Categories: Worm

Win32/Filecoder.JSWorm.C malicious file

The Win32/Filecoder.JSWorm.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.JSWorm.C virus can do?

  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Win32/Filecoder.JSWorm.C?


File Info:

crc32: 21205632md5: bb02350fc8eb8db051702042975786a8name: BB02350FC8EB8DB051702042975786A8.mlwsha1: fcc9b5a4722a70f9b17f15b4c2411bc01dc385a3sha256: a0a1fa5d66c4e3de1d7be24ca02cb0ca65721735d42a5b45572a0f40961251c5sha512: 868fffb875733ffd2c6795a83ef10e78640465e50b86cd5b5d94366c5fe5e18e1db6d587f5579986fdd7ef9a2ab100a77ae4a0a1741d0082860de1ce59e6f324ssdeep: 12288:ywbmsSMUoycSzYKJu1spJRaoEYj/EAEqGV2V2X62iz+yEFu08Rk+nav:y1sucSz3u1wadAEqcXQstype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.JSWorm.C also known as:

K7AntiVirus Trojan ( 0054e6741 )
DrWeb Trojan.Encoder.28477
Cynet Malicious (score: 99)
ALYac Trojan.Ransom.JSWorm
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.9453
Sangfor Trojan.Win32.Save.a
Alibaba Trojan:Win32/DelShad.83f38430
K7GW Trojan ( 0054e6741 )
Cybereason malicious.fc8eb8
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Filecoder.JSWorm.C
Avast Win32:Trojan-gen
Kaspersky Trojan.Win32.DelShad.mm
BitDefender Trojan.GenericKD.32051170
NANO-Antivirus Trojan.Win32.DelShad.frsqtu
MicroWorld-eScan Trojan.GenericKD.32051170
Tencent Win32.Trojan.Delshad.Pepe
Ad-Aware Trojan.GenericKD.32051170
Sophos Mal/Generic-S
Comodo Malware@#1osie9j2ongxt
F-Secure Trojan.TR/FileCoder.ktkgz
BitDefenderTheta Gen:NN.ZexaF.34722.zqW@aay0OYg
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom.Win32.JSWORM.SM
McAfee-GW-Edition Trojan-FQZW!BB02350FC8EB
FireEye Trojan.GenericKD.32051170
Emsisoft Trojan.FileCoder (A)
Jiangmin Trojan.DelShad.bp
Avira TR/FileCoder.ktkgz
eGambit Unsafe.AI_Score_100%
Antiy-AVL Trojan/Generic.ASMalwS.2BE32E8
Microsoft Trojan:Win32/Malex.gen!E
Arcabit Trojan.Generic.D1E90FE2
AegisLab Trojan.Win32.DelShad.4!c
ZoneAlarm Trojan.Win32.DelShad.mm
GData Win32.Trojan-Ransom.Filecoder.CF@gen
TACHYON Ransom/W32.DelShad.419840
AhnLab-V3 Trojan/Win32.FileCoder.R276135
McAfee Trojan-FQZW!BB02350FC8EB
VBA32 BScope.Trojan.StartPage
Malwarebytes Generic.Malware/Suspicious
Panda Trj/GdSda.A
TrendMicro-HouseCall Ransom.Win32.JSWORM.SM
Yandex Trojan.GenAsa!jnaeNLf7tVI
Ikarus Trojan-Ransom.FileCrypter
MaxSecure Trojan.Malware.74386750.susgen
Fortinet W32/Filecoder.NVV!tr.ransom
AVG Win32:Trojan-gen
Paloalto generic.ml

How to remove Win32/Filecoder.JSWorm.C?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Midie.100502 removal tips

The Midie.100502 is considered dangerous by lots of security experts. When this infection is active,…

16 mins ago

Malware.AI.3915743673 (file analysis)

The Malware.AI.3915743673 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Malware.AI.2034266737 removal

The Malware.AI.2034266737 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Trojan.Win32.Agent.xbmkmt removal tips

The Trojan.Win32.Agent.xbmkmt is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

About “MSIL/Kryptik.ALNP” infection

The MSIL/Kryptik.ALNP is considered dangerous by lots of security experts. When this infection is active,…

31 mins ago

How to remove “Malware.AI.4206534535”?

The Malware.AI.4206534535 is considered dangerous by lots of security experts. When this infection is active,…

37 mins ago