Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jan 2019

How to remove PetrWrap ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

PetrWrap ransomware exploits Petya’s code and leaves its creators empty-handed

PetrWrap virus

PetrWrap virus is a modified variant of Petya ransomware which works independently from the parent program. The experts also refer to PetrWrap as an “unauthorized” follow-up of this virus because it is based on Petya’s source code but does not belong to its official Ransomware-as-a-Service [1] campaign. This means that instead of sharing the collected profit with the original virus creators, these hackers keep it all to themselves. They achieved that by replacing the original Petya’s ECDH algorithm [2] with another one, which allowed them to generate private and public keys outside the RaaS system.

The virus analysts typically refer to such exploitation tactic as “wrapping”; hence, you can see the stem of the word “wrap” in the virus title. Undoubtedly, Janus Cybercrime Solutions [3], who proclaim themselves as the main administrators of the Petya RaaS should be quite annoyed by all that. But there is virtually nothing they can do to stop this process.

Neither do the PetrWrap victims.

Once the virus infects computers, the contained files undergo a sophisticated encryption process which is almost impossible to roll back. Of course, the victims may succumb to the extortionists' demands and purchase the special decryption key. Nevertheless, that does not guarantee the criminals will surrender the data that easily.

The criminals are unpredictable and may simply vanish without issuing any decryption software whatsoever. That’s why it is best to keep away from any interaction with the criminals and remove PetrWrap from your computer immediately. Though the ransomware is a complex virus, you can still fix your PC with the help of sophisticated antivirus programs such as FortectIntego or similar.

For quite some time PetrWrap's distribution was very moderate and many may have even forgotten about the threat completely. But the creators of this threat are not planning on letting their names be forgotten.

PetrWrap virus has just hit the spotlight again after a new string of ransomware, presumably related to this or other Petya virus version started ravaging through Europe, US and other continents of the world. 

So far, 2000 PCs have been confirmed to be infected with this virus but the numbers are expected to grow exponentially. 

PetrWrap ransomware image

PetrWrap ransomware looks like a mosaic compiled from details collected from other different viruses. So, its is not only Petya that PetrWrap creators exploit. When it comes to software distribution, the virus works more like Samas ransomware — the criminals brute force their way into the victims' computers via vulnerable RDP networks [4] and then deploy the virus on the system.

PsExec tool [5] is used for this purpose. Nevertheless, it is also possible that the infiltration may be carried out in some other ways. We will elaborate more on those later. As for now, let us get back to discussing the functionalities of PetrWrap. Looking at its exterior, the hybrid ransomware does not look like it belongs to any virus family. In its ransom note, the hackers have dropped Petya’s red skull and display the ransom text white on black.

It is interesting that the virus will “sleep” for 1.5 hours before it starts the encryption and displays the mentioned note. After it is activated, it will rewrite computer's Master Boot Record to be able to run at startup. The virus does not seem to append any extensions to the encrypted files, but it sure will render their contents unreadable. So, you will also face the challenge of recovering your files after the PetrWrap removal. Check out the end of the article for experts suggestions.

Principles of ransomware attack

We have already mentioned that PetrWrap mainly brute forces its way to the computers and it is done for a reason. This virus is not a widespread infection like Osiris or Cerber but focuses on attacks targeted towards certain organizations or companies.

That’s why the hackers must remain flexible and adjust their infiltration strategies to particular situations. Nevertheless, the good old email spoofing technique may as well be exploited to infect corporate computers.

The malicious parties may try to send out emails carrying PetrWrap to the company employees and this way enter the networks. That’s why it is crucial to learn how to recognize the potentially malicious emails and avoid them.

PetrWrap removal: the safest way to do it

If you came to this part of the article, you must be determined to remove PetrWrap virus from your computer as soon as possible. So, without further ado, let us introduce the best ways to do it. Remember, PetrWrap removal will only be successful if you obtain a reliable antivirus utility and scan your hard drive with it.

You may also use the antivirus software you already own, just make sure it is legal and updated version of the program. Do not forget — ransomware will fight back and may try to prevent its removal by blocking your antivirus. You will find a workaround of this problem below.

Did this guide help?

Be the first to comment

Read in your language

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.