Malware

About “Win32/Filecoder.Lockbit.B” infection

Malware Removal

The Win32/Filecoder.Lockbit.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Lockbit.B virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Filecoder.Lockbit.B?


File Info:

crc32: 7BF13F42
md5: 9a4df42101a680237241797dc57bd304
name: 9A4DF42101A680237241797DC57BD304.mlw
sha1: db0bc0c41f5aae7e102176eba7f0386f5701a0a3
sha256: 4d0113884f70ddbbaf1ee0365602124ba91c11a76ff7bff5908d310aa9d3dfe9
sha512: 836ffdb37bf3b0a639bf406422b46f1b3aeaddfe1b1680dc83c794a6e3e299b1c3030a82aac561740cf8ddeff3d2e554d96a0898da453e92da16dc6ef76d653e
ssdeep: 1536:juBQenvT2/XXMvFbedQHnoVNUmKV9j3MqqU+hV2FeabjZc:juBHkX8dqOnK+mK33MqqD/ad
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.Lockbit.B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
FireEyeGeneric.mg.9a4df42101a68023
McAfeeGenericRXIS-VO!9A4DF42101A6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056a69e1 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 0056a69e1 )
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.LockBitCombined-9375766-1
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Tiggre.eed7c166
NANO-AntivirusTrojan.Win32.Filecoder.gdmacf
RisingTrojan.Filecoder!8.68 (CLOUD)
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Encoder.29662
TrendMicroRansom.Win32.SANSPITIE.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.eesyi
eGambitUnsafe.AI_Score_98%
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Fuery
MicrosoftTrojan:Win32/Tiggre!plock
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Ransom.REntS.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C3513194
Acronissuspicious
BitDefenderThetaAI:Packer.C3E6D0431E
ALYacTrojan.Ransom.Filecoder
VBA32BScope.Trojan.DelShad
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Filecoder.Lockbit.B
TrendMicro-HouseCallRansom.Win32.SANSPITIE.SMTH
TencentWin32.Trojan.Raas.Auto
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.NXQ!tr.ransom
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Cybereasonmalicious.101a68
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Ransom.ec8

How to remove Win32/Filecoder.Lockbit.B?

Win32/Filecoder.Lockbit.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment