" ...">

PETYA malware. Recovery is possible


27 – Petya, . , , , . BiZone . , .


, ( ).

:


Petya :
wevtutil cl Setup & wevtutil cl System & wevtutil cl Security & wevtutil cl Application & fsutil usn deletejournal /D %c:

, , , .

:

1. $MFT (NotPetya)
MBR ( MBR 34 (xor 0x07)). ( “schtasks” “at”) CHKDSK. $MFT Salsa20 ( c Petya). , , . .

:

2. (Misha)
MBR, . :

3ds, 7z, accdb, ai, asp, aspx, avhd, back, bak, c, cfg, conf, cpp, cs, ctl, dbf, disk, djvu, doc, docx, dwg, eml, fdb, gz, h, hdd, kdbx, mail, mdb, msg, nrg, ora, ost, ova, ovf, pdf, php, pmf, ppt, pptx, pst, pvi, py, pyc, rar, rtf, sln, sql, tar, vbox, vbs, vcb, vdi, vfd, vmc, vmdk, vmsd, vmx, vsdx, vsv, work, xls, xlsx, xvd, zip. 

, , , Volume Shadow Copy, Restore points, File History.

, . , .

?


NotPetya , , . :



(MFT), . MFT , :



, , (Carving) . MFT . hiberfil.sys, MFTmirr .. , MFT .


«PSEXEC» Windows :

«C:\Windows\perfc.dat»
«C:\Windows\dllhost.dat»


  1. MS17-10 Windows
  2. SMB1

«PSEXEC.EXE» , , , , WMI.

, PsExec WMI. “C:\Windows\perfc”.

UPD: NotPetya Misha , Misha MBR. Misha .

GPT MBR, NotPetya , . , NTFS (R-Studio ).

C perfc , Petya «perfc.dat». , , .


Source: https://habr.com/ru/post/J331854/


All Articles