In May 2017, a ransomware attack called WannaCryptor (also known as WannaCry) struck over 200,000 computers across 150 countries in a single day, hitting hospitals, banks, factories, and home users alike. Unlike typical ransomware that relies on users clicking malicious email attachments, WannaCryptor actively spread itself across networks using a stolen NSA exploit called EternalBlue. While the initial outbreak was halted within hours by a security researcher who triggered an accidental kill switch, this malware remains a serious threat to unpatched Windows systems and serves as a stark reminder of how quickly a worm-ransomware hybrid can spread.
Threat Profile
| Threat Name | WannaCryptor (WannaCry, Wana Decrypt0r, WannaCrypt, Wcry) |
|---|---|
| Threat Type | Ransomware with worm capabilities |
| Platform | Windows (all versions prior to MS17-010 patch) |
| File Type | Windows PE executable |
| First Observed | May 12, 2017 |
| Propagation Method | EternalBlue SMBv1 exploit (MS17-010), self-spreading worm |
| Detection Names | Ransom.WannaCryptor, Ransom:Win32/WannaCrypt, HEUR:Trojan-Ransom.Win32.Wanna, Trojan.Cryptolocker.S |
| Kill Switch | Active (domain registration stopped initial outbreak) |
| Encryption Algorithm | AES-128 with RSA-2048 key protection |
| Ransom Demand | $300–$600 USD in Bitcoin, increasing after 3 days |
| Patch Status | Microsoft released MS17-010 in March 2017 (before outbreak) |
| Severity Level | Critical (worm + ransomware combination) |
How It Spreads
WannaCryptor's spreading mechanism is what made it historically dangerous. Most ransomware arrives via phishing emails or malicious downloads and stops there, infecting only the one computer where it lands. WannaCryptor behaves differently: once it infects a single machine on your network, it actively scans for other vulnerable Windows computers and automatically spreads to them without any user interaction. This worm-like behavior allowed it to move laterally through corporate networks, hospital systems, and even home networks with multiple PCs.
The malware exploits a vulnerability (CVE-2017-0144) in Windows' SMBv1 file-sharing protocol using code from the EternalBlue exploit, originally developed by the NSA and leaked by a hacking group in April 2017. Microsoft had already released a security patch (MS17-010) in March 2017—two months before the outbreak—but countless systems remained unpatched. Older operating systems like Windows XP, which Microsoft had stopped supporting years earlier, were particularly vulnerable, though Microsoft took the unusual step of releasing emergency patches even for unsupported versions during the crisis.
Primary distribution vectors include:
- Network propagation via EternalBlue SMBv1 exploit on unpatched systems
- Initial infection through phishing emails with malicious attachments or links (less common entry point)
- Drive-by downloads from compromised websites hosting exploit kits
- USB drives and removable media carrying the executable from infected systems
- Remote Desktop Protocol (RDP) compromise on exposed systems with weak credentials
What It Does On Your Machine
Once WannaCryptor executes on your system, it performs several actions in rapid succession. First, it attempts to contact a hardcoded domain (the "kill switch" that inadvertently stopped the initial outbreak). If that domain doesn't respond—as was the case for most victims in May 2017 before a researcher registered it—the malware proceeds with its attack. It extracts embedded components including the encryption module, the DoublePulsar backdoor installer, and the Tor-based payment portal.
The ransomware then begins encrypting files across all accessible drives, targeting over 170 file types including documents, photos, databases, archives, and multimedia files. Files are encrypted with AES-128 and given the extension .WNCRY or .WCRY. A ransom note appears on your desktop—both as a text file and as a full-screen application showing a countdown timer. The note demands payment in Bitcoin to a specific wallet address, with the amount doubling after three days and all files threatened with permanent deletion after seven days. Meanwhile, the worm component scans your local network and the broader internet for other machines with port 445 open (SMB file sharing), attempting to spread the infection exponentially.
The malware also establishes persistence through registry modifications and service creation, ensuring it survives reboots. On many infected systems, users have reported seeing these behavioral indicators:
Unlike some ransomware families that only encrypt files in user directories, WannaCryptor attempts to encrypt files across entire drives including network shares that the infected user has access to. This can result in devastating data loss across shared folders on network-attached storage devices or file servers, making it especially dangerous in business and institutional environments where multiple users access shared resources.
Manual Removal — Step by Step
Isolate the Infected System Immediately
As soon as you suspect WannaCryptor infection, disconnect from all networks. Unplug the Ethernet cable and disable Wi-Fi. Turn off the computer to prevent further encryption. Do not reconnect until the removal process is complete and verified. If you have other computers on the same network, power them down and check them individually before reconnecting anything.
Boot Into Safe Mode With Networking
Restart the computer and press F8 repeatedly during boot (or hold Shift while clicking Restart in Windows 10/11, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart). Select "Safe Mode with Networking" from the menu. This loads Windows with minimal drivers and prevents most malware from running automatically, while still allowing you to download removal tools.
Run a Full System Scan With Updated Antivirus
If you don't have antivirus software installed, download Malwarebytes or Windows Defender Offline while in Safe Mode. Update the definitions, then run a complete system scan. The scan should detect and quarantine WannaCryptor components including tasksche.exe, mssecsvc.exe, and the decryptor interface. Allow the software to remove all detected threats. This may take 1-2 hours depending on drive size.
Manually Remove Residual Files and Registry Entries
Open File Explorer and navigate to C:\Windows\. Delete tasksche.exe, mssecsvc.exe, and the qeriuwjhrf folder if present. Check your Desktop for @Please_Read_Me@.txt and @WanaDecryptor@.exe—delete them. Press Win+R, type regedit, and navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for any entry pointing to tasksche.exe and delete it. Close the registry editor.
Install the Microsoft Security Patch MS17-010
Even after removal, your system remains vulnerable to reinfection if unpatched. Open Windows Update (Settings > Update & Security > Windows Update) and install all available updates. Specifically verify that KB4012598 (Windows 7/8.1) or KB4012606 (Windows 10) is installed—these contain the SMBv1 fix. For Windows XP or Server 2003, download the emergency patch directly from Microsoft's website. Restart after installation.
Attempt File Recovery (Limited Success)
Unfortunately, WannaCryptor uses strong encryption that cannot be broken without the attackers' private key. However, if Shadow Copy was enabled before infection, you may recover some files. Right-click encrypted files, select Properties > Previous Versions, and restore earlier copies if available. Third-party tools like PhotoRec or Recuva can sometimes recover unencrypted versions from free disk space if files were recently created or modified. Success rates vary considerably.
Restore From Backup If Available
The most reliable recovery method is restoring from a recent backup that predates the infection. If you have external backups or cloud storage copies, verify they're clean before restoring. Do not reconnect backup drives to an infected system before completing malware removal, as WannaCryptor can encrypt attached drives. After confirming the system is clean and patched, restore your files from backup media.
Verify Network Security Before Reconnecting
Before bringing the computer back online, ensure all other devices on your network are also patched and scanned. Run Windows Update on every Windows PC, install antivirus if not present, and scan each machine. If you operate a business network, consult with IT professionals to verify that no infected machines remain. Only after confirming the entire environment is clean should you reconnect the repaired system.
Prevention
- Install security updates immediately. Enable automatic updates in Windows or check weekly for new patches. The MS17-010 patch that prevents WannaCryptor has been available since March 2017—if you're reading this and haven't installed it, do so today. Set Windows Update to install updates automatically rather than just notifying you.
- Disable SMBv1 on all Windows systems. This outdated protocol has multiple security vulnerabilities beyond EternalBlue. In Windows 10/11, go to Control Panel > Programs > Turn Windows features on or off, and uncheck "SMB 1.0/CIFS File Sharing Support." Restart the computer. Businesses should audit their networks and disable SMBv1 across all systems unless specific legacy applications require it.
- Maintain comprehensive offline backups. Follow the 3-2-1 rule: three copies of data, on two different media types, with one stored off-site or offline. Use external drives that you disconnect after backing up, or cloud backup services with versioning. Test your backups quarterly to ensure they actually work. Ransomware can't encrypt what it can't reach.
- Segment your network properly. Home users with multiple computers should consider separating IoT devices onto a guest network. Businesses should implement network segmentation so that malware on one system can't easily spread to others. File servers should have restricted access rather than being wide open to every workstation.
- Run reputable antivirus software with real-time protection. Windows Defender is adequate for most home users if kept updated. Business environments should consider enterprise solutions with centralized management. Ensure real-time scanning is enabled and definitions update at least daily. Schedule weekly full system scans during off-hours.
- Restrict administrative privileges. Don't run daily computing tasks with an administrator account. Create a standard user account for regular use, only elevating privileges when necessary for software installation or system changes. This limits malware's ability to modify system files and spread across networks.
- Enable and configure Windows Firewall. The built-in firewall should be active on all network profiles (domain, private, public). For added protection, configure it to block inbound connections on port 445 (SMB) from external networks. Businesses should implement proper firewall rules at the network perimeter as well.
- Train users to recognize phishing attempts. While WannaCryptor spread primarily through the SMB vulnerability, the initial infections often started with phishing emails. Teach family members or employees to verify sender addresses, avoid clicking suspicious links, and never open unexpected email attachments—especially those with file extensions like .exe, .scr, or .js.
Bring It In
WannaCryptor removal requires expertise, patience, and the right tools—especially when dealing with multiple infected machines on a home or business network. Our technicians at Computer Repair Roswell have handled dozens of ransomware cases since the 2017 outbreak, and we understand the urgency when your files are held hostage. We'll safely remove the infection, help you assess what data can be recovered, install the necessary security patches, and implement backup solutions to prevent future disasters. We work on both PC and Mac systems, though WannaCryptor specifically targets Windows environments.
Don't gamble with data recovery tools you find online or waste time with incomplete removal attempts that leave your network vulnerable. Call us at (770) 676-3301 or stop by our Roswell location at your convenience. We offer free diagnostics to assess the infection's extent, and we'll give you honest guidance about recovery options before you commit to any service. If you have a business network that's been hit, we can come to your location to contain the outbreak and handle multiple machines efficiently. The sooner you bring an infected system in, the better your chances of minimizing data loss and preventing further spread to other devices.