Malware

Win32/Filecoder.NYH information

Malware Removal

The Win32/Filecoder.NYH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.NYH virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Filecoder.NYH?


File Info:

crc32: E6684EB2
md5: d985a6610213773a43584afe1107dbd9
name: D985A6610213773A43584AFE1107DBD9.mlw
sha1: 4e743e81dcb4df6e21aacd0ad2918a5b20586127
sha256: e8931967ed5a4d4e0d7787054cddee8911a7740b80373840b276f14e36bda57d
sha512: cb7779968bc632edd6531bae810953b8c4f12018c0a1fde483c75f074a10eb49d2824e64733c280daeabe373cdf95c2a3307e6cf91c200c0e34655657447fb07
ssdeep: 49152:GgZNP3LGVfMmq1d1MRGM8Fvg9fR5HMXF9W9HrAbluBUMNk+cqG2UtBpStPvC/9f:GgXDMfql+9G9+B+tBpEPvCF
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Filecoder.NYH also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Snatch.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29918
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Snatch
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.10869
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Gocoder.c231a643
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.102137
SymantecRansom.Snatch
ESET-NOD32a variant of Win32/Filecoder.NYH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.Win32.Snatch.vho
BitDefenderTrojan.Ransom.Snatch.A
NANO-AntivirusTrojan.Win32.Encoder.ggqwzr
MicroWorld-eScanTrojan.Ransom.Snatch.A
TencentWin32.Trojan.Filecoder.Wstp
Ad-AwareTrojan.Ransom.Snatch.A
SophosMal/Generic-R + Troj/Snatch-H
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Win32.Snatch.a (v)
TrendMicroRansom.Win32.SNATCH.B
McAfee-GW-EditionBehavesLike.Win32.Trojan.rh
FireEyeGeneric.mg.d985a6610213773a
EmsisoftTrojan.Ransom.Snatch.A (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Ransom.Snatch
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2CEF104
MicrosoftRansom:Win64/Gocoder.A!MSR
ArcabitTrojan.Ransom.Snatch.A
ZoneAlarmHEUR:Trojan-Ransom.Win32.Snatch.vho
GDataTrojan.Ransom.Snatch.A
AhnLab-V3Malware/Win32.Generic.C3561635
McAfeeRansom-Snatch!D985A6610213
MAXmalware (ai score=100)
VBA32TrojanRansom.Agent
MalwarebytesRansom.Snatch
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.SNATCH.B
YandexTrojan.Snatch!lFtCUUlGLIc
IkarusTrojan-Ransom.Snatch
MaxSecureTrojan.Malware.74693704.susgen
FortinetW32/Snatch.B!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Filecoder.NYH?

Win32/Filecoder.NYH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment