Ransom

About “Ransom:Win32/Petya” infection

Malware Removal

The Ransom:Win32/Petya is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Petya virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Likely installs a bootkit via raw harddisk modifications
  • Attempts to restart the guest VM
  • Mimics the file times of a Windows system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Petya?


File Info:

crc32: CAA6FE0B
md5: 08828daf9a027e97fee2421ac6cbc868
name: 08828DAF9A027E97FEE2421AC6CBC868.mlw
sha1: ad1b006e99b9faded1a2dd4ec98cd3818cf245e3
sha256: 4ee2ae805c31ec4f11f3f6ecf56e9c6e2f59dcd517a5a73210b5e5015f63beea
sha512: 5c71865ff0fafb6a6cb51337f448a9aae70221e02d1dd8b1187bb3ed18e5152a2c2c3f9a32232a0080110277281c0917b072d438978e79a7c14217db412db734
ssdeep: 3072:HPfQjrk0CbHwg9YUrxtMwbazLuxhR49M7hcx8lNgOxkewSoM+nOJnJFCVw+P:vInk0iwgp8JLY3HK6keVFCVV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Petya also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25194
ClamAVWin.Ransomware.Petya-7088646-0
ALYacTrojan.Ransom.GoldenEye
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004ffd581 )
BitDefenderGen:Variant.Zusy.214023
K7GWTrojan ( 004ffd581 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Zusy.D34407
BitDefenderThetaGen:NN.ZexaE.34590.wqW@ayq7Y3pi
CyrenW32/Agent.AQL.gen!Eldorado
SymantecRansom.Goldeneye
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Petya.6fa090a7
NANO-AntivirusTrojan.Win32.Petr.eyadkt
MicroWorld-eScanGen:Variant.Zusy.214023
RisingRansom.Petr!8.4667 (CLOUD)
Ad-AwareGen:Variant.Zusy.214023
SophosTroj/Petya-AV
F-SecureTrojan.TR/Crypt.XPACK.uwryh
TrendMicroRansom_GOLDENEYE.BYX
McAfee-GW-EditionBehavesLike.Win32.Injector.fm
FireEyeGeneric.mg.08828daf9a027e97
EmsisoftGen:Variant.Zusy.214023 (B)
IkarusTrojan.Win32.Diskcoder
JiangminTrojan.Petr.f
AviraTR/Crypt.XPACK.uwryh
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Recam
MicrosoftRansom:Win32/Petya
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.214023
AhnLab-V3Trojan/Win32.Petr.C1701533
Acronissuspicious
McAfeeRDN/Ransom.bo
TACHYONRansom/W32.Petr.368640
VBA32BScope.Trojan.MTA
MalwarebytesMalware.AI.4210169662
PandaTrj/Genetic.gen
ESET-NOD32Win32/Diskcoder.Petya.D
TrendMicro-HouseCallRansom_GOLDENEYE.BYX
TencentMalware.Win32.Gencirc.10b3e60d
YandexTrojan.Petr!zA93Wp6e1l0
FortinetW32/Petr.MA!tr
WebrootTrojan.Dropper.Gen
AVGWin32:Trojan-gen
Cybereasonmalicious.f9a027
AvastWin32:Trojan-gen
Qihoo-360Win32/Ransom.Generic.HwoCJT8A

How to remove Ransom:Win32/Petya?

Ransom:Win32/Petya removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment