Ransom

Ransom:Win64/GoHive.PAA!MTB removal instruction

Malware Removal

The Ransom:Win64/GoHive.PAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/GoHive.PAA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Ransom:Win64/GoHive.PAA!MTB?


File Info:

crc32: 7BF1744A
md5: 504bd1695de326bc533fde29b8a69319
name: 504BD1695DE326BC533FDE29B8A69319.mlw
sha1: 67f0c8d81aefcfc5943b31d695972194ac15e9f2
sha256: a0b4e3d7e4cd20d25ad2f92be954b95eea44f8f1944118a3194295c5677db749
sha512: 18c5b28bafb13edf47f6a2b803d9d9a914945f037b266a765f2a324842c5ef04ebda27eba31851d2d63e00779a42900e0edfe4ad5bd817eb4f43fa4d4e3a4767
ssdeep: 24576:lafTGwLNdRk4RBtr/ioF4/I+CMx3cMt3/4KFG8Qz4YwY:IT7dRFr/ioFjicMtvV4z
type: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win64/GoHive.PAA!MTB also known as:

K7AntiVirusTrojan ( 0057f6901 )
LionicTrojan.Win64.Agent.j!c
CylanceUnsafe
SangforTrojan.Win32.DelShad.gmm
K7GWTrojan ( 0057f6901 )
Cybereasonmalicious.81aefc
CyrenW64/Filecoder.BL.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of WinGo/Filecoder.V
APEXMalicious
AvastWin64:Malware-gen
KasperskyTrojan.Win32.DelShad.gmm
MicroWorld-eScanTrojan.GenericKD.46665489
McAfee-GW-EditionBehavesLike.Win64.Gravity.cc
FireEyeTrojan.GenericKD.46665489
Antiy-AVLTrojan/Generic.ASBOL.C689
KingsoftWin32.Troj.DelShad.g.(kcloud)
MicrosoftRansom:Win64/GoHive.PAA!MTB
GDataTrojan.GenericKD.46665489
McAfeeArtemis!504BD1695DE3
TrendMicro-HouseCallTROJ_GEN.R002H0DGM21
IkarusTrojan-Ransom.Hive
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/DelShad.GMM!tr
AVGWin64:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgEASY4A

How to remove Ransom:Win64/GoHive.PAA!MTB?

Ransom:Win64/GoHive.PAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment