Malware

Should I remove “Win32/Filecoder.NPA”?

Malware Removal

The Win32/Filecoder.NPA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NPA virus can do?

  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Filecoder.NPA?


File Info:

crc32: F896FA04
md5: b25ec00193e1c6170d2329d5a7406065
name: B25EC00193E1C6170D2329D5A7406065.mlw
sha1: 85160e130bc498a0135137e3968cb85c0c15e5bb
sha256: 9d925f5f3a3633b4b2dc1cd13c5f11d3aac5cf6b55991c0c90e52658c6ccb894
sha512: 25b45e4c3b553dd33290a6d83ffea454399be5b3b0e8581483295d6480122f9009b0b785763dbad84fca2cea7b14bdb4e3e67ff7cf25bf0a796d68f344ca7bed
ssdeep: 192:nKtUX3AWtAPir8j55wTwtH+fYAo6h7XbSKO5TP:KtKNtCiow8t+fFh7Lb0TP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.NPA also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.30574
MicroWorld-eScanGen:Trojan.AV-Killer.amW@aO3vYkp
FireEyeGeneric.mg.b25ec00193e1c617
Qihoo-360Win32/Trojan.Anti.afe
ALYacGen:Trojan.AV-Killer.amW@aO3vYkp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005451b81 )
BitDefenderGen:Trojan.AV-Killer.amW@aO3vYkp
K7GWTrojan ( 005451b81 )
Cybereasonmalicious.193e1c
BitDefenderThetaAI:Packer.1DFEA2521E
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.AntiAV
AlibabaTrojan:Win32/Filecoder.f3ee1c90
NANO-AntivirusTrojan.Win32.Filecoder.gtgwrw
AegisLabTrojan.Win32.AntiAV.4!c
TencentWin32.Trojan.Filecoder.Pdcg
Ad-AwareGen:Trojan.AV-Killer.amW@aO3vYkp
EmsisoftGen:Trojan.AV-Killer.amW@aO3vYkp (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
TrendMicroRansom.Win32.LOCKCRYPT.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.lh
SophosML/PE-A + Mal/EncPk-ZC
IkarusTrojan-Ransom.FileCrypter
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.AntiAV
MicrosoftTrojan:Win32/Ymacco.AB9D
ArcabitTrojan.AV-Killer.ED030B
ZoneAlarmHEUR:Trojan.Win32.AntiAV
GDataGen:Trojan.AV-Killer.amW@aO3vYkp
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AntiAV.C2982142
Acronissuspicious
McAfeeArtemis!B25EC00193E1
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.Encoder
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Filecoder.NPA
TrendMicro-HouseCallRansom.Win32.LOCKCRYPT.SM
RisingTrojan.Filecoder!8.68 (CLOUD)
YandexTrojan.GenAsa!7tQJNCHkC14
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Filecoder.NPA!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.425.susgen

How to remove Win32/Filecoder.NPA?

Win32/Filecoder.NPA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment