Recommended Free Tools
There is no universal WannaCry decryptor. Europol says decryption is generally not possible, although WanaKiwi has recovered files in some circumstances. That possibility is conditional: Europol advised victims not to reboot the infected computer before trying it, and CERT-EU’s 18 May 2017 advisory described possible recovery on certain Windows systems that had not been rebooted. Neither source guarantees that it will work for a particular infection.
What to do first if you suspect a WannaCry infection
- Disconnect the computer from networks. Turn off Wi-Fi and unplug Ethernet or other network connections to reduce the risk of malware spreading. [Europol]
- Do not reboot just to try WanaKiwi. If the machine has not been restarted since infection, preserve its current state; the reported recovery method depends on conditions that may not remain after a reboot. Seek trusted incident-response help if this is an active incident. [Europol] [CERT-EU]
- Check clean backups. Restoring files from a backup is a recovery route that does not depend on decrypting the infected files. Europol also identifies Shadow Copies and undelete tools as possibilities in some cases. [Europol]
- Identify the ransomware before selecting a tool. Use a trusted resource such as No More Ransom’s Crypto Sheriff to check whether a decryptor is available for the identified ransomware. [Crypto Sheriff]
What WanaKiwi can—and cannot—do
Europol says the partial solution developed by Benjamin Delpy, Matt Suiche, and Adrien Guinet was tested by its European Cybercrime Centre (EC3) and recovered data encrypted by WannaCry in some circumstances. The key qualification is “some circumstances”: this is not a universal decryptor or a promise of recovery. [Europol]
Europol advised victims not to reboot the infected computer before trying the method. CERT-EU’s advisory dated 18 May 2017 described possible recovery on certain systems if they had not been rebooted after infection. The advisory named Windows XP, Windows 7, Windows Vista, Windows Server 2003, and Windows Server 2008. These are historical compatibility details, not a current product-support statement or a guarantee. [CERT-EU]
The cited sources do not establish whether the original WanaKiwi download is currently maintained, safe, or available from an official source. Avoid unverified mirrors; do not download a purported decryptor simply because its name matches the tool.
#1 Best Overall
Recovery routes compared
| Route | What the sources establish | Important limitation |
|---|---|---|
| WanaKiwi | EC3 tested the partial method and found recovery in some circumstances. [Europol] | Recovery is conditional; the cited advice says not to reboot first. The sources do not establish a verified current download source. [Europol] [CERT-EU] |
| Backups | Europol lists backup restoration as a recovery option. [Europol] | Recovery depends on having a clean, usable backup. |
| Shadow Copies or undelete tools | Europol says these may help in some cases. [Europol] | They are not guaranteed to restore files. |
| Paying the ransom | Europol says payment does not guarantee restored access and advises against paying. [Europol] | Payment is not a reliable recovery method. |
How to check whether a decryptor exists
No More Ransom’s Crypto Sheriff can compare two encrypted files and the ransom note against available tools, according to Europol. Use a trusted identification resource rather than choosing a decryptor based only on a filename or extension. Europol’s cited page describes more than 120 tools for over 150 ransomware types in 37 languages; these are figures stated on that page, not independently verified as current counts. [Crypto Sheriff]
Microsoft says WannaCry could rename files with the .WNCRY extension. Microsoft also lists aliases including WannaCrypt, WanaCrypt0r, WCrypt, and WCRY. Those names and extensions can help identify a suspected infection, but they are clues rather than definitive proof. [Microsoft]
Why paying is not a dependable fix
Europol advises victims not to pay because payment does not guarantee that files will be restored. Prioritize containment, backups, and trusted identification or incident-response help instead. The No More Ransom initiative reported more than 10 million tool downloads and more than 1.5 million people successfully decrypting devices without paying criminals at its sixth anniversary in 2022; those figures cover the initiative as a whole, not WannaCry specifically. [Europol]
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the Microsoft guidance does—and does not—offer
Microsoft’s 2017 material provides WannaCrypt detection and mitigation guidance. It does not establish a physical device capable of decrypting WannaCry files. A storage accessory may help protect future backups, but it cannot be represented as a decryptor for files already encrypted by WannaCry. [Microsoft]
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

