Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2017

How to remove WantMoney ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

WantMoney ransomware makes data encryption complicated procedure

WantMoney ransomware wallpaper

WantMoney ransomware is a file-encrypting virus that targets Chinese and English speaking computer users. The malicious program is designed to encrypt files with AES cryptography. During encryption procedure, malware not only appends a specific file extension but renames files as well.

The virus renames files by appending random letters instead of the original file name. Want Money ransomware uses this scheme to corrupt data on the targeted computer:

XXXXX-XXXXX-XXXXX-XXXXX.Encrypted[B32588601@163.com].WantMoney2

Following data encryption, crypto-virus a ransom note called “_Want Money_” in .bmp and .text files where hackers ask to pay 0.1 BTC. The BMP file becomes affected computer’s desktop picture that resemble’s the skull we have already seen in Petya ransomware.

In the text file, criminals provide detailed data recovery instructions. Victims have to transfer the money and send an email to b32588601@163.com (or TheYuCheng@yeah.net) with their unique ID number:

After payment please send an email to the specified email-address
Email-address: B32588601@163.com
letter name: the Request to decrypt the (W APROSAM to decrypt)
Content email: your ID + your billing information
after sending you will receive a reply, the reply message contains the key , type it into the text box to decrypt the file.

Additionally, WantMoney virus shows a pop-up window with ransom demanding information and provides Bitcoin wallet address where victims are supposed to send the money.

However, following these instructions is not recommended.[1] Crooks may never give you working decryption software. For this reason, it is recommended to focus on WantMoney removal. Once the virus is wiped out from the system, you can restore data from backups or try alternative recovery methods.

If you do not have backups, data recovery possibilities are not high because WantMoney might be capable of deleting Shadow Volume Copies by executing vssadmin.exe delete shadows /all /Quiet command. However, there’s always a chance that this malicious program fails to do that. In this case, you can call yourself lucky.

Talking about virus elimination, you will need to obtain are reputable anti-malware software, such as FortectIntego. If you cannot install or update security software, you will need to run a computer in Safe Mode with Networking in order to remove WantMoney malware.

WantMoney ransomware virus

Methods used for ransomware’s distribution

There are several ways how file-encrypting program can end up on the system. Therefore, to avoid ransomware, you have to learn about them and do not fall for crooks’ tricks.

  1. Malicious spam emails. It’s the most popular distribution method that relies on social engineering. These emails often look legit and include infected attachment, usually in Word, PDF or ZIP files. Once opened, this file drops malware payload on the system.
  2. Malvertising.[2] Criminals might create malware-laden ads and display them on both legitimate and high-risk websites. Often these ads are aggressive, eye-catchy and offer great deals. However, clicking them might lead to the installation of malware.
  3. Fake downloads/updates. Security experts from Norway[3] point out that users who download illegal programs or other content are often at risk to install ransomware or other malware. The same problem exists with downloads or available update alerts that show up in the form of a pop-up.
  4. Exploit kits. Malicious programs often take advantage of outdated software and their security flaws. Thus, installing latest updates from the official sources is the most important prevention tip.

Additionally, crypto-malware might still find the way to your PC. For this reason, you should strengthen your computer’s security with antivirus software and create backups.

Complete deletion of the WantMoney ransomware virus

WantMoney removal requires system scan with reputable and powerful malware removal software. We suggest using FortectIntego or MalwarebytesMalwarebytes, but you can choose your preferred tool as well. However, if you consider manual elimination method, we want to discourage you because this task is difficult and can be performed successfully only by IT professionals.

However, if you cannot install security software and remove WantMoney automatically, you have to take additional steps in order to disable the virus. Follow the guide below.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.