Malware

How to remove “Win32/Filecoder.NFQ”?

Malware Removal

The Win32/Filecoder.NFQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NFQ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Kannada
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.cerdanya-hobbies.es
a.tomx.xyz

How to determine Win32/Filecoder.NFQ?


File Info:

crc32: ACBF6DF9
md5: f7ff1b2be3488ab73ce62f5662c79e5c
name: F7FF1B2BE3488AB73CE62F5662C79E5C.mlw
sha1: 6e3d700cb2735392ad04af792f0fdcddb13ba46b
sha256: 5717617dec7a5422780994a41e10147b11561671e53d7a4c3f2168e15a48a525
sha512: 0a208074bc607861cf452389ea3a45b9b8333f422b5d653d993a292cd5773151d756a9b75ed6efe55ab034bd34033b6c094b6e839f3929b3db8b0c1061c43da2
ssdeep: 24576:TOkThE2j6kVTbOmn4S1cIJQ9aASie0LfQ9O99pf97rE:TLFp1xESrJQ4ie0UUNf9H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright sobrevivencia 2015-2016
InternalName: CDNSexDPeVvb0roJ
FileVersion: 2.00.0594
CompanyName: Artigo em destaque
LegalTrademarks: Dionaea muscipula
Comments: copiado e reutilizado sob a mesma licenca
ProductName: Apresentacao
ProductVersion: 2.00.0594
FileDescription: Em seu habitat nativo
OriginalFilename: CDNSexDPeVvb0roJ.exe

Win32/Filecoder.NFQ also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Aura.j!c
DrWebTrojan.Encoder.2667
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.100
CylanceUnsafe
ZillyaTrojan.Aura.Win32.213
SangforSuspicious.Win32.Save.a
AlibabaRansom:Win32/Filecoder.c5751b29
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.be3488
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.NFQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Aura.akb
BitDefenderGen:Variant.Barys.100
NANO-AntivirusTrojan.Win32.Aura.eglezp
MicroWorld-eScanGen:Variant.Barys.100
TencentWin32.Trojan.Aura.Egol
Ad-AwareGen:Variant.Barys.100
SophosMal/VBInject-D
ComodoMalware@#15rkoff6ntxpx
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Virus.th
FireEyeGen:Variant.Barys.100
EmsisoftGen:Variant.Barys.100 (B)
WebrootW32.Aura.akb
AviraTR/AD.Pottieq.xrdf
Antiy-AVLTrojan/Generic.ASMalwS.1AAAA77
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom
GDataGen:Variant.Barys.100
McAfeeArtemis!F7FF1B2BE348
MAXmalware (ai score=87)
VBA32Hoax.Aura
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
YandexTrojan.Aura!S7KadRVtTV0
IkarusTrojan.Win32.Spy
FortinetW32/Aura.AKB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Filecoder.NFQ?

Win32/Filecoder.NFQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment