Ransom

Ransom:Win64/Hive.E removal

Malware Removal

The Ransom:Win64/Hive.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/Hive.E virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ransom:Win64/Hive.E?


File Info:

name: 0AD575DD81BCFEA05481.mlw
path: /opt/CAPEv2/storage/binaries/5b55acb91c5760d26c548346d5b94595941f76d8665195bf46bfd71f50d4fcb9
crc32: 787973D4
md5: 0ad575dd81bcfea05481dd47f3a9b054
sha1: 3caafdf6e4f1ac1bdf5784ba6e9977681845fb5e
sha256: 5b55acb91c5760d26c548346d5b94595941f76d8665195bf46bfd71f50d4fcb9
sha512: 8fa6c754ba3dc745105afbd794de925e4a52e31e281b1cf77440d637d8c964d12a718c292c396e7f5f9338efc704ab600c9d0ed2202f32ac7f0cf8fbe70c88eb
ssdeep: 12288:Ekp7gILzBt94Q2dKdMTQqcWvQG67RhL4WgXFh:7p7JLa7TQqcWvQt7Ruj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15FE47D06FAA783F9C45B1C70109FA23AE6711A0DC13A5FA7EFF66D70B25E701B50590A
sha3_384: 097575139dd487ef651f0b507ef98006da191c1710ac7ea9f06cd060f21dc0f0653056d62a8876df8813ab339f7407ae
ep_bytes: c70570514a0001000000e9b1fcffff90
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ransom:Win64/Hive.E also known as:

LionicTrojan.Win32.Generic.j!c
Elasticmalicious (high confidence)
FireEyeGen:Variant.Zusy.424862
McAfeeRDN/Ransom
MalwarebytesMalware.AI.326103902
SangforRansom.Win32.Hive.Vhbs
K7AntiVirusTrojan ( 005926751 )
BitDefenderGen:Variant.Zusy.424862
K7GWTrojan ( 005926751 )
CyrenW32/ABRisk.LFGH-5511
ESET-NOD32a variant of Win32/Filecoder.Hive_AGen.A
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Generic
AlibabaRansom:Win32/Hive_AGen.20b648ce
MicroWorld-eScanGen:Variant.Zusy.424862
RisingRansom.Hive!8.12EEE (CLOUD)
Ad-AwareGen:Variant.Zusy.424862
ZillyaTrojan.Filecoder.Win32.24381
TrendMicroRansom.Win32.HIVE.SMYXCDA
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
EmsisoftGen:Variant.Zusy.424862 (B)
IkarusTrojan-Ransom.Hive
GDataGen:Variant.Zusy.424862
JiangminTrojan.Generic.hhvqc
AviraHEUR/AGEN.1250038
ArcabitTrojan.Zusy.D67B9E
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:Win64/Hive.E
AhnLab-V3Ransomware/Win.Ransom.R492086
VBA32BScope.TrojanRansom.Generic
ALYacTrojan.Ransom.Filecoder
MAXmalware (ai score=80)
CylanceUnsafe
PandaTrj/GdSda.A
TencentWin32.Trojan.Filecoder.Isr
MaxSecureTrojan.Malware.10307848.susgen
FortinetW32/Filecoder_Hive_AGen.A!tr
BitDefenderThetaGen:NN.ZexaF.34742.PKX@aCSWamj
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win64/Hive.E?

Ransom:Win64/Hive.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment