Ransom

Ransom.Petya.Generic removal tips

Malware Removal

The Ransom.Petya.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Petya.Generic virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine Ransom.Petya.Generic?


File Info:

crc32: 4436A533
md5: a75afc2f3043bb36dd0b6623b94bf222
name: A75AFC2F3043BB36DD0B6623B94BF222.mlw
sha1: 52ddf770ac8f7984e54cce704acfe61fa39fecc0
sha256: 7d02e77ce382507977d4dba8aa9be8f6731fb48336af6ca06c520e97fc1aa593
sha512: 2f2789342694ee23f3aa762a4ad3ff0f85cd9b4c9cb561ec0d6352836d3bbc469a159218b65cb0aa4daa4a3bdc2b93ff490a00583c404a165615fcc10733ccd5
ssdeep: 3072:bqrbwA3MZslUmPgBzczGUPWXZa6cNolW:4kdseHUP/2
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: VSSADMIN.EXE
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 5.1.2600.0
FileDescription: Command Line Interface for Microsoftxae Volume Shadow Copy Service
OriginalFilename: VSSADMIN.EXE
Translation: 0x0409 0x04b0

Ransom.Petya.Generic also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.265
CynetMalicious (score: 100)
ALYacGenPack:Trojan.Ransom.BHE
CylanceUnsafe
ZillyaTrojan.Generic.Win32.304510
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/PETYA.52a49864
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.f3043b
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGenPack:Trojan.Ransom.BHE
NANO-AntivirusTrojan.Win32.MBRlock.eyfqyb
MicroWorld-eScanGenPack:Trojan.Ransom.BHE
TencentWin32.Trojan.Crypt.Lmas
Ad-AwareGenPack:Trojan.Ransom.BHE
SophosMal/Generic-S
ComodoTrojWare.Win32.Petya.E@6yquji
BitDefenderThetaGen:NN.ZexaF.34608.hmuaausAfUci
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_PETYA.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.a75afc2f3043bb36
EmsisoftGenPack:Trojan.Ransom.BHE (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Patched.Gen
eGambitUnsafe.AI_Score_96%
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitGenPack:Trojan.Ransom.BHE
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGenPack:Trojan.Ransom.BHE
AhnLab-V3Malware/Win32.Generic.C1815245
McAfeeArtemis!A75AFC2F3043
MAXmalware (ai score=97)
VBA32Trojan.MBRlock
MalwarebytesRansom.Petya.Generic
TrendMicro-HouseCallRansom_PETYA.SM1
RisingRansom.Petya!8.48D7 (CLOUD)
FortinetW32/Generic.SM1!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HxIBEpsA

How to remove Ransom.Petya.Generic?

Ransom.Petya.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment