Malware

Should I remove “Win32/Filecoder.NGQ”?

Malware Removal

The Win32/Filecoder.NGQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NGQ virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Filecoder.NGQ?


File Info:

crc32: 2944014F
md5: cd073c5345a6afc4ca48441fb495d506
name: CD073C5345A6AFC4CA48441FB495D506.mlw
sha1: d03415d0063c7bb13a783c9603206f9f500abb90
sha256: 5bb008d36cade9846e5e0737f5d86b869d49c20c8a1bb161f9f050a3a1dae38d
sha512: db85a9c331fcf7a99c9dd35fdf9b9588e18027d116a928456d01173172460305c3bf1a20c89ff96b0b62891300e885a60a9a05c2056c0bc8de0a94a84d1eb35c
ssdeep: 768:g1bgtZ7yqyzDUG+abSQ/yQk1o1ROClHa9ikz8F9Tl3:g1EZ7yBDUPa+Q/y1e1kKHWik8l3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.NGQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.5
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.2609
SangforRansom.Win32.Cryptor.dl
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Cryptor.ffe0b2f5
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.345a6a
SymantecRansom.777
ESET-NOD32a variant of Win32/Filecoder.NGQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Symmi-1791
KasperskyTrojan-Ransom.Win32.Cryptor.dl
BitDefenderGen:Heur.Mint.Zard.5
NANO-AntivirusTrojan.Win32.FileCoder.edaqhh
MicroWorld-eScanGen:Heur.Mint.Zard.5
TencentRansom.Win32.777.a
Ad-AwareGen:Heur.Mint.Zard.5
SophosMal/Generic-S
ComodoMalware@#34omyp2eg8pse
BitDefenderThetaGen:NN.ZexaF.34790.jrZ@a42ZOkc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_SieteCrypto.R002C0DG921
McAfee-GW-EditionBehavesLike.Win32.Dropper.tz
FireEyeGeneric.mg.cd073c5345a6afc4
EmsisoftGen:Heur.Mint.Zard.5 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Democry.b
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1128760
eGambitUnsafe.AI_Score_91%
Antiy-AVLTrojan/Generic.ASMalwS.18DC873
MicrosoftRansom:Win32/SieteCrypto.A
GDataGen:Heur.Mint.Zard.5
McAfeeArtemis!CD073C5345A6
MAXmalware (ai score=88)
VBA32BScope.TrojanRansom.Cryptor
MalwarebytesRansom.FileLocker
PandaTrj/CI.A
TrendMicro-HouseCallRansom_SieteCrypto.R002C0DG921
RisingTrojan.Generic@ML.100 (RDML:69nVrSTe21lhlv2mEwaCEw)
YandexTrojan.GenAsa!1suhfuVJyXY
IkarusTrojan.Win32.Filecoder
FortinetW32/Generic.AC.3458194
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cryptor.HwgABHwC

How to remove Win32/Filecoder.NGQ?

Win32/Filecoder.NGQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment