Trojan.Ransom.Petya (Petya 2.0 2016 Ransomware, flashing lights warning)

Sdílet
Vložit
  • čas přidán 26. 06. 2017
  • / danooct1
    / danooct1
    hopefully my explanation of how it spreads/works is accurate, but everything with it is pretty new so i might be wrong.
    links for some good reading on the topic:
    blog.malwarebytes.com/threat-...
    blog.kryptoslogic.com/malware...
    www.malwaretech.com/2017/06/p...
    Special thanks to the following patrons for their support! I really appreciate it!
    crymera
    Mister Sparkly
    John Kizer
    Numou Impfox
    Jacob W.
    Joshua Mack
    Thomas H Khoury
    squigly-kip
    Sleepy Owl
    BluePolarBearz
    Alice J
    Blaise
    CutePikachu
    Renaud Bedard
    Rosenator
  • Zábava

Komentáře • 818

  • @danooct1
    @danooct1  Před 7 lety +969

    My mistake - this is actually the 2.0 version of Petya from 2016, and not the network spreading variant that hit Europe and other parts of the world yesterday. I'll try to have a new video up tonight if I can find the *correct* sample, maybe I'll even LAN a few computers together and let it go to town.
    thanks to everyone who let me know about this!

    • @louispiccoli1852
      @louispiccoli1852 Před 7 lety +1

      danooct1 thanks

    • @Cvolton
      @Cvolton Před 7 lety +1

      if you find the new sample, please showcase the spreading

    • @drkastenbrot
      @drkastenbrot Před 7 lety

      Tanasije Tasa you need to disable smb and stop the winmgmt service

    • @twitchytails
      @twitchytails Před 7 lety

      danooct1 will you be using the same variant (red) or are you going to use the yellow or green?

    • @inactive6226
      @inactive6226 Před 7 lety

      Is this new?

  • @TheDopeyElephant
    @TheDopeyElephant Před 7 lety +232

    Now I know what to get if my neighbor is stealing my wifi

    • @zwz.zdenek
      @zwz.zdenek Před 4 lety +26

      A WPA2-ready router, I hope!

  • @digitaljokerman
    @digitaljokerman Před 7 lety +2363

    I wanna cry right now

  • @asasasasasasasa1982
    @asasasasasasasa1982 Před 7 lety +563

    Fucking hell, this one is actually legitimately TERRIFYING, and not just because of the "screamer" (more of a flasher).
    Can't really explain why, it just seems so...

    • @LegoLad659
      @LegoLad659 Před 7 lety +133

      Maybe because it uses the BIOS text, rather than opening a new window with the demand. This also means it doesn't actually boot to Windows, so you have to use another computer in order to get the key.
      So anyone with only a single computer to their name is pretty well screwed unless they're willing to not only shell out the money for the ransomware, but also for an entirely new computer just to download Tor and *get* to that point in the first place. Really it'd just be cheaper to only get the new computer.

    • @fdbosco7111
      @fdbosco7111 Před 7 lety +28

      I wonder if there really is a key to restore the computer though, it may well be a scam

    • @vivz5075
      @vivz5075 Před 7 lety +48

      LegoLad659 Good to see that I'm not the only one who's kinda scared by these things.

    • @kawaiiprincess3607
      @kawaiiprincess3607 Před 7 lety

      didn't they change Tue name to Jumpscare?

    • @oops8685
      @oops8685 Před 7 lety +29

      WCry wasn't all that scary cause it was just an ugly pop up with broken English instructions that were bogus. This one actually locks you out of the system and essentially turns your computer into a glorified note pad

  • @KnoppersBomber
    @KnoppersBomber Před 7 lety +195

    Well, the skull is pretty dope.

    • @seismic112
      @seismic112 Před 4 lety +6

      DevilsAvocado it gave me a seizure

    • @AX_-
      @AX_- Před 3 lety

      NICE ASCII DRAW .RIGHT !!

  • @TheLivingHeiromartyr
    @TheLivingHeiromartyr Před 7 lety +98

    I now realize how much of a blessing it is that I have nothing on my computer that I really need.

  • @mikelmendioroz8210
    @mikelmendioroz8210 Před 7 lety +122

    This is the "red" variant of Petya which can be decrypted due to vulnerabilities in the encryption itself. The new(ish?) green one has it fixed and there's no cure.

    • @xAffan
      @xAffan Před 6 lety +4

      Mikel Mendioroz I can decrypt all versions in 2 mins.

    • @ItsNotFrey
      @ItsNotFrey Před 5 lety +40

      xAffan
      Proof or it’s BS.

    • @stephaniehutchens3222
      @stephaniehutchens3222 Před 5 lety +11

      and xAffan gave no proof

    • @Cloud_Strife1997
      @Cloud_Strife1997 Před 5 lety

      @@xAffan Proof.

    • @xAffan
      @xAffan Před 5 lety +21

      @@Cloud_Strife1997 for everyone asking for proof, Petya has been decrypted by malware bytes lab so yeah

  • @JetFuueled
    @JetFuueled Před 7 lety +230

    Read the title as Peta at first and was like "Oh boy"

  • @23trekkie
    @23trekkie Před 7 lety +849

    - requires e-mail to get the key to unlock the files
    - blocks *entire computer* which makes using e-mail obviously impossible.
    logic so much.

    • @H3llfire320
      @H3llfire320 Před 4 lety +9

      @50 SUBS WITHOUT A VIDEO? yeah I dont think that will go well if you did it on your phone

    • @thisisaperson1536
      @thisisaperson1536 Před 4 lety +5

      10/10 logic amirite

    • @thisisaperson1536
      @thisisaperson1536 Před 4 lety +7

      Cool thing is that it does have a decryption key. I am not telling cuz
      1. I dont know it, someone actually typed the decryption key in and it restored everything but I forgot it
      2. The key is subject to change every now and then.

    • @xeroxcopy8183
      @xeroxcopy8183 Před 4 lety +5

      Everyone here had a soybot reddit moment r/soyboy r/openmouth

    • @niccoart
      @niccoart Před 4 lety +6

      The logic, thats who have enought money for pay, also have another device

  • @Turutle
    @Turutle Před 7 lety +112

    One of the few CZcams notifications i'll check out right away

  • @bluegoatfanclickyes1825
    @bluegoatfanclickyes1825 Před 2 lety +19

    This is how everyone imagined malware

  • @sundragoonx
    @sundragoonx Před 3 lety +103

    Person1: oh hey what’s your dog’s name?
    Person2: ransomware.
    P1: How about you Petya ransomware?
    P2: *intense pupper petting*

  • @olekzonder
    @olekzonder Před 7 lety +195

    I've seen this ransomware on the Russian channel.The worst part is that russian systems were encrypted, but channels focus on the fact that Ukrainian systems were encrypted as well.And most channels proudly announce that ransomware's name is the name of Ukrainian president Pyotr (Petya) Poroshenko.I hate this politician crap.

    • @sabhotep5153
      @sabhotep5153 Před 7 lety +12

      Our channels state that our country suffered the most. Also it is seemingly implied the virus originates from your country (although the name is equally popular in both countries).

    • @isaacmoraesdornelasdesouza3314
      @isaacmoraesdornelasdesouza3314 Před 4 lety +10

      Turtles Rock yes Greece is a country

    • @screamsinrussian5773
      @screamsinrussian5773 Před 4 lety

      @@isaacmoraesdornelasdesouza3314 what's a Greece?

    • @whoopssteyrs
      @whoopssteyrs Před 4 lety +2

      @[screams in Russian]
      i think it's that stuff thats leftover on a frying pan if bacon is cooked
      [this reply is a joke]

    • @iamfrommiami
      @iamfrommiami Před 4 lety +1

      @@KawaiianArgument Exotic Butters. Exotic Butters. Exotic Butters.

  • @stalinyourleader3846
    @stalinyourleader3846 Před 7 lety +9

    Hey, just wanted to say that I love these virus videos you make! in the last week I've been binge watching a ton of em, so I hope I've made you that sweet ad money so you can continue doing this awesome stuff!
    (*insert floppy drive seek test here*)

  • @defb4dishonor211
    @defb4dishonor211 Před 7 lety +36

    Kinda hard to have sympathy for companies when wannacry just happened and they don't learn from mistakes. Just sucks that hospitals can be affected by this and put people's lives at risk

  • @yungsunnyd3610
    @yungsunnyd3610 Před 7 lety +6

    Thanks for keeping my PC safe with your knowledge! Glad to have a youtuber like you

  • @jimcarreyfan01
    @jimcarreyfan01 Před 7 lety

    im so glad i turned on notifications for this channel omg this is the earliest ive been ? great video !!

  • @InterstellarVulpine
    @InterstellarVulpine Před 7 lety +164

    GOT YOUR COMPUTER, GIMME YA MONEY, FUCCBOI!

  • @MacTrillion
    @MacTrillion Před 7 lety +24

    Did you happen to test the supposed killswitch for Petya? In which you would create an extension-less "perfc" file and place it in C:\Windows?

  • @KynikossDragonn
    @KynikossDragonn Před 7 lety

    I don't know why but I really like how your videos end with the captions just saying [Chiptune] at the end.

  • @marytracy7955
    @marytracy7955 Před 7 lety +17

    This is nice to think about.

  • @3l3TR1C
    @3l3TR1C Před 6 lety +7

    "Do we want to make changes. You bet we do."
    danooct1 - June 27, 2017, or October 24, 2016, at 12:24 pm.

  • @deltacell4298
    @deltacell4298 Před 7 lety +20

    "We'll run this dropper which will infect our pc, search for more computers to infect and ultimatly crash the system so the new bootloader can take hold and decrypt your drive. So let's run it!"
    Dan. Dan never changes.

  • @acrobro5912
    @acrobro5912 Před 4 lety +69

    friend: where is petya ur girlfriend
    me:she ransomware

    • @Keznen
      @Keznen Před 4 lety +10

      Your girlfriend is named Pyotr?

    • @acrobro5912
      @acrobro5912 Před 3 lety +2

      @@stereocomponent and u lesbian

    • @Katfri3
      @Katfri3 Před 3 lety +10

      Why is gay and lesbian an insult

    • @JagaGamingDude
      @JagaGamingDude Před 3 lety +1

      this pun is so underrated

    • @knox7316
      @knox7316 Před 2 lety +1

      @Badger Drawz Not sure why you felt the need to bring incels into that, or is it just another buzzword you like to fling around?

  • @aurathedraak7909
    @aurathedraak7909 Před 7 lety +43

    This is so Dan stuff!

    • @aurathedraak7909
      @aurathedraak7909 Před 7 lety +1

      Jealous

    • @Kevzz2srs
      @Kevzz2srs Před 7 lety

      Aurα вírdч i mean if you into that shit but its pretty gay tbh

    • @Kevzz2srs
      @Kevzz2srs Před 7 lety

      Aurα вírdч Not a programmer but you love 'coding' hm

  • @spacekraken666
    @spacekraken666 Před 7 lety +161

    Petya плохой.
    Не будь как Petya.

    • @wolfy7561
      @wolfy7561 Před 5 lety +2

      I am not Russian.

    • @broddajanes6910
      @broddajanes6910 Před 5 lety +37

      He said "Petya is bad. Don't be like Petya."

    • @Cold88
      @Cold88 Před 4 lety

      Ок

    • @nergon7821
      @nergon7821 Před 4 lety +4

      Я Петя кста

    • @iamfrommiami
      @iamfrommiami Před 4 lety +8

      Миша, Петя по утру вызывали сатану.

  • @butterflywings9747
    @butterflywings9747 Před rokem +1

    That flashing skull is, like, specifically designed to cause seizures oh my gosh. Thanks for putting the flash warning!

  • @rusty9287
    @rusty9287 Před 7 lety

    hey Dan, nice double upload

  • @crazyfatefan
    @crazyfatefan Před 7 lety +1

    I didn't know another attack happened till you uploaded this video. Thank you for showing us. This one spread very fast and it wasn't to long ago that we had Wannacry attack. Sadly like people say...This won't be the last we see ransomware. They will always be made to find new exploits and still demand money. Viruses just keep getting scarier and scarier.

  • @LuizFernandoSC
    @LuizFernandoSC Před 7 lety +5

    Its fantastic how a 226KB file can do all of this so fast.

  • @DMack6464
    @DMack6464 Před 7 lety +53

    *- Computer?*
    *Computer machine broke.-*
    *-Understandable have a great day.*

    • @vayretunes
      @vayretunes Před 7 lety

      D Mack GREAT DAY*

    • @kawaiimango646
      @kawaiimango646 Před 7 lety

      D Mack MY COM🅱️UTER IS greaaaaaaat. Have a nice day 🅱️eter

  • @mattquellobello
    @mattquellobello Před 4 lety +103

    Petya: encrypts the sistem
    Victim: re-install the sistem
    Petya creator: You are not supposed to do that
    Victim: This Is what i call a "pro gamer move"

    • @jumprjimg1598
      @jumprjimg1598 Před 4 lety +1

      👽👌

    • @kybravo3744
      @kybravo3744 Před 4 lety +8

      you still lose your data if you haven't backed it up externally

    • @gigigaou
      @gigigaou Před 3 lety +2

      Data has left the chat

    • @marcosgreg9983
      @marcosgreg9983 Před 3 lety

      What if deepfreeze was on?

    • @realpraxor
      @realpraxor Před 3 lety

      wouldn't you need to fix the MBR since it got destroyed from petya

  • @zvalex3539
    @zvalex3539 Před 7 lety +20

    Jesus ;_; ill be keeping an eye on my systems network for a while now...

    • @rechtrecht
      @rechtrecht Před 6 lety +1

      ZeroVoiden Alex it is like the Virus you always feared

  • @InfernalMonsoon
    @InfernalMonsoon Před 7 lety +11

    Whenever I see freaky viruses like this where they genuinely scare me and make me fear for my sanity and machine, I think I might have a bad case of cyberphobia which sounds silly since I love electronics, guess they need a new name for computer viruses :/ Keep your machines properly protected folks!

    • @AdamantLightLP
      @AdamantLightLP Před 7 lety

      DarkStarAngelo Not sure it'd be a phobia as that is generally an exaggerated fear (at least as I see it) Viruses and stuff are things that are legitimately scary. Luckily a lot of them can be avoided.

    • @InfernalMonsoon
      @InfernalMonsoon Před 7 lety +1

      I guess you could say I am terrified of them. I keep my PC locked up as tight as possible but if even the smallest bug makes its way through, I start to freak out and wonder how it got in. But I manage to compose myself and get rid of the threat asap!

  • @Jedexpff
    @Jedexpff Před 5 lety

    I'm here for Victor Montoya, thanks you for this video dude :D

  • @StarWarriorKirby
    @StarWarriorKirby Před 7 lety

    Nice video, Dan.

  • @oledcrt
    @oledcrt Před 7 lety +34

    I looked up one of the bitcoin addresses I saw in a screenshot of this ransomware, and people have sent almost $9,000 to it so far. I wonder how many addresses there are besides that one.

  • @PantsYT
    @PantsYT Před 4 lety +5

    Gee, that scary encryption message must have been encrypted with Google Translate grade translation algorithm.

  • @fireplayer442
    @fireplayer442 Před 7 lety

    Nice, Petya is back.

  • @Drunkycat
    @Drunkycat Před 7 lety +56

    saw this thing at russian news channel yesterday

    • @Randomizer92mx
      @Randomizer92mx Před 7 lety +3

      Drunkycat I heard this virus actually comes from Russia

    • @nikitpad3532
      @nikitpad3532 Před 7 lety +13

      Randomizer Petya is a Russian name. That's quite obvious.

    • @200nutman4
      @200nutman4 Před 7 lety +4

      ESET company said that virus began to spread from Ukraine.

    • @user-ho5ti6hq2f
      @user-ho5ti6hq2f Před 7 lety +1

      He's a Petya Bukalo, a guy from Ukraine, he said to everyone "ДА ИДИ ТЫ НА!" - "GO TO HELL!", even to his teacher. Watch "Ростян" channel for more information.

    • @FrogDoc
      @FrogDoc Před 7 lety

      дороу

  • @undynethefish2872
    @undynethefish2872 Před 7 lety

    Thanks for video presenting this ransomware.

  • @SATYATAMA
    @SATYATAMA Před 7 lety +1

    I love the ending song

  • @cyborgnoodle426
    @cyborgnoodle426 Před 7 lety

    gasp, new video

  • @SmeddyTooBestChannel
    @SmeddyTooBestChannel Před 7 lety +2

    Just to elaborate, a "network" constitutes as computers that are linked together and can access each other's files and whatnot and _not_ computers that are simply connected to the same router, right?

    • @TotalInsanity4
      @TotalInsanity4 Před 7 lety +4

      Smedis2 A router acts as a local network, so yes, the virus will spread to anything using the same router

  • @tunainoil
    @tunainoil Před 7 lety +1

    "Happy, happy Halloween, Halloween, Halloween!/ Happy, happy Halloween, Silver Shamrock!"

  • @chakalzoku3467
    @chakalzoku3467 Před 7 lety

    keep it up Dan!!!

  • @HYPNOGLANCE87
    @HYPNOGLANCE87 Před 7 lety +7

    The pirates have hijacked my pc!!! Damn!.

  • @ryanaxtell5069
    @ryanaxtell5069 Před 7 lety +1

    What's the ending song from? I want it as my ringtone. But as the chiptune version.

  • @dan3a
    @dan3a Před 7 lety +1

    Thanks daniel ! Now all your subs know how this ransomware looks like ! And... they don't need to try to install this ransomware to look what he looks like.
    (sorry if my english is awful i'm frensh)

    • @link_legend819
      @link_legend819 Před 7 lety

      :!: Dan3A :!:, this was the older version though. He'll test the other one later.

  • @TCGProductions03
    @TCGProductions03 Před 5 lety +4

    The decryption key may be stored in the boot sector itself, and it's looking for the end-user to type that key in. Maybe infect a physical computer, pull the drive, put it in another computer and use a hex editor to see if you could maybe pull the decryption key from the boot sector?

  • @renayuuki2759
    @renayuuki2759 Před 7 lety

    這個中文字幕啊,excited!

  • @duckmaneuvers
    @duckmaneuvers Před 7 lety +14

    That one guy who's willing to sacrifice a couple of virtual machines just to let us know how such evil programs work....
    Great job, buddy.

  • @geekygirl2596
    @geekygirl2596 Před 4 lety

    So my moms computer had what was probably a petya variant. I shut it down during chkdisk. After realizing her harddrive was fine ( ie hadn't actually failed and wasnt a real chkdisk), I brought it to a reputable it guy the next town over (since none are near me). It took him 3 days and my moms computer getting reinfected along with his computers but he fixed it! I think he got unlimited data (a good data connection is rare up here cuz I'm out in the boonies of northeastern mn) and turned his phone into a mobile hotspot. As long as I live in the area, he has my buisness at least. Thanks techbytes!

  • @AoSXSilent
    @AoSXSilent Před 7 lety +1

    I turned on my PC this morning and my monitor was flashing colors and my heart was pounding.
    But it was my only my left monitor and it proceeded to boot normally.

