Ransom Trojan

Trojan-Ransom.Win32.Petr.aqv removal guide

Malware Removal

The Trojan-Ransom.Win32.Petr.aqv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Petr.aqv virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Unusual version info supplied for binary

How to determine Trojan-Ransom.Win32.Petr.aqv?


File Info:

crc32: 2D7B3758
md5: 5d7716156b6dd6add16263e315386015
name: 5D7716156B6DD6ADD16263E315386015.mlw
sha1: 4087a070d300c799b80e50237f80980eeed16ff6
sha256: 8119d22a27853b88b72d87a151b1c8d4cef9abee319ed1424fa50a4012ed41f4
sha512: 816a074754b0477d4ee9e26db09c88dc5d8ba1843300a51491ad4d05ecf8ffa9e4de3cbb430324b10bcc2d81724885f34975c8a2b7c7cadb0cde40b74c0b1a6a
ssdeep: 3072:pzW+DiC9iLo+GnHT559UU7URLvrsH9UepC:kKwLo7zeU7Utcb
type: PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 8.00.7600.16385 (win7_rtm.090713-1255)
CompanyName: KIKES
ProductName: Windowsxae Internet Explorer
ProductVersion: 8.00.7600.16385
FileDescription: This is not policies
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Petr.aqv also known as:

K7AntiVirusTrojan ( 004e19001 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.57150
CynetMalicious (score: 90)
ALYacTrojan.GenericKD.31511142
CylanceUnsafe
ZillyaTrojan.Petr.Win32.57
SangforRansom.Win32.Petya.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Petya.201c4358
K7GWTrojan ( 004e19001 )
Cybereasonmalicious.56b6dd
CyrenW32/Injector.PEQY-5235
ESET-NOD32Win32/Diskcoder.Petya.A
APEXMalicious
AvastMBR:Ransom-C [Trj]
ClamAVWin.Ransomware.Petya-6992434-0
KasperskyTrojan-Ransom.Win32.Petr.aqv
BitDefenderTrojan.GenericKD.31511142
NANO-AntivirusTrojan.Win32.Diskcoder.fhbqwx
MicroWorld-eScanTrojan.GenericKD.31511142
TencentMalware.Win32.Gencirc.11bb2847
Ad-AwareTrojan.GenericKD.31511142
SophosMal/Generic-S
ComodoMalware@#1f9yoeyc2u5at
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.ch
FireEyeGeneric.mg.5d7716156b6dd6ad
EmsisoftTrojan.GenericKD.31511142 (B)
JiangminAdWare.Generic.svgg
AviraHEUR/AGEN.1117117
MicrosoftRansom:Win32/Petya.A
ArcabitTrojan.Generic.D1E0D266
AegisLabTrojan.Win32.Petr.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.31511142
AhnLab-V3Malware/Win32.Generic.C2889012
McAfeeArtemis!5D7716156B6D
MAXmalware (ai score=99)
VBA32TrojanRansom.Petr
MalwarebytesRansom.Petya
PandaTrj/CI.A
RisingRansom.MBBlocker!8.31B7 (CLOUD)
IkarusTrojan.Win32.Diskcoder
FortinetW32/Petya.A!tr.ransom
AVGMBR:Ransom-C [Trj]
Qihoo-360Win32/Ransom.Generic.HwYDEpsA

How to remove Trojan-Ransom.Win32.Petr.aqv?

Trojan-Ransom.Win32.Petr.aqv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment