Malware

Win32/Filecoder.OBQ removal guide

Malware Removal

The Win32/Filecoder.OBQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.OBQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • Attempted to write to a harddisk volume
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Writes a potential ransom message to disk
  • Likely installs a bootkit via raw harddisk modifications
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Filecoder.OBQ?


File Info:

name: 207E6F51489A89799188.mlw
path: /opt/CAPEv2/storage/binaries/0dc0da0739b227a9dae83be93d1b232c645dbffc7499709ae05c4ffa1bf44000
crc32: 4DED7CBD
md5: 207e6f51489a897991888a38efa3acd6
sha1: 1fb9b8115d74cf38d6a90b9049c73ea6eb743643
sha256: 0dc0da0739b227a9dae83be93d1b232c645dbffc7499709ae05c4ffa1bf44000
sha512: 04ccdb65893feae417da5f43b252616dd8c20629e82a63bcd20ca34d0ea8a7b0823ba3425f9c5c5d7010b6ed8be524b430677500bf1b9306173089afd76d8140
ssdeep: 3072:F/ZYDaoAN6vHt5pmXcQ8QAjD44vcbl4ewhp891H9EZfTd3zHZ0DELbTI:qlmXcQHA0JdSpq1eV50DErI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FD37E10E9D690F1DDAB0FB995FA29FE50312A308735A2F7EBD54E94C9336C2D235221
sha3_384: ee783dc13aacf76435dda4f2088abcd3e73aed789e6fe513dcf2bcdb241c6d787b60f24b5adc6eb9d19729ee1a77fc52
ep_bytes: 558bec681c01000068884c4200e82ef6
timestamp: 2022-01-25 16:58:49

Version Info:

0: [No Data]

Win32/Filecoder.OBQ also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.207e6f51489a8979
McAfeeGenericRXRH-KS!207E6F51489A
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.22904
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/FileCoder.87fefa8c
K7GWTrojan ( 00564d931 )
K7AntiVirusTrojan ( 00564d931 )
CyrenW32/Trojan.NILQ-3200
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Filecoder.OBQ
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Filecoder.Hoos
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Encoder.33303
VIPREGen:Heur.Ransom.REntS.Gen.1
TrendMicroRansom.Win32.VENUS.THCCOBB
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SophosMal/Generic-S + Mal/Emogen-Y
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Ransom.REntS.Gen.1
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1D6F
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftTrojan:Win32/Mamson.A!ac
AhnLab-V3Trojan/Win.Generic.C4474325
Acronissuspicious
VBA32BScope.TrojanDropper.Daws
ALYacTrojan.Ransom.Filecoder
MAXmalware (ai score=80)
MalwarebytesMalware.AI.4085622967
TrendMicro-HouseCallRansom.Win32.VENUS.THCCOBB
RisingTrojan.Generic@AI.86 (RDML:CuZWokESAi6ll/fkqaNBhg)
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.OBQ!tr.ransom
BitDefenderThetaAI:Packer.D2D1B3CA1F
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.1489a8
PandaTrj/GdSda.A

How to remove Win32/Filecoder.OBQ?

Win32/Filecoder.OBQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment