Back to Error Database
PETYA-NOTPETYA-WIPER

Petya / NotPetya Ransomware-Wiper

CRITICAL malware ID: VIR-009

What is PETYA-NOTPETYA-WIPER?

Petya / NotPetya Ransomware-Wiper is a critical-severity malware/security issue. Petya/NotPetya is a highly destructive wiper malware masquerading as ransomware. It targets Windows computers, encrypting the Master File Table (MFT) and overwriting the Master Boot Record (MBR) to completely prevent the operating system from booting. It's most often caused by SMB vulnerabilities (EternalBlue/EternalRomance) on unpatched machines, compromised administrative credentials harvested via Mimikatz-like methods and malicious updates in accounting software supply chains. The steps below are ordered to resolve this efficiently.

Common Causes

Step-by-Step Fix Guide

Commands & Diagnostics

bootrec /fixmbr
powershell.exe Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol

Frequently Asked Questions

Still Need Help?

Search our full database of 535+ documented PC errors for more solutions and step-by-step repair guides.

Search Error Database