Skip to content
www.24-my.info
www.24-my.info
Page of "Hackney hacker found a way to locally stop the virus-extortionist Petya".
  • HiTech
  • politics
  • RUNEWS
  • sport
  • uanews
  • world

Hackney hacker found a way to locally stop the virus-extortionist Petya

Uncategorized June 28, 2017


 


Found a way to locally stop the virus-extortionist Petya

Reuters

Found a way to locally stop the execution of the program virus-the extortioner Petyaaffecting many computers in Russia and Ukraine. For this in the folder with Windows you need to create a file without extension with the name “perfc” – his lack of virus checks before acting destructively. However, experts of “Kaspersky Lab” claimedthat networks attacked another virus.

Manual to block of the virus published in his Telegram-channel specialist in cyber security Alexander Litreyev.

In detail the mechanism of virus described by the experts of Positive Technologies. TASS reports that intensified on the eve Petya virus affects the master boot record (MBR code, which is needed to load the operating system) boot sector of disk. The malware encrypts the record and replaces its own data. After entering the virus into the system gives the computer a command to reboot in 1-2 hours, and after reboot instead of the operating system runs the malicious code.

If you have time before the reboot to run the command bootrec/fixMbr (allows you to restore the MBR), it is possible to recover the operating system and run it, noted in Positive Technologies. In this case, the files will still be encrypted, to decrypt them requires knowledge of a special key.

Locally disable encryption by creating a file “C:Windowsperfc” experts say Positive Texhnologies. The virus, which has administrator privileges, before substitution, the MBR checks to the address specified empty file with no extension with the same name as the name of the dll file of the Trojan horse. If a virus finds an empty file, the execution of the virus program will stop.

However, if the virus is not an administrator he will not be able to verify the presence of an empty file in the folder “C:Windows”. Then the process of file encryption will still run, but without replacing the MBR and restart the computer.

To avoid becoming a victim of such an attack, experts recommend to update the Windows operating system, as well as to minimize user privileges on workstations.

If infection has occurred is to pay the cyber criminals you should not. “The postal address of the violators were blocked, and even in the case of payment of redemption key to decrypt the files probably will not be received,” said Positive Technologies.

27 Jun virus ransomware, locking access to data and demanding money for the unlock, attacked dozens of companies and organizations in Russia and Ukraine and then spread around the world. How figured out the experts of the company Group-IB, specializing in computer security and cyber defence, the reason for the large-scale attacks in the energy, telecommunications and financial companies in Ukraine and in Russia has become virus-cryptographer Petya, which prevents your system from booting, locks computers and demands a ransom.

According to preliminary estimates of Group-IB, the virus attacked nearly 80 companies, most of whom were Ukrainian. Russia was attacked by “Rosneft”, “Bashneft”, Mars, Nivea and Mondelez International (maker of chocolate Alpen Gold). The Bank of Russia also reported cyber attacks on Russian credit institutions which have not led to disturbances in the operation of banks.

Virus-the extortioner struck Petya network […]

In Odessa in the murder of two children, th[…]

  • Статьи о медицине

Recent Posts

  • На Покровском направлении снизилась интенсивность боев – Генштаб ВСУ
  • ​”Перевозка сырой нефти в Венгрию снова прекращена”, – Сийярто отреагировал на новый удар по “Дружбе”
  • Украина впервые обошла Россию в поставках стратегического продукта в Индию
  • ​Фото в три ряда: в Сети показали мемориал в Пхеньяне с ликвидированными на Курщине солдатами Кима
  • Россия усилила вербовку граждан одной из среднеазиатских стран для войны в Украине

Categories

  • HiTech
  • politics
  • RUNEWS
  • sport
  • uanews
  • Uncategorized
  • usa-world
  • world
Copyright © 2025 www.24-my.info All Rights Reserved.
Powered by WordPress. Designed by Yossy's web service.
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT