Torrent Invites! Buy, Trade, Sell Or Find Free Invites, For EVERY Private Tracker! HDBits.org, BTN, PTP, MTV, Empornium, Orpheus, Bibliotik, RED, IPT, TL, PHD etc!



Results 1 to 5 of 5
Like Tree4Likes
  • 3 Post By whiteLight
  • 1 Post By DGM

Thread: How to decrypt Petya Ransomware for Free

  1. #1
    It's Alright,You Heard?
    whiteLight's Avatar
    Reputation Points
    214616
    Reputation Power
    100
    Join Date
    Aug 2014
    Posts
    9,269
    Time Online
    462 d 3 h 45 m
    Avg. Time Online
    3 h 7 m
    Mentioned
    2378 Post(s)
    Quoted
    807 Post(s)
    Liked
    12475 times
    Feedbacks
    440 (100%)

    How to decrypt Petya Ransomware for Free

    Ransomware has risen dramatically since last few years and is currently one of the most popular threats on the Internet.

    The Ransomware infections have become so sophisticated with the time that victims end up paying ransom in order to get their critical and sensitive data back.But if you are infected with Petya Ransomware, there is good news for you.

    You can unlock your infected computer without paying the hefty ransom. Thanks to the Petya author who left a bug in the Ransomware code.

    What is Petya Ransomware?

    Petya is a nasty piece of ransomware that emerged two weeks ago and worked very differently from any other ransomware.

    The ransomware targets the victims by rebooting their Windows computers, encrypting the hard drive's master boot file, and rendering the master boot record inoperable.A master boot record (MBR) is the information in the first sector of any hard disk that identifies how and where an OS is located while a master boot file is a file on NTFS volumes that includes the name, size, and location of all other files.

    Once done, the infected PC restarts and the Petya ransomware code is booted rather than the operating system, displaying a ransom note that demands 0.9 Bitcoin (approx. US$381) in exchange for the decryption key to recover the system's files.

    Now, without the decryption password, the infected PC would not boot up, making all files on the startup disk inaccessible.
    However, a researcher who goes by the Twitter handle leostone has developed a tool that generates the key Petya requires decrypting the master boot file.

    Here's How to Unlock your Petya-infected Files for Free

    The researcher discovered a weakness in the nasty malware's design after Petya infected his father-in-law's PC.

    According to security researcher Lawrence Abrams from the Bleeping Computer, the key generator tool developed by Leostone could unlock a Petya-encrypted PC in just 7 seconds.In order to use the Leostone's password generator tool, victims must remove the startup drive from the Petya affected computer and connect it to another Windows computer that's not infected.

    The victim then needs to extract data from the hard disk, specifically:

    -the base-64-encoded 512 bytes that start at sector 55 (0x37h) with an offset of 0.
    -the 64-bit-encoded 8-byte nonce from sector 54 (0x36) offset 33 (0x21).

    This data then needs to be used on this Web app (mirror site) created by Leostone to generate the key. The victim will then retrieve the key Petya used to decrypt the crucial file.


    Here's a Simple Tool to Unlock your Files For Free

    Since the Leostone's tool is not a straight-forward method, extracting the encrypted data is not easy for many victims.

    The good news is that Fabian Wosar, a separate researcher, has created a free tool called the Petya Sector Extractor that can be used to easily extract the data in seconds.In order to use Petya Sector Extractor, victims must run the tool on the uninfected Windows computer that is connected to the infected hard drive from the affected computer.

    Abrams provided this step-by-step tutorial that will walk victims through the entire process.

    This is a great solution to decrypt your infected files, but most likely, the Petya authors have already heard about this tool and are modifying their code to disable the solution. So, there is no guarantee the tool will continue to work indefinitely.
    DGM, kuho and ciganus like this.

  2. #2
    DGMDonor Icon
    DGM is offline
    iLLuSioNist
    DGM's Avatar
    Reputation Points
    77147
    Reputation Power
    100
    Join Date
    Aug 2015
    Posts
    4,744
    Time Online
    204 d 20 h 52 m
    Avg. Time Online
    1 h 33 m
    Mentioned
    969 Post(s)
    Quoted
    453 Post(s)
    Liked
    4014 times
    Feedbacks
    170 (100%)
    Will be very useful for many but hackers have surely started working on new one too.
    ciganus likes this.
    DGM Says ! Be Busy Be Happy TI'ian. !

  3. #3
    User IllMethods's Avatar
    Reputation Points
    10
    Reputation Power
    30
    Join Date
    Apr 2016
    Posts
    29
    Time Online
    1 d 16 h 50 m
    Avg. Time Online
    N/A
    Mentioned
    2 Post(s)
    Quoted
    3 Post(s)
    Liked
    3 times
    Feedbacks
    1 (100%)
    Damn... This is a whole other level. I'm still trying to figure out how to properly remove the one that installs all those search engines on your pc and then stops you from uninstalling them... All I did was install Imgburn to get that one :/

    Did a whole lot of Googling and ended up giving up and doing a reinstall...

    Any idea how this one gets into your system?

  4. #4
    User caprii's Avatar
    Reputation Points
    10
    Reputation Power
    31
    Join Date
    Dec 2015
    Posts
    44
    Time Online
    1 d 16 h 18 m
    Avg. Time Online
    N/A
    Mentioned
    11 Post(s)
    Quoted
    6 Post(s)
    Liked
    4 times
    Feedbacks
    0
    Quote Originally Posted by IllMethods View Post
    Any idea how this one gets into your system?
    Did you open something suspicious lately? Like a file you downloaded? I mean there must be a file that you opened because the code inside must be executed in order to harm your computer..

  5. #5
    User IllMethods's Avatar
    Reputation Points
    10
    Reputation Power
    30
    Join Date
    Apr 2016
    Posts
    29
    Time Online
    1 d 16 h 50 m
    Avg. Time Online
    N/A
    Mentioned
    2 Post(s)
    Quoted
    3 Post(s)
    Liked
    3 times
    Feedbacks
    1 (100%)
    I already explained how I got the other one, it was bundled in the imgburn install.

    I am more curious as to how the new one gets in...


Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •