ACTIVE MALWARE WINDOWS TESTED: WINDOWS XP, WINDOWS SERVER 2003, WINDOWS 8

How to remove
Protect Yourself from WannaCry Ransomware
from Windows

Safeguard your Windows 10 or 11 device from WannaCry ransomware with expert-tested tips and effective removal strategies. Stay protected, updated 2025.

How to Protect Yourself from WannaCry Ransomware?
Quick Summary
Threat level
Medium
Est. time
10 minutes
Offer Fortect PC Suite
Start removal →
Ad · we may earn a commission
0 Comments
01

How does How to Protect Yourself from WannaCry Ransomware end up on your PC?

  • Use of EternalBlue exploit
  • Unpatched MS17-010 vulnerability
  • Outdated Windows versions
  • Lack of security updates
  • Malicious script execution
Offer Fortect PC Suite

Repairs Windows system files, removes malware, and restores a clean OS state — without reinstalling.

Ad · we may earn a commission
Get Fortect PC Suite ↗

WannaCry ransomware is the new and widespread cyber pandemic that has taken hostage more than 230,000 computers already. With its current volume of dispersion, WannaCry is approaching the level of other infamous cyber threats such as Cerber or Locky.

Nevertheless, what distinguishes WCry from these two last year’s most dangerous parasites is the use of new distribution techniques which do not need victims to click on the infected links or take part in the ransomware acquisition in any other way.

Wannacrypt protecion image
Wannacrypt protecion image

The malware uses practices and tools used by the U.S. intelligence to break into computers and run the malicious script to render user’s data inaccessible. In particular, ransomware employs EternalBlue exploit to target Windows devices with an unpatched MS17-010 vulnerability. This security gap is open on Windows versions which are no longer supported and receive no security updates.

Luckily, in response, the latest events, Microsoft has released emergency patches for the Windows XP, Windows Server 2003, Windows 8 and a few other outdated operating systems. But even the software update may not be enough to prevent ransomware attack.

Below, we will provide instructions how to disable SMB (Server Message Block) functionality which is used to deploy the malicious WanaCrypt0r files on the computer. But before we head to the tutorial, we want to give a brief definition of the malware and how it behaves on the infected computer, to help you recognize it easier.

Wannacry uses different extensions to mark encrypted files

As you may have noticed, throughout previous paragraphs we have used different names to refer to the WannaCry virus. It’s because of the virus, indeed, travels around in a variety of different shapes and forms, most likely to be trickier to recognize and terminate.

The research has revealed that the virus now uses four different extensions .wncry, .wncrytt, .wcry or .wncryt to mark the encrypted files, but we can expect more variations as the ransomware picks up speed. To drop these extensions and recover files, the users must pay the extortionists up to 600 dollars in Bitcoin; otherwise, the encrypted data will be destroyed. @[email protected] window opens a timer which counts down the time until data destruction. Unfortunately, no free decryption software currently exists that would help recover encrypted data for free.

So, once you’ve been infected, there is really nothing much you can do to roll back the consequences of the attack. So, it is much more important to take action and protect your device before any virus sets foot on your system. Here are some steps you should take to prevent WannaCry infiltration.

How to disable SMB and prevent WannaCry attack?

SMB (Server Message Block) function is the main vulnerability that allows the ransomware to infect computers. Since this feature is enabled on Windows by default, extortionists can easily use it to carry out the attack. Thus, we highly recommend disabling it if you are not using it. It is really simple and you can achieve in three basic steps:

  1. Click the Windows logo on the bottom-left corner of the screen and type in “Windows Features” into the search bar
  2. Open the feature window and go to settings and look for the SMB entry. Unmark it and click OK
  3. Restart the computer

You can also disable SMB via PowerShell. What you have to do is type in "Disable-WindowsOptionalFeature -Online -FeatureName smb1protocol". After the feature is disabled, we recommend rebooting the computer.

Bottom line

To protect yourself from WannaCry ransomware, it is essential to disable SMB functionality and apply emergency patches released by Microsoft for outdated operating systems. If these measures do not resolve the issue, consider seeking professional help or using data recovery services.

Frequently asked questions

Ensure that your Windows 10 system is updated with the latest security patches and enable Windows Defender for real-time protection against threats.

You can remove WannaCry ransomware by booting into Safe Mode and using a reliable antivirus program to scan and eliminate the malware.

While there are no specific programs to uninstall, always remove any suspicious or untrusted software that could serve as a vulnerability for ransomware like WannaCry.

Did this fix work for you?
Alice Woods

Written & verified by

Security Analyst
Virus removal Rootkit detection System integrity verification Firewall configuration Antivirus tools testing

Alice Woods is a security analyst who covers antivirus software, virus removal procedures, and post-infection system verification. She tests security tools hands-on before recommending them and writes removal guides backed by direct malware analysis rather than theoretical instructions. Alice's background in security operations gives her guides an edge in accuracy — she understands how infections behave at a system level, which lets her identify the full scope of what needs to be cleaned. Her writing is trusted by both home users and IT professionals handling compromised machines.

0 Comments

Be the first to comment

Still worried? Run a free check.

Paste any URL or domain — we'll scan it against 4.2M known threats in 10 seconds.

View full scanner → Add to your website →