Petya ransomware overwrites MBRs, locking users out of their computers

It’s hard enough for non-technical users to deal with ransomware infections: understanding public-key cryptography, connecting to the Tor anonymity network and paying with Bitcoin cryptocurrency. A new malicious program now makes it even more difficult by completely locking victims out of their computers.

The new Petya ransomware overwrites the master boot record (MBR) of the affected PCs, leaving their operating systems in an unbootable state, researchers from antivirus firm Trend Micro said in a blog post.

The MBR is the code stored in the first sectors of a hard disk drive. It contains information about the disk’s partitions and launches the operating system’s boot loader. Without a proper MBR, the computer doesn’t know which partitions contain an OS and how to start it.

To read this article in full or to leave a comment, please click here

Read more: Petya ransomware overwrites MBRs, locking users out of their computers

Story added 28. March 2016, content source with full text you can find at link above.