Petya ransomware is affecting users globally, here are things you can do

  • 1
    Share
Petya_ransomware_quick_heal

Quick Heal Security Labs has come across a new strain of Petya Ransomware that is affecting users globally. This clearly looks like early signs of a new ransomware attack that is spreading fast across the globe. Currently, we have seen multiple reports of this ransomware attack from several countries.

Our Analysis Shows

Petya delivery mechanism is by scam emails or phishing emails. Once the email attachment is executed on the computer it shows the prompt of User Access Control. However, after executing the program it encrypts the Master Boot Record (MBR) and replaces it with a custom boot loader with a code to encrypt the full disk starting with MFT (Master File Tree) and leaves a ransom note to users. Upon successfully encrypting the whole disk of the computer it shows below ransom prompt.

Petya ransom screen.

Fig 1. Petya ransom screen

Are we (Quick Heal users) protected from this ransomware?

All Quick Heal users are protected from this ransomware infection where an exploit called EternalBlue targets the security vulnerability MS17-010. This is the same vulnerability which WannaCry Ransomware has been exploiting to spread. Quick Heal IDS successfully blocks Eternal Blue exploit attempts. Quick Heal’s Behavior Based Detection (BDS) also blocks and warns user of a potential attack under way. Just make sure all the security mechanism of Quick Heal are switched ON.

Quick Heal Security Labs is continuously monitoring the threat and working on releasing updates to protect the threat at different layers. So please keep your Quick Heal up-to-date with all the current updates that are regularly released.

Preventive steps and recommendations

  1. Avoid clicking on links in email received from unknown sender
  2. Apply all Microsoft Windows patches including MS17-010 that patches the Eternal Blue Vulnerability
  3. Make sure your Quick Heal’s auto update is ON and is updated to latest.
  4. Ensure you take a backup of your data to some external disk regularly.
  5. Avoid login to computer with Administrative privileges. Work with user account that has standard user privileges and not administrative privileges. Click here to know more about this.

If a threat is executed in my computer, can I still prevent my data?

If by mistake someone executes the threat on an unprotected computer by clicking on the link in the email and downloading the attachment, and if you see a BSOD (blue screen) that restarts your computer, you can still save your data by not restarting the computer. Just keep it switched off.

When you see the BSOD screen and the system re-starts only the MBR is replaced and your data on the disk is still intact and it can be accessed by mounting the hard disk on some other clean system. Make sure you do not boot the infected computer hard disk at that stage. Once mounted the data can be accessed and copied.

Pradeep Kulkarni

Pradeep Kulkarni

Follow @

Subscribe
Notify of
guest
51 Comments
Inline Feedbacks
View all comments
Dr.K.N.Babu
Dr.K.N.Babu
3 years ago

socially beneficial to the society
KEEP IT UP

jahun51@gmail.com
jahun51@gmail.com
3 years ago

GOOD SERVICE

Dharmendra yadav
Dharmendra yadav
3 years ago

GOOD

PREMSHANKAR PATEL
PREMSHANKAR PATEL
3 years ago

thankyou

Kiran
Kiran
3 years ago

plz update us regularly by describing the do’s and dont’s

m.k.mali
m.k.mali
3 years ago

I know only virus and some of its effects. Hence to give any remarks is avoided. However u r doing the best for us (Quick Heal .. users) Thanks a lot With regards.. M.K.

gosher dinesh
gosher dinesh
3 years ago

PL. FOLLOWS INSTRUCTION MADE BY QUICKHEAL TO WORK US SMOOTHLY.

Shailendra
Shailendra
3 years ago

Extremely Thanks For Suggesting…………

somenath mahapatra
somenath mahapatra
3 years ago

thanks for suggestion

Kevin patel
Kevin patel
3 years ago

His app is amazing

Kevin patel
Kevin patel
3 years ago

Good serious

Nagaraj.s
Nagaraj.s
3 years ago

Thank you so Mach

Dhruvik jaguwala
Dhruvik jaguwala
3 years ago

Mind-blowing…axelent…app…best ….

vinay kumar
vinay kumar
3 years ago

VERY GOOD PROGRAMME

Souvik Malik
Souvik Malik
3 years ago

THANK YOU SIR.

Gaurav Goswami
Gaurav Goswami
3 years ago

wonderful

SUWALAL
SUWALAL
3 years ago

SCAN ALL

deepak panchal
deepak panchal
3 years ago

Dear I want quick scan virus free

bachchu hati
bachchu hati
3 years ago

So good

chinmya tripathy
chinmya tripathy
3 years ago

how do i update my quick heal total security

BABULAL DEORA
BABULAL DEORA
3 years ago

GOOD

Ravi Singh
Ravi Singh
3 years ago

very nice antivirs

SANJAY jadav
SANJAY jadav
3 years ago

One of the best using the provide the quick heal anti &security guard for Mobail

nyk
nyk
3 years ago

GOOD

Aritra
Aritra
3 years ago

Good

Samit Kumar Mahata
Samit Kumar Mahata
3 years ago

Very Good Update Sir

goesstefan26@gmail.com
goesstefan26@gmail.com
3 years ago

thank you………..

SUDIP GUHA ROY
SUDIP GUHA ROY
3 years ago

Use QUICK HEAL TOTAL SECURITY for PC, LAPTOP, DESKTOP,TAB, MOBILE any of it’s kind.

p.moitra
p.moitra
3 years ago

Fruitful result obtained
Thanks

Debabrata Pradhan
Debabrata Pradhan
3 years ago

good service & high version alert

ayush
ayush
3 years ago

Good anti virus

Veena
Veena
3 years ago

Nice service please update regularly

Surjendra Singh
Surjendra Singh
3 years ago

its good to work with quick heal

amzadhussain88@gmail.com
amzadhussain88@gmail.com
3 years ago

Quick Heal is better than best !

vivek
vivek
3 years ago

Wow…nice .
Very good service

manoj cherian
manoj cherian
3 years ago

Good

Marutiappa Madhavrao Ravankole
Marutiappa Madhavrao Ravankole
3 years ago

Thanks good service

Rajesh
Rajesh
3 years ago

Good security

chirag
chirag
3 years ago

good service sar

951995vikash@gmail.com
951995vikash@gmail.com
3 years ago

I love it. Nice weekend in this thread for me.

Goutam
Goutam
3 years ago

Antivirus is very good

prince kumar
prince kumar
3 years ago

Good apps

A K H Sharma
A K H Sharma
3 years ago

I am using quickheal since last 11 years , services and security is improving up to satisfaction level.

padvi breet
padvi breet
3 years ago

it was awesome and coool….i love it because its antitheft was nice because someone’s change my sim card its quickly block them.

Chinni
Chinni
3 years ago

Good

Dagade Rajaram
Dagade Rajaram
3 years ago

Very good

Ravi Kumar Gupta
Ravi Kumar Gupta
3 years ago

Nice

Srawan kumar
Srawan kumar
3 years ago

Good service for Mobile security

Shahil Rai
Shahil Rai
2 years ago

Nice app….LIKED IT !

Amit Kumar Singh
Amit Kumar Singh
2 years ago

good

51
0
Would love your thoughts, please comment.x
()
x