Malware

Win32/Diskcoder.Petya.G information

Malware Removal

The Win32/Diskcoder.Petya.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Diskcoder.Petya.G virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/Diskcoder.Petya.G?


File Info:

name: 82CE3E26A74270262AD0.mlw
path: /opt/CAPEv2/storage/binaries/444f062c376a1c1d58ea62b664fddcb0a84bf8eb6f1bca7b75286c16119d3dc3
crc32: BD60906D
md5: 82ce3e26a74270262ad08fd1ea02a5f5
sha1: 058ab4e43d90c23f639882629cd660466924e3f9
sha256: 444f062c376a1c1d58ea62b664fddcb0a84bf8eb6f1bca7b75286c16119d3dc3
sha512: 4b367b8efb197a417060f36bd9c0782b18f34dfffb4e77cda91227cfd5b4d50590045c956e1aa5247fe1fba0f4cdb2a59536e1c53550f276cacd94e334e6ecac
ssdeep: 1536:/BMT/qQfQPUEfLa51nmoIUxXIMUg3g0ztC2x8qwXAKjGV4FaqeHrN+0tG:Z9dUEfLafdSMFztbGwrDHrN+8G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125E37D14F5A0D0B2DBCA2D7618B8CB7DCE3A68254F646097779403FE5FB0EE09266139
sha3_384: 65a3b7e14e4c8a4306dfe1a3a72aa231e13bc2d6c9db84ed9df7686e8ccfd71a36fc6f5e5cffe5a8bdc5ad46f3b8c351
ep_bytes: e83f8f0000e9a4feffff8bff558bec8b
timestamp: 2012-06-09 21:40:33

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Offers the user a choice
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
InternalName: choice.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: choice.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Win32/Diskcoder.Petya.G also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.107024
FireEyeGeneric.mg.82ce3e26a7427026
CAT-QuickHealRansom.Genasom.S239266
CylanceUnsafe
VIPREGen:Variant.Midie.107024
SangforRansom.Win32.Petya_4.se2
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.6a7427
VirITTrojan.Win32.Encoder.VVQ
CyrenW32/S-e2063586!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Diskcoder.Petya.G
APEXMalicious
ClamAVWin.Ransomware.Petya-9763114-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Midie.107024
NANO-AntivirusTrojan.Win32.AD.esxwko
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b19a98
Ad-AwareGen:Variant.Midie.107024
SophosML/PE-A + ATK/Shellter-AC
ComodoTrojWare.Win32.Skeeyah.AE@7gam2b
DrWebTrojan.Encoder.14758
ZillyaTrojan.DiskcoderGen.Win32.1
TrendMicroRansom_PETYA.SM2
EmsisoftGen:Variant.Midie.107024 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Midie.107024
AviraHEUR/AGEN.1242366
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASBOL.C5E2
ArcabitTrojan.Midie.D1A210
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/Petya.C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gen
VBA32Malware-Cryptor.General.3
ALYacGen:Variant.Midie.107024
MalwarebytesRansom.Petya
TrendMicro-HouseCallRansom_PETYA.SM2
RisingTrojan.Generic@AI.100 (RDMK:XeW0QdAegk0mGCYI1tRBxg)
IkarusTrojan.Win32.Diskcoder
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Petya.E!tr
BitDefenderThetaGen:NN.ZexaF.34786.jq0@aKPcuPoi
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Diskcoder.Petya.G?

Win32/Diskcoder.Petya.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment