What is PETYA-NOTPETYA-WIPER?
Petya / NotPetya Ransomware-Wiper is a critical-severity malware/security issue. Petya/NotPetya is a highly destructive wiper malware masquerading as ransomware. It targets Windows computers, encrypting the Master File Table (MFT) and overwriting the Master Boot Record (MBR) to completely prevent the operating system from booting. It's most often caused by SMB vulnerabilities (EternalBlue/EternalRomance) on unpatched machines, compromised administrative credentials harvested via Mimikatz-like methods and malicious updates in accounting software supply chains. The steps below are ordered to resolve this efficiently.
Common Causes
- SMB vulnerabilities (EternalBlue/EternalRomance) on unpatched machines
- Compromised administrative credentials harvested via Mimikatz-like methods
- Malicious updates in accounting software supply chains
Step-by-Step Fix Guide
-
1
Install MS17-010 patch and keep system updated
"Install MS17-010 patch and keep system updated" is the next step worth ruling out for PETYA-NOTPETYA-WIPER.
-
2
Disable SMBv1 and limit administrative share access
"Disable SMBv1 and limit administrative share access" is worth trying when compromised administrative credentials harvested via Mimikatz-like methods turns out to be the culprit.
-
3
Use boot sector write protections in BIOS/UEFI
"Use boot sector write protections in BIOS/UEFI" handles an edge case some users report with PETYA-NOTPETYA-WIPER.
-
4
Perform clean OS installation if MBR/MFT is completely destroyed
"Perform clean OS installation if MBR/MFT is completely destroyed" handles an edge case some users report with PETYA-NOTPETYA-WIPER.
Commands & Diagnostics
bootrec /fixmbr
powershell.exe Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol
Frequently Asked Questions
In most cases, SMB vulnerabilities (EternalBlue/EternalRomance) on unpatched machines is behind PETYA-NOTPETYA-WIPER. Compromised administrative credentials harvested via Mimikatz-like methods and malicious updates in accounting software supply chains can trigger it too.
The fastest fix is "Install MS17-010 patch and keep system updated". Only move on to the later steps if PETYA-NOTPETYA-WIPER keeps coming back.
Treat PETYA-NOTPETYA-WIPER as urgent — it's flagged critical severity, meaning repeated occurrences risk data loss or hardware damage.
Usually. PETYA-NOTPETYA-WIPER is fixable with the steps above; a full Windows reinstall is rarely necessary unless everything else has failed.
Still Need Help?
Search our full database of 535+ documented PC errors for more solutions and step-by-step repair guides.
Search Error Database