How to remove WannaCry ransomware

The ransomware WannaCry (Wanna Cprypt0r) spreads at a dizzying speed, making users unable to turn around. This is the largest global cyberattack ever. As soon as they hacked into the computer, they would automatically encrypt all of the data, and then require the user to pay a ransom of $ 300.

To WannaCry ransomware prevention system attacks, users absolutely do not open links with .hta extension or unstructured links, shortened links. So what to do when the computer is infected with WannaCry? We invite you to follow the following article of

How to remove WannaCry Ransomware?

To remove WannaCry ransomware, you need to do it in Safe Mode. How to enable Safe Mode on each operating system will be different:

  • Windows XP and Windows 7: Press F8 before Windows starts. On Boot Menu, choose Safe Mode with Networking, then press Enter.
  • Windows 8 and Windows 8.1: To enter Start Menu> Control Panel> Administrative Tools> System Configuration. Then find and select Safe Boot and choose Networking> Restart. Soon the computer will switch to Safe Mode.
  • Windows 10: To enter Start Menu> Settings> Update and Security> Recovery. Under Advanced Startup, click Restart Now to restart the machine. When the machine allows to choose Choose Option Screen, click Troubleshoot> Advanced Options> StartupSettings> Enable Safe Mode with Networking Option and press Enter.

Then, follow the instructions below to remove WannaCry Ransomware from the computer:

Eliminate the infected process

Right-click the Taskbar, select Task Manager or press a combination of keys Ctrl + Shift + Esc to open the Task Manager dialog box.

Read More:  What is WannaCry? How to know WannaCry? Which computer is susceptible to this ransomware ransomware?

Task Manager

At the card Process, find running processes on your computer that are related to WannaCry. Usually, the malicious processes are consuming a lot of system resources. You just need to observe the field CPU, Memory If the process is abnormal, right-click and select Open the File, then delete everything related in the folder.

Open the path

Startup programs

Type in keywords System Configuration into the search box, and then click the first result. And those who are using Windows 10 can see the programs that start right in the card Startup of the Task Manager. Then, check if the program has a strange developer name, if it is suspicious, click on it, select Disable.



Press the key combination Windows + R to open the dialog box Tremor. Then, type in keywords regedit into the box Open and press OK.

The Run window

When the Registry Editor window appears, press Ctrl + F and type the name of the virus. Later, delete all associated with this name and select Find Next to find the next results. According to Kaspersky Lab security firm, the following viruses are related to WannaCry:

  • Trojan-Ransom.Win32.Scatter.uf.
  • Trojan-Ransom.Win32.Gen.djd.
  • Trojan-Ransom.Win32.Wanna.b.
  • Trojan-Ransom.Win32.Wanna.c.
  • Trojan-Ransom.Win32.Wanna.d.
  • Trojan-Ransom.Win32.Wanna.f.
  • Trojan-Ransom.Win32.Zapchast.i.
  • Trojan.Win64.EquationDrug.gen.
  • Trojan.Win32.Generic.

Registry Editor

Viruses stick files

Finally, type the following options:% AppData%,% LocalAppData%,% ProgramData%,% WinDir%,% Temp% into the search bar. When searching, a folder will appear, just click on it, then filter by time and delete the most recent folders and files. In the Temp folder you can delete everything in it.

Delete virus files

Hopefully the above article will help you get rid of WannaCry that has been crazy about the community during the past few days!

Read More:  How to effectively prevent WannaCry ransomware most effectively for operating systems from Windows 2000 to Windows 10

Wish you all success!

Source link: How to remove WannaCry ransomware
– Https://

Leave a Reply

Your email address will not be published. Required fields are marked *