Ransom

Ransom.Petya removal instruction

Malware Removal

The Ransom.Petya is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Petya virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Clears web history

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Petya?


File Info:

crc32: 46CEE9B1
md5: 6f280a70aaec1236b1685c44b889bd6d
name: 6F280A70AAEC1236B1685C44B889BD6D.mlw
sha1: 89851b3a684844cefee0593bf1012e0fe81dc4c8
sha256: f22aba84a350000f234c9b62b259fc232c7dcbe98bb467dfa01f89ba916a5c56
sha512: 1d3deb7a0e4db0ca3e69e66f1513e3260c12692e3aa0f82f0b04bdaf2ba1b00ef7b242c93a5bddfa91b88b56c690dc10f6fcec746875bfee97fcc4defdd5a771
ssdeep: 3072:+9dUEfLpw3gCidSMFztbGw9Pz5DHrN+qi:+9d/w3gN/pZY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: verclsid.exe
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Extension CLSID Verification Host
OriginalFilename: verclsid.exe
Translation: 0x0409 0x04b0

Ransom.Petya also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GoldenEye.10
FireEyeGeneric.mg.6f280a70aaec1236
Qihoo-360Win32/Trojan.Ransom.9ef
ALYacGen:Variant.Ransom.GoldenEye.10
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Ransom.GoldenEye.10
K7GWTrojan ( 00500e631 )
K7AntiVirusTrojan ( 00500e631 )
CyrenW32/S-e2063586!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Petya-9763114-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.AD.esxwko
AegisLabTrojan.Win32.Generic.j!c
TencentMalware.Win32.Gencirc.10b25df9
Ad-AwareGen:Variant.Ransom.GoldenEye.10
TACHYONRansom/W32.GoldenEye.150528
EmsisoftGen:Variant.Ransom.GoldenEye.10 (B)
ComodoTrojWare.Win32.Skeeyah.AE@7gam2b
F-SecureHeuristic.HEUR/AGEN.1127675
DrWebTrojan.Encoder.14758
ZillyaTrojan.DiskcoderGen.Win32.1
TrendMicroRansom_PETYA.SM2
McAfee-GW-EditionRansomware-GGU!6F280A70AAEC
SophosMal/Generic-R + ATK/Shellter-G
AviraHEUR/AGEN.1127675
Antiy-AVLTrojan[Ransom]/Win32.Petya.a
ArcabitTrojan.Ransom.GoldenEye.10
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.GoldenEye.10
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gen
Acronissuspicious
McAfeeRansomware-GGU!6F280A70AAEC
MAXmalware (ai score=82)
VBA32Trojan.Encoder
MalwarebytesRansom.Petya
PandaTrj/Genetic.gen
ESET-NOD32Win32/Diskcoder.Petya.E
TrendMicro-HouseCallRansom_PETYA.SM2
RisingRansom.Diskcoder!1.AE41 (CLOUD)
YandexTrojan.Agent!VPK4gKsbzm0
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/Petya.E!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34590.jq0@aKWADJji
AVGWin32:Malware-gen
Cybereasonmalicious.0aaec1
Paloaltogeneric.ml

How to remove Ransom.Petya?

Ransom.Petya removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment