Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2017

How to remove WannaCrypt ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

WannaCrypt virus updated: developers removed ransomware kill-switch

WannaCrypt virus is a malicious computer program that is set to corrupt files on Windows OS except Windows 10[1]. It usually adds .wcry, .wncry, or .wncrypt file extensions to files that it distorts. Although the ransomware hit the headlines after May 12, 2017, when it was used in a massive cyber attack that affected over 230,000 computers[2] worldwide, versions of it were spotted back in February. The virus has quite a lot of different names, including Wcrypt, WannaCryptorWana Decrypt0r 2.0 and even more, however, the name that draws everyone’s attention the most is WannaCry and the second version of it. The malicious program is extremely dangerous, and PC users should take whatever it takes to protect their computers because as soon as this virus enters the system, it encrypts files using an AES-128 cipher, meaning it is no longer possible to open or edit them. Although such attack can bring painful consequences, companies affected by it can lose years of work and experience financial losses, because the virus tends to replicate itself on connected computers and damage data stored on them as well[3].

WannaCrypt ransomware

Unfortunately, virus successfully attacked some giant companies such as Telefonica[4], England’s National Health Service, and dozens of other companies. The ransomware typically asks to pay $300 per computer if the ransom is paid within three days or $600 later on. The virus promises to delete all data on the computer if the PC user refuses to pay up or fails to collect the required amount of money in 7 days. However, we do not suggest paying the ransom because the criminals might not help you to restore your data. Besides, if you pay, you would fund further ransomware projects, meaning that you can be infected again. Cyber criminals have already earned a whopping $50k[5], and such sum can be used for evil purposes again. Therefore, if your files were corrupted, we suggest you start thinking about WannaCrypt removal. We usually recommend using anti-malware programs like FortectIntego or SpyHunterCombo Cleaner to delete the malware with ease.

WannaCrypt virus

Essential facts to know about ransomware distribution

WannaCrypt ransomware differs from typical malware variants because it uses a more sophisticated trick to attack Windows computer systems. The cyber attack launched on May 12, 2017, managed to hit over 150 countries. Experts suggest an explanation why the ransomware has proliferated so rapidly – although the majority of malware samples reached victims with the help of phishing emails, the primary infection vector was EternalBlue exploit combined with DoublePulsar backdoor, which was developed by U.S. NSA. These tools helped the ransomware spread through connected computers and corrupt data stored on them. No matter if you have been infected with this ransomware or not, we highly suggest reading these tips on how to survive the WannaCrypt0r attack. If you are using a computer running Windows 10, most likely you won’t fall victim to this ransomware. However, older versions of the indicated operating system proved to be vulnerable to the ransomware. For this reason, Microsoft has issued certain security updates to address security vulnerabilities in Windows OS. It is highly advisable to install MS17-010. Learn more about ransomware prevention methods.

Remove WannaCrypt malware from affected computers

The first and foremost thing that you should do if your computer has been affected is to remove WannaCrypt virus as soon as possible. If you were infected, shut down the computer until you find out how to complete WannaCrypt removal. We have provided comprehensive instructions on how to boot your PC to disable the ransomware temporarily. You should start your PC in a Safe Mode because this way you will be able to use your security software (after booting the computer into the Safe Mode, update your security software or install a preferred one). We have also provided in-detail data recovery guidelines for those who do not have a data backup.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.