Ransom

About “Ransom:Win64/Gocoder.A!MSR” infection

Malware Removal

The Ransom:Win64/Gocoder.A!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/Gocoder.A!MSR virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win64/Gocoder.A!MSR?


File Info:

crc32: 37414B02
md5: 32de66a467db22cf0f5b65d1a9f4e19c
name: 32DE66A467DB22CF0F5B65D1A9F4E19C.mlw
sha1: cdb5c200cba7da3f6e80e868ef7df380ac1259c2
sha256: 36a4311ef332b0b5db62f8fcabf004fdcfbbde62f791839a8be0314604d814c4
sha512: af200cc334c05e5fe0df1d4c76b5ce469d034c0d62288d207b6bb6562579e07dc4510e4bfc4b726cf1a9f82ae8cb69c4630e981f23d05fb85e3be842a34244f1
ssdeep: 49152:fgZNPqLGVfMmq1d1MRGM8Fvg9fR5HMXF9W9HrAbluBUMNk+cqG2UtBpStPvC/9f:fgXsMfql+9G9+B+tBpEPvCF
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win64/Gocoder.A!MSR also known as:

K7AntiVirusTrojan ( 004bcce41 )
DrWebTrojan.Encoder.29918
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Snatch
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.10793
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Snatch.7fff4cc4
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.0cba7d
TrendMicroRansom.Win32.SNATCH.B
SymantecRansom.Snatch
ESET-NOD32a variant of Win32/Filecoder.NYH
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32704991
KasperskyHEUR:Trojan-Ransom.Win32.Snatch.vho
BitDefenderTrojan.GenericKD.32704991
NANO-AntivirusTrojan.Win32.Encoder.ggqwzr
MicroWorld-eScanTrojan.GenericKD.32704991
TencentWin32.Trojan.Snatch.Lkoc
Ad-AwareTrojan.GenericKD.32704991
SophosTroj/Ransom-FSV
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.32de66a467db22cf
EmsisoftTrojan.GenericKD.32704991 (B)
SentinelOneDFI – Malicious PE
Endgamemalicious (high confidence)
WebrootW32.Ransom.Snatch
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Ransom]/Win32.Snatch
MicrosoftRansom:Win64/Gocoder.A!MSR
JiangminTrojan.Snatch.c
ArcabitTrojan.Generic.D1F309DF
AegisLabTrojan.Win32.Snatch.j!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Snatch.vho
AhnLab-V3Malware/Win32.Generic.C3561635
McAfeeRansom-Snatch!32DE66A467DB
MAXmalware (ai score=100)
VBA32TrojanRansom.Snatch
MalwarebytesRansom.Snatch
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.SNATCH.B
RisingRansom.Snatch!8.113EE (CLOUD)
YandexTrojan.Snatch!zuUE7ZrbB+k
IkarusTrojan-Ransom.Snatch
MaxSecureTrojan.Malware.74693890.susgen
FortinetW32/Snatch.C!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM19.1.2937.Malware.Gen

How to remove Ransom:Win64/Gocoder.A!MSR?

Ransom:Win64/Gocoder.A!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment