Malware

What is “Win32/Filecoder.NIC”?

Malware Removal

The Win32/Filecoder.NIC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NIC virus can do?

  • Unconventionial language used in binary resources: Spanish (Modern)
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Filecoder.NIC?


File Info:

crc32: B431B24D
md5: 548f509a14545dc28885a16a06ca7cd8
name: 548F509A14545DC28885A16A06CA7CD8.mlw
sha1: 7e9073b93194bc9f98d94e9fbe2b2f06747640c6
sha256: 918a5f0d186d82ce0af97e847bb6ec7f1263d201e3c09f88cc529b87dcf52313
sha512: f8bb86612c29aeb63b970b5890055816c79f93ac2da97d092ba5d4b57d012cc7de84665a9d2461fba525f7feaf562253a039b520504617f0c8f1eca7c8d94336
ssdeep: 768:x1y6k/ohmGV3l6q9GVM5+d6u4QLBr6O6wb:x1pkkmGP6qgVM5+sXQLREwb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. Todos los derechos reservados.
InternalName: explorer
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
CompanyName: Microsoft Corporation
ProductName: Sistema operativo Microsoftxae Windowsxae
ProductVersion: 10.0.14393.0
FileDescription: Explorador de Windows
OriginalFilename: EXPLORER.EXE.MUI
Translation: 0x0c0a 0x04b0

Win32/Filecoder.NIC also known as:

K7AntiVirusTrojan ( 004f246c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5883
CynetMalicious (score: 100)
McAfeeGenericRXAP-DF!548F509A1454
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.10257
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 004f246c1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NIC
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Au6r-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Malware.eq0@au6r@EVc
NANO-AntivirusTrojan.Win32.Crypted.ehenxx
MicroWorld-eScanGen:Trojan.Malware.eq0@au6r@EVc
TencentMalware.Win32.Gencirc.114b5dbf
Ad-AwareGen:Trojan.Malware.eq0@au6r@EVc
SophosMal/FakeAV-CS
ComodoTrojWare.Win32.Fabiansomware.A@6mnx0l
BitDefenderThetaGen:NN.ZexaF.34628.eq0@au6r@EVc
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_APOCALYPSE.E
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.kt
FireEyeGeneric.mg.548f509a14545dc2
EmsisoftGen:Trojan.Malware.eq0@au6r@EVc (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.gkdxo
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_94%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Apocalypse
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Apocalypse.C
AhnLab-V3Trojan/Win32.Fsysna.R189238
VBA32BScope.Trojan.Encoder
MAXmalware (ai score=88)
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_APOCALYPSE.E
YandexTrojan.GenAsa!X6Z4O+cgMzQ
IkarusTrojan-Ransom.Fabiansom
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Generic.AC.395335!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQB5h8A

How to remove Win32/Filecoder.NIC?

Win32/Filecoder.NIC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment