Ransom Trojan

GenPack:Trojan.Ransom.Petya.C removal guide

Malware Removal

The GenPack:Trojan.Ransom.Petya.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.Ransom.Petya.C virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs

How to determine GenPack:Trojan.Ransom.Petya.C?


File Info:

crc32: B3B6FBF0
md5: f9e6654310f3632e4c3ebd05a274fe1a
name: F9E6654310F3632E4C3EBD05A274FE1A.mlw
sha1: c97c79d3385acac86fb6bd42b7e0f295d24d54cb
sha256: 94205af590f131bdb662f1f873a2f1addcfe4c182a61bc33b0952c5919c180ce
sha512: 4553080c0ee8fc4465d253d79a69c6a87f750342735e6cf9bee32fffd5ab59e58e68fddad77921ec33db4dc00054dfc7a92a2698fcce0c96b558b6a7394f724e
ssdeep: 3072:DXPK/9ZBV6jM8T/zS1p9LkDNuzDvHX3ip:AclQ9qYDvHS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

GenPack:Trojan.Ransom.Petya.C also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004e19001 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Ransom.369
CynetMalicious (score: 100)
ALYacGenPack:Trojan.Ransom.Petya.C
CylanceUnsafe
ZillyaTrojan.Diskcoder.Win32.16
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Petya.5fad4138
K7GWTrojan ( 004e19001 )
Cybereasonmalicious.310f36
SymantecTrojan.Gen
ESET-NOD32Win32/Diskcoder.Petya.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGenPack:Trojan.Ransom.Petya.C
NANO-AntivirusTrojan.Win32.MBRlock.ejfwaa
MicroWorld-eScanGenPack:Trojan.Ransom.Petya.C
TencentWin32.Trojan.Generic.Egxy
Ad-AwareGenPack:Trojan.Ransom.Petya.C
SophosMal/Generic-S
ComodoMalware@#1s4iupygzjexy
BitDefenderThetaGen:NN.ZexaF.34142.imW@aSPDCCgi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_PETYA.F116L5
McAfee-GW-EditionBehavesLike.Win32.Pinkslipbot.cc
FireEyeGeneric.mg.f9e6654310f3632e
EmsisoftGenPack:Trojan.Ransom.Petya.C (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Petya.wpzsr
MicrosoftRansom:Win32/Petya.A
ArcabitGenPack:Trojan.Ransom.Petya.C
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGenPack:Trojan.Ransom.Petya.C
AhnLab-V3Trojan/Win32.RL_Petr.R285840
McAfeeArtemis!F9E6654310F3
MAXmalware (ai score=100)
VBA32Trojan.Ransom
PandaTrj/CI.A
TrendMicro-HouseCallRansom_PETYA.F116L5
YandexTrojan.GenAsa!fc6RKnPZNZI
IkarusTrojan.Win32.Diskcoder
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Petya.EOB!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove GenPack:Trojan.Ransom.Petya.C?

GenPack:Trojan.Ransom.Petya.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment