Malware

Win32/Filecoder.KingOuroboros.A malicious file

Malware Removal

The Win32/Filecoder.KingOuroboros.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.KingOuroboros.A virus can do?

    How to determine Win32/Filecoder.KingOuroboros.A?

    
    

    File Info:

    crc32: 200552F6
    md5: 0ead1097d9568c31bb19f4284be9cdeb
    name: 0EAD1097D9568C31BB19F4284BE9CDEB.mlw
    sha1: 0a3f6d04932b7c0efa0e096936a220b5139080d6
    sha256: dc8f856e879796f8c1c46d087ec2cca1b94848b4095769c23b0c839edd529096
    sha512: a48e56cd9ed076e1f2404bac6efabaeb66325114ced06eb83fb795360284845242c250e595948195bc4e12d15c66f686cf8b078a2d3144725d489cffa2060ad3
    ssdeep: 24576:nAHnh+eWsN3skA4RV1Hom2KXSmHdxLOG9PVFZH/DMK:ah+ZkldoPKiYdxyG95HbM
    type: PE32 executable (GUI) Intel 80386, for MS Windows

    Version Info:

    LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
    InternalName: MSEInstall.exe
    FileVersion: 4.10.0209.0
    CompanyName: Microsoft Corporation
    ProductName: Microsoft Security Client
    ProductVersion: 4.10.0209.0
    FileDescription: MSEInstall Package
    OriginalFilename: MSEInstall.exe
    Translation: 0x0409 0x04b0

    Win32/Filecoder.KingOuroboros.A also known as:

    BkavW32.AIDetect.malware1
    K7AntiVirusTrojan ( 004f65341 )
    Elasticmalicious (high confidence)
    DrWebTrojan.Encoder.25149
    CynetMalicious (score: 100)
    CAT-QuickHealRansom.AutoIt.Genasom.ZZ
    ALYacGen:Trojan.Heur.AutoIT.2
    CylanceUnsafe
    SangforTrojan.Win32.Save.a
    CrowdStrikewin/malicious_confidence_80% (D)
    AlibabaRansom:Win32/Cossta.c14174b2
    K7GWTrojan ( 004f65341 )
    Cybereasonmalicious.7d9568
    SymantecTrojan.Gen.2
    ESET-NOD32Win32/Filecoder.KingOuroboros.A
    APEXMalicious
    AvastFileRepMetagen [Malware]
    ClamAVWin.Ransomware.Cryptowire-7595054-0
    KasperskyTrojan.Win32.Cossta.alcx
    BitDefenderGen:Trojan.Heur.AutoIT.2
    NANO-AntivirusTrojan.Win32.Encoder.fewcxz
    MicroWorld-eScanGen:Trojan.Heur.AutoIT.2
    TencentWin32.Trojan.Raas.Auto
    Ad-AwareGen:Trojan.Heur.AutoIT.2
    SophosMal/Generic-S
    ComodoMalware@#38rhk9hcidgzk
    BitDefenderThetaAI:Packer.44866B6B18
    VIPRETrojan.Win32.Generic!BT
    McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
    FireEyeGeneric.mg.0ead1097d9568c31
    EmsisoftGen:Trojan.Heur.AutoIT.2 (B)
    AviraHEUR/AGEN.1134135
    MicrosoftTrojan:Win32/Skeeyah.A!rfn
    AegisLabHacktool.Win32.Gamehack.3!e
    GDataGen:Trojan.Heur.AutoIT.2
    Acronissuspicious
    McAfeeArtemis!0EAD1097D956
    MAXmalware (ai score=97)
    VBA32Trojan.Cossta
    MalwarebytesTrojan.Dropper.AutoIt
    PandaTrj/CI.A
    YandexTrojan.AvsArher.bS9LKk
    IkarusTrojan-Ransom.Ouroboros
    FortinetAutoIt/Ouroboros.A!tr.ransom
    AVGFileRepMetagen [Malware]
    Paloaltogeneric.ml
    Qihoo-360Win32/Ransom.FRS.HwoCEpsA

    How to remove Win32/Filecoder.KingOuroboros.A?

    Win32/Filecoder.KingOuroboros.A removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment