Malware · critical

How to fixPETYA_NOTPETYA_WIPER

Petya / NotPetya Ransomware-Wiper

What this error means

Petya / NotPetya Ransomware-Wiper is a critical-severity malware/security issue. Petya/NotPetya is a highly destructive wiper malware masquerading as ransomware. It targets Windows computers, encrypting the Master File Table (MFT) and overwriting the Master Boot Record (MBR) to completely prevent the operating system from booting. It's most often caused by SMB vulnerabilities (EternalBlue/EternalRomance) on unpatched machines, compromised administrative credentials harvested via Mimikatz-like methods and malicious updates in accounting software supply chains. The steps below are ordered to resolve this efficiently.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 4 complete
01Install MS17-010 patch and keep system updated

Install MS17-010 patch and keep system updated.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Disable SMBv1 and limit administrative share access

Disable SMBv1 and limit administrative share access.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Use boot sector write protections in BIOS/UEFI

Use boot sector write protections in BIOS/UEFI.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
04Perform clean OS installation if MBR/MFT is completely destroyed

Perform clean OS installation if MBR/MFT is completely destroyed.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • SMB vulnerabilities (EternalBlue/EternalRomance) on unpatched machines
  • Compromised administrative credentials harvested via Mimikatz-like methods
  • Malicious updates in accounting software supply chains