Malware

BAT/Filecoder.DN removal instruction

Malware Removal

The BAT/Filecoder.DN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BAT/Filecoder.DN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine BAT/Filecoder.DN?


File Info:

name: 0C7FDD9DCD109C742FEE.mlw
path: /opt/CAPEv2/storage/binaries/9a740b7766ff54cb597d7e2609897d492e98011332f01ee86537f0615ccd18f8
crc32: EB8E5790
md5: 0c7fdd9dcd109c742fee67866125759c
sha1: 821fb89e6a26b08d41f8f960cf30d4ef2dffc1ac
sha256: 9a740b7766ff54cb597d7e2609897d492e98011332f01ee86537f0615ccd18f8
sha512: d79a65c419519414d73e2192bb0a4709a8a6eb6132b1d11aecaa0e54d3d0a81a8ff50637e5732a5929c60b98eb133a89d0c9c69e16577d4f758260b4950ebf6b
ssdeep: 3072:0q6+ouCpk2mpcWJ0r+QNTBfw+2BdZ6RL5mkkvUskk/9TEwEF:0ldk1cWQRNTB4+udQLLkvUskk/BcF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138F37D41F3D142F7D8B1073104A7A61BA336BF28B7605ADB934C3A425E73BD259392E9
sha3_384: 4af03fafa9d88e3c77930402e2754bc85734df18dab3d000e45994782a9550c309a2b14dbed601462f4c897cda56ee10
ep_bytes: 68ac00000068000000006810804100e8
timestamp: 2019-07-30 08:52:50

Version Info:

0: [No Data]

BAT/Filecoder.DN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Tiny.trFe
FireEyeGeneric.mg.0c7fdd9dcd109c74
CAT-QuickHealTrojan.FuerboosPMF.S18713185
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRansom:BAT/Crypter.89ae7e97
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Filecoder.DN
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.BAT.Crypter.c
AvastWin32:Malware-gen
TencentBat.Trojan.Crypter.Hfr
SophosGeneric ML PUA (PUA)
IkarusTrojan-Ransom.FileCrypter
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/CryptInject!ml
McAfeeArtemis!0C7FDD9DCD10
MalwarebytesMalware.AI.392946571
RisingRansom.Crypter!8.1C3A (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.108558566.susgen
FortinetBAT/Crypter.C!tr
AVGWin32:Malware-gen

How to remove BAT/Filecoder.DN?

BAT/Filecoder.DN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment