Page 1 of 3 123 LastLast
  1.    28 Mar 2016 #1
    Join Date : Oct 2013
    Posts : 15,630
    64-bit Windows 10 Pro build 14951

    Nasty ransomware overwrites your PC's master boot record

    Itís hard enough for non-technical users to deal with ransomware infections: understanding public-key cryptography, connecting to the Tor anonymity network and paying with Bitcoin cryptocurrency. A new malicious program now makes it even more difficult by completely locking victims out of their computers.

    The new Petya ransomware overwrites the master boot record (MBR) of the affected PCs, leaving their operating systems in an unbootable state, researchers from antivirus firm Trend Micro said in a blog post.

    The MBR is the code stored in the first sectors of a hard disk drive. It contains information about the diskís partitions and launches the operating systemís boot loader. Without a proper MBR, the computer doesnít know which partitions contain an OS and how to start it.

    Trend Micro researchers say Petya is distributed through spam emails that masquerade as job applications. This suggests that its creators target businesses in particular, with the messages being directed at human resources departments.

    The emails have a link to a shared Dropbox folder that contains a self-extracting archive posing as the applicantís CV and a fake photo. If the archive is downloaded and executed, the ransomware is installed.

    The malicious program will rewrite the computerís MBR and and will trigger a critical Windows error that will cause the computer to rebootóa condition known as a Blue Screen of Death (BSOD).

    Following this initial reboot, the rogue MBR code will display a fake Windows check disk operation that normally occurs after a hard disk error, according to computer experts from popular tech support forum

    During this operation, the ransomware actually encrypts the master file table (MFT). This is a special file on NTFS partitions that contains information about every other file: their name, size and mapping to the hard disk sectors...

    Read more: This nasty ransomware overwrites your PC's master boot record | PCWorld
      My System SpecsSystem Spec

  2.    28 Mar 2016 #2
    Join Date : Oct 2013
    Posts : 108
    Windows 10 Clean Install

    Trying to stay one step ahead of ransomware and other nasties, I make a weekly backup, run a quality antivirus, malwarebytes and stay away from sites that I feel might be unsafe.
      My System SpecsSystem Spec

  3.    28 Mar 2016 #3
    Join Date : Nov 2015
    Posts : 388
    Windows 10.0.14393 (1607) Home 64-bit

    I do daily backups, and when I remember to, I use a VM for questionable sites and software.
      My System SpecsSystem Spec

  4.    28 Mar 2016 #4
    Join Date : Jul 2015
    Posts : 34
    Linux Mint 17.3, Windows 10 and 7 Pro

    This a good one to install. Downloading Malwarebytes Anti-Ransomware
      My System SpecsSystem Spec

  5.    28 Mar 2016 #5
    Join Date : Jan 2014
    Walnut Beach, Milford, Ct
    Posts : 16,392
    Win10 Pro / Remix 3.0
      My System SpecsSystem Spec

  6.    28 Mar 2016 #6
    Join Date : Jul 2015
    Posts : 157
    Windows 10 Home x64

    Looks like hacking got more sophisticated
      My System SpecsSystem Spec

  7.    28 Mar 2016 #7
    Join Date : Jul 2015
    Posts : 135
    Windows 10 Enterprise (64-bit)

    Have a backup image in hand and get your self a copy of " Sandboxie Control 5.10 latest version " and educate your self, via you tube instruction's and you wont ever have one worry about getting nailed by any of these evil and criminal engineered attacks on any or your devices...

    Like I have said before it takes me at least three days to set up a clean install and configured to my taste " if no back up in in hand "

    Sandboxie is the most import protection on the market if you educate yourself in how it works and the ins and outs " been using this very fine app for the last 8 years and hands down " not one glitch or a fatal attack on any of my toys " Windows, Mac, and Linux and on a couple of smartphones powered by android

    Deep Freeze is also a must have asset
      My System SpecsSystem Spec

  8.    28 Mar 2016 #8
    Join Date : Sep 2014
    Sydney NSW Australia
    Posts : 269
    Windows 10 Pro 64bit 1607 (14393.222)

    I use Malwarebytes and Avast Pro AV. Avast comes with a browser, Safe Zone it is called.
    I NOW backup after a little problem about 2 weeks ago. I do hope I am SAFE.
      My System SpecsSystem Spec

  9.    28 Mar 2016 #9

    Now to clarify aren't most newer systems UEFI, which no longer uses the MBR method? and thus making the virus non-invasive?

    I thought that was, in part, one of the purposes of UEFI?
      My System SpecsSystem Spec

  10.    29 Mar 2016 #10
    Join Date : Sep 2014
    Posts : 80

    Quote Originally Posted by Trust_No1 View Post
    Now to clarify aren't most newer systems UEFI, which no longer uses the MBR method? and thus making the virus non-invasive?

    I thought that was, in part, one of the purposes of UEFI?
    Yes. If you installed Windows via UEFI then that ransomware doesn't do anything since EFI doesn't use boot sectors such as the MBR and uses a EFI file located on the partition. It also helps to have Secure Boot enabled since that also prevents any tampering with the EFI files.
      My System SpecsSystem Spec

Page 1 of 3 123 LastLast

Similar Threads
Thread Forum
Windows Update Overwrites new files with old ones.
So I installed windows 10 earlier this week, I believe the 7th of February. The system moves all my files into windows.old. I retrieve my vital files (mostly current projects and some game files) and marvel at how much faster my computer seems to...
Windows Updates and Activation
Solved Can't re-establish Master Boot Record on my Windows 10 Boot drive
I'm perplexed and frustrated. I have a legacy 64 bit dual core desktop (ASUS mobo). I have several Sata hard drives in it with the 4th partition of my 1 Terabyte drive containing my Windows 10 Professional boot OS. After converting another...
Installation and Setup
Window 10 ver 1511 overwrites device drivers - need to reinstall
The original upgrade of my Samsung Q330 laptop from W7 to W10 wiped some of the device drivers, and required the following A physical change of wifi card, since the Broadcom card was incompatible with W10 Reinstallation of the Synaptics...
General Support
Something nasty in my tech preview
I have had a copy of the technical preview since the beginning, using WD and the free Malwarebytes with no problems up till last night. My home page on Edge is which has my email and news, and I was looking through the many news items when a...
AntiVirus, Firewalls and System Security
'Nasty' Reg Hack
There's another registry hack floating around the internet for W10TP called 'Experimental Login' DO NOT try it, there's a darn good chance you won't be able to log back in after a restart or clean start. It's a big PITA! 11523
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 20:35.
Find Us
Twitter Facebook Google+

Windows 10 Forums