You are welcome to discuss various security topics with our professional team and other users like you!
Read our Registration Agreement and create your FREE account here!



  • *****
  • 122
  • +26/-0
  • Network Administrator and Malware Researcher
      • View Profile
Independent malware researcher "MalwareHunter" has discovered a new version of the Wanna Decryptor ransomware, calling itself Wana Decrypt0r 2.0. The virus uses .WNCRY file extension which it adds to the files encrypted by the virus. Then, the ransomware drops a ransom note with the following content:

Ooops, your files have been encrypted!
What Happened to My Computer?
Your important files are encrypted.
Many of your documents, photos, videos, databases and other files are no longer
accessible because they have been encrypted. Maybe you are busy looking for a way to
recover your files, but do not waste your time. Nobody can recover your files without
our decryption service.

Can I Recover My Files?
Sure. We guarantee that you can recover all your files safely and easily. But you have
not so enough time.
You can decrypt some of your files for free. Try now by clicking <Decrypt>.
But if you want to decrypt all your files, you need to pay.
You only have 3 days to submit the payment. After that the price will be doubled.
Also, if you don't pay in 7 days, you won't be able to recover your files forever.
We will have free events for users who are so poor that they couldn't pay in 6 months.

How Do I Pay?
Payment is accepted in Bitcoin only. For more information, click <About bitcoin>.
Please check the current price of Bitcoin and buy some bitcoins. For more information,
click <How to buy bitcoins>.

And send the correct amount to the address specified in this window.
After your payment, click <Check Payment>. Best time to check:

The ransowmare also deletes the backup copies and other system restore points and changes the wallpaper on the victim's computer to the following image:

More information on the virus can be found on our blog:

This is a help and support topic for the Wana Decrypt0r ransomware virus. Feel free to ask questions, add decryption instructions and suggest methods to remove and restore files by this virus

Best Regards,



  • *
  • 19
  • +9/-0
      • View Profile
Do you think that new attack campaigns are going to be launched soon?



  • *****
  • 388
  • +55/-0
  • Your friendly neighbourhood IT guy
      • View Profile
This is definitely not the end of it. Who knows what tactic the ransomware developers will try next.
Also, other ransomware viruses might try to imitate this one and spread via different ways.
Just be careful and do not open email attachments from unknown sources...



Do you think that new attack campaigns are going to be launched soon?
Yes, thats because everyone have a backup planes expect some who don't have mind and dont keeps backup of your data ,and have to pay ransomeware ! LOL
yup they are many chances of that as i to have noticed some such talk in USundernet IRC.