Home » Blog » Cybersecurity » Cybersecurity » How to remove Wana Decrypt0r (Virus Removal Guide)
Wana Decrypt0r

How to remove Wana Decrypt0r (Virus Removal Guide)

Wana Decrypt0r ransomware is a computer virus that takes encrypts files and demands a ransom payment.

The Wana Decrypt0r virus (also referred to as WanaCry or Wana Decrypt0r 2.0) is ransomware that uses the stolen NSA’s EternalBlue exploit and drops NSA’s DoublePulsar malware to infect computers that use versions of the Microsoft Windows Operating System. When the ransomware infects a computer it will append the .wcry, .wcryt, .wncry, or .wncrrytt extension to the file name and hold the files ransom.

Wana Decrypt0r

The ransom note contains information about what happened to your computer and how to pay the $300 ransom to recover your encrypted files via bitcoin. Here’s an example of the ransom note displayed by this virus:

Oooops, your files have been encrypted!

What Happened to My Computer?

Your important files are encrypted.

Many of your documents, photos, videos, databases and other files are no longer accessible because they have been encrypted. Maybe you are busy looking for a way to recover your files, but do not waste your time. Nobody can recover your files without our decryption service.

Can I Recover My Files?

Sure. We guarantee that you can recover all your files safely and easily. But you have not so enough time.

You can decrypt some of your files for free. Try now by clicking <Decrypt>.

But if you want to decrypt all your files, you need to pay.

You only have 3 days to submit the payment. After the price will be doubled.

Also, if you don’t pay in 7 days, you won;t be able to recover your files forever.

We will have free ecents for users who are so poor that they couldn’t pay in 6 months.

How Do I Pay?

Payment is accepted in Bitcoin only. For more information ,click <About bitcoin>.

Wana Decrypt0r ransomware is an EternalBlue exploit, which is a cyberspying tool that was previously stolen from the National Security Agency (NSA) and leaked online in 2016 by a hacker group called Shadow Brokers. The NSA’s EternalBlue exploit targets Windows CVE-2017-0145 vulnerability in Microsoft’s implementation of SMB (Server Message Block) protocol even though the vulnerability has been patched since May 14th of 2017. This concludes that the ransomware infects outdated versions of Microsoft Windows.

The ransomware will use a trojan to drop the exploit on the computer it infects. The most recent variants of Wana Decrypt0r ransomware are distributed via girlfriendbeautiful[.]ga/hotgirljapan.jpg?i=1 in APAC region. Once the ransomware infects the targeted computer it creates a random folder in C:\ProgramData. The folder created by the ransomware contains executable files named tasksche.exe, mssecsvc.exe, and tasksche.exe; However, the mssecsvc.exe and tasksche.exe files can might also and only be found in C:\Windows.

The virus executes the Icacls . /grant Everyone:F /T /C /Q command in order to obtain complete access to all the files on the computer it infects. The ransomware will then connect to domain in order to infect the machine.

The free instructions on this page will help you remove Wana Decrypt0r ransomware, viruses, malware, and decrypt encrypted files. Follow each step below to remove this infection and secure your computer from malicious threats. On the bottom of this guide you will also find recovery and decryption software for various ransomware infections.

1. Remove Wana Decrypt0r with Malwarebytes


  1. Open your browser window and download Malwarebytes 3.0 Premium or Malwarebytes Anti-Malware Free.
  2. Open the executable file (mb3-setup.exe) to begin installing Malwarebytes.
  3. Select your language, click Next, then select “I accept the agreement,” click the Next button several times, and then click the Install button to install Malwarebytes. Click Finish once the install process is complete.
  4. Open Malwarebytes and click the Scan Now button on the Dashboard to begin scanning your computer.
  5. Click the Quarantine Selected button once the scan is finished.
  6. If Malwarebytes says “All selected items have been removed successfully. A log file has been saved to the logs folder. Your computer needs to be restarted to complete the removal process. Would you like to restart now?” click the Yes button to restart your computer.

2. Remove trace files with HitmanPro


  1. Open your browser window and download HitmanPro.
  2. Open the executable file (hitmanpro_x64.exe or hitmanpro_x32.exe) to begin installing HitmanPro.
  3. Click the Next button, check “I accept the terms of the license agreement,” and click the Next button again.
  4. On the Setup page select “Yes, create a copy of HitmanPro so I can regularly scan this computer (recommended)” and add your email address to the registration fields to begin the free trial.
  5. Click Next to begin scanning your computer.
  6. Once the Scan results are displayed click the Next button and click the Next button again on the Removal results page.

3. Clean up and repair issues with CCleaner


  1. Open your browser window and download CCleaner Professional or CCleaner Free.
  2. Open the executable file (ccsetup.exe or other) to begin installing CCleaner.
  3. Click the Install button to begin stalling the program.
  4. Click Run CCleaner to open the program when installation is complete.
  5. Select the Cleaner tab and click the Analyze button.
  6. When the Analyze process is complete click the Run Cleaner button to clean all files.
  7. Next, select the Registry tab and click the Scan for Issues button to scan for issues in your registry.
  8. When the scan is complete click the Fix selected Issues button and Fix All Selected Issues button to fix the issues.
  9. Next, select the Tools tab and click Startup. Examine each area, search for suspicious entries, and delete any suspicious startup entries by selecting the entry and clicking the Delete button.
  10. Next, click Browser Plugins and search each internet browser for unwanted browser add-ons and extensions. Click the extension you want to delete and click the Delete button to remove it.

Decryption Software

wanakiwi Decryptor for Wana Decrypt0r Download
gentilkiwi/wanadecrypt Decryptor for Wana Decrypt0r Download

File Recovery Software

Shadow Explorer Restores lost or damaged files from Shadow Copies Download (Free)
Photorec Recovers lost files Download (Free)
Recuva Recovers lost files Download (Free) | Buy

Sean Doyle

Sean is a tech author and engineer with over 20 years of experience in cybersecurity, privacy, malware, Google Analytics, online marketing, and other topics. He is featured in several publications.

More Reading

Post navigation

Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

How to remove .wcry ransomware and decrypt files

How to remove Exotic ransomware (Virus Removal Guide)

How To Remove The Search Safer Toolbar Hijacker Virus (SearchSafer.com Redirection Malware, Search Safer Virus)