WannaSmile ransomware targets Iranian organizations and computer users

After the infiltration, the computer users are provided with a How to decrypt files.html ransom note, which is written in Iranian. Experts from NoVirus.uk[2] have found linkages to the ZCrypt ransomware and believe that WannaSmile virus is an offspring of the latter one. The following is the translation of the text message:
WARNING!
Your system is infected with the WannaSmile Ransomware virus, all your important files, including databases and backups, are encrypted with complex encryption algorithms, so you will not be able to access files, only we can decrypt.
In the event that we do not receive a fee for our bitcoin-purse a maximum of 5 days after infection, then 1 bitcoin will be added daily to the original amount (20 bitcoins) . You must pay an amount of 20 bitcoins to decrypt your files, at the following address: 1KvmWVRxqw8HeFpR2tHBaoTJiTczU7PRzwAnd once you pay, do not forget to send us an email to wannasmile@tuta.io so we can send you a file from which you can restore all the files and infected systems to their original state.
You can buy bitcoins at one of the following currency exchangers:
www.exchanging.ir
www.payment24.ir
www.farhadexchange.net
www.digiarz.com
WannaSmile developers threaten to increase the amount of the ransom by one Bitcoin if the victim fails to make a transaction within 5 days. Note, that it is already an enormous amount money and you should not fall into the hackers’ trap. There is a high risk that they will keep increasing the ransom as long as you keep paying.

Thus, we recommend you to remove WannaSmile virus instead and use alternative retrieval methods, which are provided at the end of this article. This way, you will make sure that the criminals won’t take advantage of you to generate illegal profits and investments to their malicious activity.
If you wonder how to safely eliminate the ransomware from your system, employ FortectIntego or MalwarebytesMalwarebytes and it will complete WannaSmile removal for you.
Distribution peculiarities of the ransomware
Developers of the malicious programs tend to employ several distribution methods to increase the rate of successful infections.
The file-encrypting virus might spread via[3]:
- Fraudulent software updates;
- Malicious links;
- Spam e-mails.
Hackers impersonate legitimate companies or software to trick naive computer users to open the executable of the malware. It might be disguised as an Adobe Flash update or an ad offering to install system optimization tools or video/audio converters.
You should stay away from any suspicious ads, programs, e-mails, and updates. Download applications only from authorized websites and avoid opening letters from unknown senders.
Another great option to protect your computer from ransomware infections would be to use a professional antivirus system. It would scan your PC regularly and eliminate all unreliable programs. This way you wouldn’t be forced to monitor your browsing activity so attentively in order to avoid high-risk computer infections.
Learn how to terminate WannaSmile
You should remove WannSmile automatically because only experienced IT specialists can perform the manual termination. Since the infected system is vulnerable, criminals might infiltrate other malicious programs to make elimination even more complicated. Therefore, using a security software is highly recommended. It will detect all types of viruses and clean your PC safely.
You can choose FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes for WannaSmile removal since they will quickly eliminate the virus and maintain your computer's security in the future. However, if you have difficulties this automatic elimination, you should check the instructions attached below. Make sure to follow them strictly.
Did this guide help?
Be the first to comment