  • @dan55800
    @dan55800 Před 7 lety

    Give me a download link of that

  • @damian9303
    @damian9303 Před 7 lety +57

    This is a WinRAR Extractor looking at the icon, you should try opening the file through WinRAR and see what it extracts

    • @expression6180
      @expression6180 Před 7 lety +35

      Damian9303 I wouldn't be surprised it if was only given that icon in an attempt to fool people.

    • @davidhubbard8353
      @davidhubbard8353 Před 7 lety +33

      Damian9303 It's a disguised executable, not a WinRAR extractor...

    • @nikitpad3532
      @nikitpad3532 Před 7 lety +3

      Kyoshiro Tasya Executables can be extracted into sections like .rsrc, .text etc...

  • @remyfortuin7977
    @remyfortuin7977 Před 2 lety +3

    1:58 My uncle was watching this with me and started breakdancing, he has some kickass moves.

  • @borisvolski
    @borisvolski Před 4 lety

    Sounds like... "this is Petya! Run somewhere! Quick!"

  • @scaleop4
    @scaleop4 Před 5 lety +1

    this is why is a good idea to back up your system and anything in portent just in case.

  • @HoneyOTU
    @HoneyOTU Před 7 lety

    Good vid Dan

  • @TekWarfare
    @TekWarfare Před 7 lety +1

    Out of curiosity, at 1:20 when you say it's possible to recover your PC with a live CD how do you?

    • @xAffan
      @xAffan Před 6 lety

      TekWarfare No it isnt.

  • @dullboykrieg
    @dullboykrieg Před 7 lety

    OH YEAH NEW DAN VIDEO

  • @CZghost
    @CZghost Před 7 lety

    Why's that the video stops playing when I'm logged on, and plays perfectly while anonymous?

  • @Endaplayz
    @Endaplayz Před 2 lety

    You are a villain of all malwares!

  • @JOELwindows7
    @JOELwindows7 Před 7 lety +1

    *"I've pet your master file!"*

  • @KRcanondaisa
    @KRcanondaisa Před 7 lety

    Would this be able to spread through a Tunngle LAN network?

  • @brandon.smith8667
    @brandon.smith8667 Před 7 lety

    dancoot1 do you have any websites ware i can get hold of some of the malware you have

  • @user_romanport
    @user_romanport Před 7 lety +1

    Oh man, imagine this on a college intranet.

  • @arthurtheanteater7649
    @arthurtheanteater7649 Před 5 lety

    can i use this video for a school project that i will be doing?

  • @garnitek7722
    @garnitek7722 Před 7 lety

    Yes to do it!!!

  • @kjaro621
    @kjaro621 Před 6 lety

    This hit my school

  • @97Giorgos97
    @97Giorgos97 Před 7 lety +1

    Clicks on video.
    *Likes*
    Continues to watch 😀

  • @ongong9772
    @ongong9772 Před 7 lety +6

    The skull screen looks like the "Apple" virus for DOS.

  • @Spyros1976
    @Spyros1976 Před 2 lety +1

    But what if you go in the websites that the EncryptedScreen says in step 2???

  • @CheddarVG
    @CheddarVG Před 5 lety

    The skull looks pretty neat, I'm not gonna lie.

  • @zeeby1
    @zeeby1 Před 7 lety +3

    Now that's a plus to living in a countryside!

  • @adamtheman17
    @adamtheman17 Před 4 lety +1

    i have a question i have few old computers of mine and my parents with personal data that been infected by ransomeware and i was wondering
    if you got or know where to find tools to get those files back

    • @Odsku
      @Odsku Před 4 lety

      Depends on the ransomware and encryption algorithm

  • @corgy9832
    @corgy9832 Před 4 lety +8

    Я русский сижу и крепеж с произношения "петюа"))))

  • @thmUNIX
    @thmUNIX Před 4 lety

    This is a 2015 version, there is a decryptor for it.

  • @LordGabenisIlluminati
    @LordGabenisIlluminati Před 7 lety +17

    What is it with ransomware and bad spelling?

    • @drakonua
      @drakonua Před 4 lety

      @@HiddenButcher It was made in Russia to attack Ukrainian computers.

