Unfortunately Amit Serper (a security expert) has found a way to prevent the Petya(NotPetya/SortaPetya/Petna) ransomware from infecting computers. The solution is create C:\Windows\perfc file and make it read only. This batch file can help you for quickly: https://github.com/vnheros/utilscripts/blob/master/nopetyavac.bat. It also creates perfc.dat and perfc.dll for more secure. Let run it with Administrator right:
Here are emails which are used to send infected attached files (don't open email when receiving from theses emails):
- wowsmith123456@posteo.net
- iva76y3pr@outlook.com
- carmellar4hegp@outlook.com
- amanda44i8sq@outlook.com
- Let update your Windows, especially patches for MS17-010, CVE 2017-0199.
- Disable SMB port: 445/137/138/139
- Remove WMIC (Windows Management Instrumentation Command-line) tool
This comment has been removed by a blog administrator.
ReplyDeleteThis comment has been removed by a blog administrator.
ReplyDelete