Malware

Win32/Filecoder.NAN removal tips

Malware Removal

The Win32/Filecoder.NAN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NAN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ocsp.digicert.com
readion.deaftone.com
youhappenes.flnet.org

How to determine Win32/Filecoder.NAN?


File Info:

crc32: 4C5AA54D
md5: 07f5a7d948fe49bf1065a251d49904cc
name: 07F5A7D948FE49BF1065A251D49904CC.mlw
sha1: 4345ce5431121cfb05460ac4785748052692df03
sha256: 98bdca36ba088191acbb654f46b2206ab7e57f6ef3c364a8bee750ece63b1e05
sha512: bd7126a6482080f4ed9ad8d132544bef5be5cdb66696acb39960075d194d013eb8d18a280dba7eb41802a739edbbe8bbd79087c8a585411c97f006f0cc9322b6
ssdeep: 6144:EvUcz0z5kSGkufAGkvhDvhayrLqicIBsBtFaLHcpI+nzeO:Epz8SSEAJ9rLqi5BsBtccp9eO
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Sqmxfifhp Cwvheieax
InternalName: Ojfwnjtv
FileVersion:
CompanyName: Sqmxfifhp Cwvheieax
ProductName: Wjyxrmzhsjk Dmjfxj Giqjeyf
ProductVersion:
FileDescription: OjfwnjtvBnebwq
OriginalFilename: Ojfwnjtv.exe
Translation: 0x0409 0x04b0

Win32/Filecoder.NAN also known as:

CyrenCloudW32/Trojan.OQRG-8226.98BDCA36!Threatlookup
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.217
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic
ALYacGen:Variant.Symmi.20547
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.9857
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.948fe4
NANO-AntivirusTrojan.Win32.RiskGen.brqucg
ESET-NOD32Win32/Filecoder.NAN
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-738837
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.20547
SUPERAntiSpywareTrojan.Agent/Gen-Sisron
MicroWorld-eScanGen:Variant.Symmi.20547
TencentMalware.Win32.Gencirc.10b61cb5
Ad-AwareGen:Variant.Symmi.20547
SophosMal/Generic-R + Troj/Ransom-RZ
ComodoTrojWare.Win32.Sisron.DS@5rvfip
BitDefenderThetaGen:NN.ZexaF.34686.quX@aGYrYNki
VIPRETrojan.Win32.Generic!BT
EmsisoftGen:Variant.Symmi.20547 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Foreign.ejk
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1118864
Antiy-AVLTrojan[Ransom]/Win32.Foreign
MicrosoftRansom:Win32/Haperlock.A
ArcabitTrojan.Symmi.D5043
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.20547
AhnLab-V3Trojan/Win32.Foreign.R64899
Acronissuspicious
McAfeePWS-Zbot-FASG!07F5A7D948FE
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.Heuristic.1008
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HAPERLOCK.SM
RisingRansom.Haperlock!8.5355 (CLOUD)
YandexTrojan.Foreign!zor55H6MRlw
IkarusTrojan.Win32.Sisron
FortinetW32/Filecoder.NAN!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Filecoder.NAN?

Win32/Filecoder.NAN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment