Malware

How to remove “Win32/Filecoder.FS”?

Malware Removal

The Win32/Filecoder.FS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.FS virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Filecoder.FS?


File Info:

crc32: E9F9EC17
md5: b251687d3cdd28055c3dd85654f87171
name: B251687D3CDD28055C3DD85654F87171.mlw
sha1: 008cf51a143d3811ec98528cc59c6839a2eea002
sha256: 29af4eb16b3a921085bc7436fb1e831924b49558331b88ba46fc2d9e8d97a22f
sha512: 0c61c21e84c754f10f65dcd869a7dcb5bd29412c1972aa3f4dcc6a06650c08df9248d18918988ce2b4c061cb73437e7d316a1905a5c3b9c10e6c3c8f6016d116
ssdeep: 3072:yAzXdojpB1Q0dK+1zS4OWI4HXd7I4sBAZrzVPFGXF:yAzatB1Qn+JlOWI4HKuZn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.FS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f700b1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.REntS.Gen.1
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.5831
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004f700b1 )
Cybereasonmalicious.d3cdd2
SymantecRansom.Gen!gm
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Scarab-6336012-1
KasperskyHEUR:Trojan-Ransom.Win32.Purga.gen
BitDefenderGen:Heur.Ransom.REntS.Gen.1
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentWin32.Trojan.Filecoder.Pdbt
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaAI:Packer.B4E1CC7018
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.b251687d3cdd2805
EmsisoftTrojan-Ransom.Scarab (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Dldr.Delphi.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Higuniel.A
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Heur.Ransom.REntS.Gen.1
AhnLab-V3Malware/Win32.Generic.C2005516
Acronissuspicious
McAfeeGeneric.ayb
MAXmalware (ai score=83)
VBA32BScope.Trojan.Encoder
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Purge
RisingTrojan.Filecoder!8.68 (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Msht.GJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASOYA

How to remove Win32/Filecoder.FS?

Win32/Filecoder.FS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment