Malware

Win32/Filecoder.NUX removal guide

Malware Removal

The Win32/Filecoder.NUX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NUX virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk

How to determine Win32/Filecoder.NUX?


File Info:

crc32: 725E5EFC
md5: 4f029ba5cccc075a5132565eb3eabccc
name: 4F029BA5CCCC075A5132565EB3EABCCC.mlw
sha1: 837e5c5e87d0179b5a32793a105734aa1906d7be
sha256: 8a28d340e9df3c693f39e13466a2b2cc7eaf9d21cff2bb4bd9cfe7e69b01e0ac
sha512: b46e054554ea854cad393f9f145f4a2f937c93bb4d871f8531fb7097e4889e7b5906430454220f5a3a3be561bff39ad7578e2fcc1c4c1b9fe6e256206886705e
ssdeep: 24576:MkeJP6OCGJsf5fFtsF2l0ye6vcON71Rv:MkeJP6OCnBrsFlvs7
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Filecoder.NUX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Encoder.Win32.437
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Filecoder.9c417596
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5cccc0
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.NUX
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Encoder.atj
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusTrojan.Win32.Encoder.fkffxs
ViRobotTrojan.Win32.S.Agent.840704.CL
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentWin32.Trojan.Encoder.Pdmg
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosMal/Generic-S
ComodoMalware@#3g90a4g79r5ko
BitDefenderThetaGen:NN.ZexaF.34670.ZmGfaGVxPFpi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.4f029ba5cccc075a
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan[Ransom]/Win32.Encoder
MicrosoftRansom:Win32/Genasom
ArcabitTrojan.Ransom.REntS.Gen.1
AegisLabTrojan.Win32.Imps.4!c
GDataGen:Heur.Ransom.REntS.Gen.1
AhnLab-V3Malware/Win32.Generic.C2889060
McAfeeArtemis!4F029BA5CCCC
MAXmalware (ai score=100)
VBA32TrojanRansom.Encoder
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
RisingRansom.Encoder!8.FFD4 (CLOUD)
YandexTrojan.GenAsa!SXQHH4ms6Ic
IkarusTrojan-Ransom.Rokku
FortinetW32/Encoder.ATJ!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Encoder.HwsBEpsA

How to remove Win32/Filecoder.NUX?

Win32/Filecoder.NUX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment