HomeinetUnlock systems infected by Petya Ransomware

Unlock systems infected by Petya Ransomware

Good news for victims infected by the Petya Ransomware. Two security researchers have created an online service and a desktop tool that can help them generate the password needed to unlock their computer.

lock online Petya Ransomware

The Petya Ransomware appeared around March 25th and works in a very different way than any other ransomware. Instead of encrypting files while leaving the computer in a working state, the ransomware crashes the entire system. After a reboot, it encrypts the entire hard drive.

The computer will freeze at this point unless you enter a password that is required before the operating system can boot. Of course, to obtain the password, you will have to pay the ransom demanded by the crooks who developed the Petya Ransomware.

The two researchers noticed that the ransomware was not communicating with any server and realized that the encryption settings and decryption keys were stored locally. Then they found them very easily.

An anonymous researcher (who uses the Twitter handle Leo Stone ) has discovered the algorithms to crack the ransomware and has even created two websites where victims of the malware can obtain their own decryption code.

The problem is that to unlock your system from Petya, you'll need some information that's locked away on the infected computer's hard drive. That's where Fabian Wosar of Emsisoft comes in, who created a tool to extract this information.

 

Download the tool from the link below:

Petya Extractor

 

The first thing you need to do is take the infected hard drive and connect it to another computer. You will need a Windows computer that is capable of running Mr. Wosar's tool. The Petya Ransomware Extractor application scans hard drives for Petya infections and automates the process of extracting the information needed to crack the ransomware.

Once Petya Ransomware Extractor detects the hard drive infected with Petya, press the first button that says “Copy Nonce.” Copy it to the clipboard, and go to any of Leo Stone’s websites, press CTRL + V to paste the text into the box that says “Base64 encoded 8 bytes nonce.”

Once you have the appropriate data, fill in the boxes and press the “Submit” button and wait for the algorithm to do its job.

Once you have the decryption code, put the Petya-infected hard drive back in its original location and restart your computer. Once you see the ransom-demanding screen, simply enter the code in the appropriate box and press Enter.

Your disk will be unlocked, and the data will be decrypted.

The pages for decryption:

 

https://petya-pay-no-ransom.herokuapp.com/

https://petya-pay-no-ransom-mirror1.herokuapp.com/

 

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS