. Of course, the most efficient and 100% working way to restore your files is using a data backup. However, if you hadn’t created a backup before ransomware attack, it is going to be very hard to restore your files.
Did this guide help?
4 comments
Foshure
Why theres no decryptor? :((((9
drag28
Thanks for providing the removal tutorial. I had antivirus but I couldnt start it. I guess the ransomware was blocking it or something. Anyway, thanks again.
Clifford
Do you even imagine how much time it takes to create a decryptor for a ransomware? It can take years if not centuries to brute force even one decryption key.
johanna
This drives me into despair. I need my files...