Published Mar 28, 2016 | Updated Sep 15, 2017

Ransom:Win32/Petya

Severe |Detected with Windows Defender Antivirus

Aliases: No associated aliases

Summary

Windows Defender Antivirus  detects and removes this threat.

This can stop you from using your PC or accessing your data. It might ask you to pay money to a malicious hacker.ransomware

This ransomware has worm-like capabilities that allows it spread across infected networks. It's spreading capabilities include:

For more information on this threat, which caused an outbreak on Jun 27, 2017, read these blog posts on the Windows Security blog:

Our  has more information on this type of threat.ransomware page

  • Lateral movement using credential theft and impersonation
  • Lateral movement using the EternalBlue and EternalRomance exploits

There is no one-size-fits-all response if you have been victimized by ransomware. There is no guarantee that paying the ransom will give you access to your files. If you've already paid, see  for help on what to do now.ransomware page

Use the following free  software to detect and remove this threat:Microsoft

You should also run a full scan. A full scan might find hidden malware.

To restore your PC, you might need to . See our  for more help.download and run Windows Defender Offlineadvanced troubleshooting page

You can also visit our  or search the for more help.advanced troubleshooting pageMicrosoft virus and malware community

If you’re using , see our .Windows XPWindows XP end of support page

Use cloud protection to help guard against the latest malware threats. It’s turned on by default for Microsoft Security Essentials and Windows Defender Antivirus for Windows 10. 

Go to and make sure that your settings is turned .Settings > Update & security > Windows Defender > Windows Defender Security Center > Virus & threat protectionCloud-based ProtectionOn

Run antivirus or antimalware software
Advanced troubleshooting
Get more help
Use cloud protection
Follow us