    • @knox1392
      @knox1392 Před 4 lety +1

      Russians. They can barely speak english too so lol.

  • @15fakeaccount
    @15fakeaccount Před 7 lety

    I think I have seen this already, DiskKiller!

  • @fazygiot4217
    @fazygiot4217 Před 6 lety

    im in the patrons!

  • @boxi.iroasztal
    @boxi.iroasztal Před 2 lety +1

    Me watching this at 1 A.M.: Oooh interesting
    My eyes: Please just end my suffering already

  • @user-wg9hc5pf2r
    @user-wg9hc5pf2r Před 3 lety

    MVP: User Account Control.

  • @reversevelocity
    @reversevelocity Před 7 lety

    Ransomware with creativity? That's a new one.

  • @payday121
    @payday121 Před 7 lety +4

    Stuff like this keeps getting released.. makes me a bit worried. What sort of places would this virus come from? I want to know what to avoid.

    • @nerd0Chija
      @nerd0Chija Před 7 lety +1

      payday121 Mostly as file attachment form e-mail (pdf, M$ Office file with macro) or form infected network.

    • @Vordhosbn
      @Vordhosbn Před 7 lety +1

      And as danooct has shown, .exe's disguised as .zip files.

  • @siregne4343
    @siregne4343 Před 4 lety +28

    lol from the point of view of Russian or Ukrainian, you actually pronounce "Petya" wrong but soo cutely :)

  • @jakefromstatefarm1219

    What's the outer music called it's kind of calming

  • @BlazeTc1402-7
    @BlazeTc1402-7 Před 7 lety

    Can confirm germany is down with the new one now. Love how the providers say its a technical issue though.

  • @roxwize
    @roxwize Před 7 lety

    hi notification squad
    i only came here because it was danooct1

  • @Huwng1337
    @Huwng1337 Před 7 lety +3

    And now we must thanks NSA to create the tool for recently ransomware use
    (sorry if my eng suck)

    • @themumbles5808
      @themumbles5808 Před 7 lety +1

      Hưng Kềnh *And now we must thank the NSA for creating the tool for recent ransomware usage.
      You were still understandable though! :D

  • @samleen
    @samleen Před 4 lety

    and that's why you always want to have a power supply with a switch on it

  • @alloreon4338
    @alloreon4338 Před 3 lety +1

    “...so a new bootloader can take hold and encrypt your drive, *_SO LET’S RUN IT!_*

  • @olpqay
    @olpqay Před 7 lety

    Hey Dan, this one was hitting Germany over a year ago. March 2016 to be precise. In April a free decryption tool was released, here is a HowTo showing that: Aa-60SFbz0s
    But unfortunately the sites used in that video are down nowadays.
    Anyways, there have been a decryption - hope that helps ;-)

    • @olpqay
      @olpqay Před 7 lety

      Okay.. found out myself. This is petya 2.0

    • @xAffan
      @xAffan Před 6 lety

      olpqay The sites are taken down but i have a seperate decrypter.

  • @kassandrapiotrowski9650

    Just saying, I did a report on computer malware in high school a year ago and that was one of the ransomwares I covered. Very sad it only now makes headlines.

  • @volo870
    @volo870 Před 7 lety +1

    It is March 2016 version. Current virus is completely different.

  • @davoid-
    @davoid- Před 7 lety

    Now im scared to turn on my computer...

  • @SuperSmashDolls
    @SuperSmashDolls Před 7 lety

    Wait, wouldn't replacing the bootloader make the computer fail secure boot? (on modern machines) Or does this ransomware have a separate payload for that setup?

    • @xAffan
      @xAffan Před 6 lety

      Super Smash Dolls no i dont think so

  • @austinsmith6714
    @austinsmith6714 Před 4 lety

    @Danooct1 have you ever had an accidental infection?

  • @thecybercrack4561
    @thecybercrack4561 Před 4 lety

    Can we run it inside a VM which is inside another VM just to be on a safe side