Ransom

Should I remove “Ransom:Win64/Gocoder.P!dha”?

Malware Removal

The Ransom:Win64/Gocoder.P!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/Gocoder.P!dha virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Ransom:Win64/Gocoder.P!dha?


File Info:

crc32: C1BF3A91
md5: bbb3926056bf27f2b9a7f63ba89b6af6
name: BBB3926056BF27F2B9A7F63BA89B6AF6.mlw
sha1: 78cc138e945a8f962c5901d521962a2f8f346c2d
sha256: e9734b0de45aacf78c47261faac073255852595f5756d4992594f3470d520021
sha512: beb6824577313ddbcb98e8371080fd8f7126f6d1b0f05cd50b05071b4c41c7fbc6c47df4aa2d464e0fd70c06a118bd28acd26ebaf533b5118414cda1fdd97b00
ssdeep: 24576:tIx1badkMpx3eWuV67IO36DRjyGVqK/IuiaCGIihuHMo:tIfbGatAqDdVF/IuB0rM
type: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win64/Gocoder.P!dha also known as:

MicroWorld-eScanTrojan.GenericKD.41925627
Qihoo-360Win64/Ransom.Filecoder.HgEASOoA
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.FileCoder.ocnbv
K7AntiVirusTrojan ( 00559c581 )
BitDefenderTrojan.GenericKD.41925627
K7GWTrojan ( 00559c581 )
Cybereasonmalicious.056bf2
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Filecoder.AM
APEXMalicious
AvastWin64:Trojan-gen
KasperskyHEUR:Trojan.Win32.DelShad.vho
AlibabaRansom:Win64/Gocoder.1b72795f
NANO-AntivirusTrojan.Win64.DelShad.gdyhou
TencentWin32.Trojan.Delshad.Pitn
Ad-AwareTrojan.GenericKD.41925627
EmsisoftTrojan.GenericKD.41925627 (B)
ComodoMalware@#1oor94a0b9e75
F-SecureTrojan.TR/FileCoder.ocnbv
DrWebTrojan.Encoder.29809
McAfee-GW-EditionBehavesLike.Win64.Trickbot.tc
FireEyeGeneric.mg.bbb3926056bf27f2
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.DelShad.ih
AviraTR/FileCoder.ocnbv
Antiy-AVLTrojan/Win32.DelShad
MicrosoftRansom:Win64/Gocoder.P!dha
ArcabitTrojan.Generic.D27FBBFB
AhnLab-V3Malware/Win64.RL_Generic.R300784
ZoneAlarmHEUR:Trojan.Win32.DelShad.vho
GDataTrojan.GenericKD.41925627
CynetMalicious (score: 85)
McAfeeArtemis!BBB3926056BF
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
YandexTrojan.GenAsa!2P9RdDdPMmU
FortinetW32/DelShad.AM!tr
AVGWin64:Trojan-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Ransom:Win64/Gocoder.P!dha?

Ransom:Win64/Gocoder.P!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment