The new Ransomware is called Wannacry. Wannacry ransomware is targeting Windows-based PCs that have weaknesses related to the SMB functionality that runs on the computer.
Currently, allegedly Wannacry attack has taken many victims to various countries. It is therefore important to carry out a series of precautions as well as handling in the event of an incident.
Then someone named Niqo Qintharo (perpustakaan24.net) made a status on facebook about how to solve the computer affected by Ransomware virus (how to remove ransomware virus wannacry). Here’s how.
If you’ve entered the .wcry virus (check image)
1. Log in to Safe Mode
2. Click Safe Boot -> minimal, Click Ok and Restart
3. Once restarted go to Control Panel -> Folder Options -> Show Hidden Files (check image) then click Apply
4. Go to msconfig -> Startup -> Disable Program is suspicious or unknown, click ok and Click “Exit without Restart”
5. Delete Malicious Files (All Virus Files)
6. Check the next folder to find suspicious files:
(If there is a folder / File Wanna Cry delete directly)
7. Check the host file, because it can corrupt with the Virus
Location of host:
C: \ windows \ System32 \ drivers \ etc
There will be a file host and open pake notepad
(There if there are sites that are not known, then delete them directly)
8. Then, go back to msconfig continue disable Safe Mode click ok then Restart
9. After restarted, there is no “Decryption Tool” now, but ente can restore files from backup or restore a separate folder
10. Now you can see the old version of the encrypted file
11. Delete Files named:
! Please Read Me! .txt
! WantDecryptor! .exe
If successful please comment below.