Up to this point, it is difficult to decrypt the infected file. However, a famous cyber security company called Symantec is looking for a way to decode it more easily. If you do not want you or your organization to become a victim of the WannaCry attack, follow these steps.
To remove WannaCry, you will need to use Safe Mode. Here's how to turn on Safe Mode on your computer. Also note that the information below is based on search and does not guarantee that your computer can remove WannaCry. To follow the instructions below, you will need to read this article on another device because during the operation, you will have to turn off the browser.
How to turn on Safe Mode
Note: On some computers, the Boot Key is not F8, then you will need to review the manufacturer's instructions to find this key.
Read the steps carefully and make sure you know what you are doing before you work.
Eliminate infected processes
Now you need to find processes that are running on WannaCry-related machines. Press Ctrl + Shift + Esc to open the Task Manager dialog box . Then look closely on the Processes tab to find strange entries.
Usually poisoning processes will consume a lot of computer resources, such as CPU or RAM. If you see an unusual entry, right-click, and select Open the File > Delete Everything. Be sure to do so only when you are sure the process is related to WannaCry.
Programs start up
Now open Startup Programs by typing System Configuration in the Windows search box. Then select the first result and you will see the list of programs.
If you use Windows 10, you can see the Startup Programs right in Task Manager. On all Windows versions, if you see any program with a strange or suspicious developer name, uncheck it and click OK.
Registry
Open Windows Run dialog box or press Windows + R key combination. Then type regedit and press Enter.
When you see the Registry Editor, press Ctrl + F and type Ransom.CryptXXX or WannaCry. Please delete all that is related to this name and select Find Next to find the next results.
Virus-infected files
Finally, don't forget to delete all files that are likely to be infected. On the Start Menu, type each of the following options in turn: % AppData%,% LocalAppData%,% ProgramData%,% WinDir%,% Temp% . Each time you search by one of the names above, a folder will appear, select by time and delete the most recent folders and files. Alternatively, you can go to the Temp directory to delete everything in it.
Although not 100% guaranteed, the above guidelines may be helpful to help you remove WannaCry from your computer.
Related articles:
How to handle the emergency WannaCry malicious code from the National Information Security Department
Microsoft released an emergency patch to prevent ransomware from attacking