Malware

About “Win32/Diskcoder.Petya.A” infection

Malware Removal

The Win32/Diskcoder.Petya.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Diskcoder.Petya.A virus can do?

  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Diskcoder.Petya.A?


File Info:

crc32: CE79C60D
md5: e9fdc21bd273444925a4512166188e5b
name: tunamor.exe
sha1: e398138686eedcd8ef9de5342025f7118e120cdf
sha256: 78972cdde1a038f249b481ea2c4b172cc258aa294440333e9c46dcb3fbed5815
sha512: 64989534f56fcd70f3ff08bb47a331d5624fc1e3b387420a885d6f32a537e05182de8c5890612cde03fdd312ad101955674d7455c84b900bf7eed97b402a2b08
ssdeep: 768:Uv3mq1oJQpwvZlXhVkcDsaoi9P9TJKvaoStYARRQwfwiIySf4BtIl82+hE8x:YmqMQoXhVN4aooJhDCSeyxel82WNx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Diskcoder.Petya.A also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Heur.Ransom.RTH.1
FireEyeGeneric.mg.e9fdc21bd2734449
McAfeeGenericR-QIP!E9FDC21BD273
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004e1c831 )
AlibabaRansom:Win32/Mbrint.181211
K7GWTrojan ( 004e1c831 )
Cybereasonmalicious.bd2734
CyrenW32/Injector.PEQY-5235
SymantecRansom.Petya
ESET-NOD32Win32/Diskcoder.Petya.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Petya-6992434-0
GDataGen:Heur.Ransom.RTH.1
KasperskyTrojan-Ransom.Win32.Petr.aqv
BitDefenderGen:Heur.Ransom.RTH.1
NANO-AntivirusTrojan.Win32.Diskcoder.fhbqwx
ViRobotTrojan.Win32.Z.Petya.73216.C
SUPERAntiSpywareTrojan.Agent/Gen-DiskCoder
AvastMBR:Ransom-C [Trj]
RisingRansom.MBBlocker!8.31B7 (CLOUD)
Ad-AwareGen:Heur.Ransom.RTH.1
TACHYONTrojan/W32.DP-DiskWriter.73216
SophosMal/Generic-S
ComodoMalware@#5d6gj25p7ak9
F-SecureHeuristic.HEUR/AGEN.1117117
DrWebTrojan.Siggen7.57150
ZillyaTrojan.Petr.Win32.114
TrendMicroRansom_Petya.R002C0CC820
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Ransom.RTH.1 (B)
IkarusTrojan-Ransom.Petrwrap
F-ProtW32/Injector.HZO
JiangminAdWare.Generic.svgg
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1117117
Antiy-AVLTrojan/Win32.DiskWriter
Endgamemalicious (high confidence)
ArcabitTrojan.Ransom.RTH.1
AegisLabTrojan.Win32.Petr.tquH
ZoneAlarmTrojan-Ransom.Win32.Petr.aqv
MicrosoftRansom:Win32/Petya.A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2672345
ALYacGen:Heur.Ransom.RTH.1
MAXmalware (ai score=81)
VBA32TScope.Trojan.Delf
TrendMicro-HouseCallRansom_Petya.R002C0CC820
TencentMalware.Win32.Gencirc.10b9a637
YandexTrojan.Agent!k6GxQdsZptA
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Petya.A!tr.ransom
BitDefenderThetaAI:Packer.FD0CED3F19
AVGMBR:Ransom-C [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.Ransom.261

How to remove Win32/Diskcoder.Petya.A?

Win32/Diskcoder.Petya.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment