Malware

Win32/Filecoder.BTCWare.I malicious file

Malware Removal

The Win32/Filecoder.BTCWare.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.BTCWare.I virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Writes a potential ransom message to disk
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup

How to determine Win32/Filecoder.BTCWare.I?


File Info:

name: 0C30DAF1058ABED43F8B.mlw
path: /opt/CAPEv2/storage/binaries/28c6d4c26a374d0c83b8431e269b3571550c8442f9a011280d506a58d34f048a
crc32: CF5A9988
md5: 0c30daf1058abed43f8bc0e3401872fe
sha1: 36efc4f101134f1c527d409fa37c2fde11d15583
sha256: 28c6d4c26a374d0c83b8431e269b3571550c8442f9a011280d506a58d34f048a
sha512: ea8a8bb94e642f61901a61302d75ae8bd8974e79e655af5e0475a87e70420476c6fde8c3e9b684ff827833035fad59c4213e3bb86163c02ab26cadb4bf02e245
ssdeep: 3072:EwDijpS4DbYcR3bA4Dztu/Luw98xHFWsgoWU5OYO1WO:EFtA416u7xHFWnoWUpWJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AF301562AF0C8B7F36903B40A7A2F37FB75511676164283A3A02F977823193452D3AF
sha3_384: e42dec66ac51d80081371a82b3d606eb750ee75b3ac947a95be365544eb1659e5da1027428d28c05f0a565bf11288f60
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2017-08-01 00:34:02

Version Info:

0: [No Data]

Win32/Filecoder.BTCWare.I also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!e
CynetMalicious (score: 99)
McAfeeGeneric.adc
CylanceUnsafe
ZillyaTrojan.Cryptor.Win32.141
SangforTrojan.Win32.BTCWare.I
K7AntiVirusTrojan ( 0050b3cb1 )
AlibabaRansom:Win32/Cryptor.13932743
K7GWTrojan ( 0050b3cb1 )
Cybereasonmalicious.1058ab
VirITTrojan.Win32.NSISDrp.NQN
CyrenW32/Cryptor.YPWI-7473
SymantecPacked.NSISPacker!g4
Elasticmalicious (high confidence)
ESET-NOD32Win32/Filecoder.BTCWare.I
TrendMicro-HouseCallRansom_GRYPHON.D
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Cryptor.je
BitDefenderTrojan.Ransom.BTA
NANO-AntivirusTrojan.Win32.Cryptor.ethqda
ViRobotTrojan.Win32.S.Ransom.161125
MicroWorld-eScanTrojan.Ransom.BTA
APEXMalicious
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.Ransom.BTA
EmsisoftTrojan-Ransom.Gryphon (A)
ComodoMalware@#2wsj5bf8oa9h
DrWebTrojan.Encoder.13648
VIPRETrojan.Ransom.BTA
TrendMicroRansom_GRYPHON.D
McAfee-GW-EditionBehavesLike.Win32.ICLoader.cc
FireEyeTrojan.Ransom.BTA
SophosMal/Generic-L
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Ransom.BTCWare.KX44BU
WebrootW32.Trojan.Gen
AviraTR/AD.NsisPureInject.hlwrn
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASSuf.1F252
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Ransom.BTA
MicrosoftTrojan:Win32/Predator.GJ!MTB
AhnLab-V3Trojan/Win32.GryphonCryptor.R206550
ALYacTrojan.Ransom.Gryphon
VBA32Hoax.Cryptor
AvastWin32:Trojan-gen
RisingRansom.Genasom!8.293 (KTSE)
IkarusTrojan-Ransom.Gryphon
FortinetW32/Cryptor.JE!tr
AVGWin32:Trojan-gen
PandaTrj/WLT.D
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Filecoder.BTCWare.I?

Win32/Filecoder.BTCWare.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment