Malware

What is “Win32/Filecoder.CryptProjectXXX.H”?

Malware Removal

The Win32/Filecoder.CryptProjectXXX.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.CryptProjectXXX.H virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Win32/Filecoder.CryptProjectXXX.H?


File Info:

crc32: D60472DF
md5: 9555f06774763bb8906f01b28d18df44
name: 9555F06774763BB8906F01B28D18DF44.mlw
sha1: aa0b7be02b65cfaf5b022c6a3eba557b68a6193c
sha256: b5b437a6a3d9aa4c8642c17c4e87e1b1470fe5b835ce13eb0c35c1b65e38b567
sha512: 6e6cc31f90a1fa7304d90d9bde3ba3cea4a0b83c935fbc978ebc5f2b020988a88b8a5beebb0b2c87d2ccafe7acea02d0b72e7174ba1fec25b8c2400dc13cedb2
ssdeep: 3072:LjB5NThiAQeALvBq40bfr3qIir6LXn6v8:LjB5NcAJGuvVimLX6
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003 - 2011 Nir Sofer
InternalName: NirCmd
FileVersion: 2.65
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.65
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Win32/Filecoder.CryptProjectXXX.H also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f8bc31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 99)
CAT-QuickHealRansom.Crowti.MUE.A6
ALYacGen:Variant.Barys.59243
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.3507
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/CryptXXX.839287a3
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.774763
CyrenW32/Ransom.CJ.gen!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32Win32/Filecoder.CryptProjectXXX.H
APEXMalicious
AvastWin32:Goblinek [Inf]
KasperskyTrojan-Ransom.Win32.CryptXXX.asdnfx
BitDefenderGen:Variant.Barys.59243
NANO-AntivirusTrojan.Win32.Encoder.fucstm
MicroWorld-eScanGen:Variant.Barys.59243
TencentMalware.Win32.Gencirc.116984b1
Ad-AwareGen:Variant.Barys.59243
SophosMal/Generic-S
ComodoMalware@#7tefx1qt1z7q
BitDefenderThetaGen:NN.ZexaF.34670.gy0@a0Bb0BbQ
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionRansomware-FTK!9555F0677476
FireEyeGeneric.mg.9555f06774763bb8
EmsisoftGen:Variant.Barys.59243 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.ebozp
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1110705
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Barys.DE76B
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Barys.59243
TACHYONRansom/W32.CryptXXX.108544
AhnLab-V3Malware/Win32.RL_Generic.R285865
Acronissuspicious
McAfeeRansomware-FTK!9555F0677476
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingRansom.CryptXXX!8.5DF0 (CLOUD)
YandexTrojan.GenAsa!ao0N/xdCg2Q
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Goblinek [Inf]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.CryptXXX.HxQBdN4A

How to remove Win32/Filecoder.CryptProjectXXX.H?

Win32/Filecoder.CryptProjectXXX.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment