Malware

How to remove “Win32/Filecoder.OKO”?

Malware Removal

The Win32/Filecoder.OKO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.OKO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Clears Windows events or logs
  • Harvests cookies for information gathering

How to determine Win32/Filecoder.OKO?


File Info:

name: 81063E103630A017F9E2.mlw
path: /opt/CAPEv2/storage/binaries/c1808d1d60b78b2b6e9b60b60c8f49320d621013c0e621b316201af2ae372303
crc32: DAE8D261
md5: 81063e103630a017f9e20aad90dfea15
sha1: 12d3e83c7db6eb8d75214508ab15804b1814274a
sha256: c1808d1d60b78b2b6e9b60b60c8f49320d621013c0e621b316201af2ae372303
sha512: 881c5958670e953c86ce0ac8d63368a5826aafd65296b1aa7daae9128594632fe7e75ff925f10557b3f3a398826b59bb96b2e27721cbc976a18f59b85eeb412d
ssdeep: 6144:U/s86W766rQ66548kUmsRsvwhCQcV4lChjX70tfqTi8wzv5MaImSjIxgOGz24hYa:RsPAVYRQTBA+0h/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B3645B20B353F672D46148F84E6DAA66B91DAC081B249BFBB3DC3669ED351C04A31FD4
sha3_384: ae9ec16c33b5e1aa60cb96565f7c2a5ac33525180bd308f58ac3a64dbfefe78c19fea60886068578a03c0742dcd337f2
ep_bytes: e8a8050000e974feffff558bec6a00ff
timestamp: 2022-04-28 11:13:42

Version Info:

0: [No Data]

Win32/Filecoder.OKO also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Ransom.District.2
FireEyeGen:Variant.Ransom.District.2
ALYacGen:Variant.Ransom.District.2
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.23222
Cybereasonmalicious.03630a
CyrenW32/Ransom.QN.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.OKO
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
BitDefenderGen:Variant.Ransom.District.2
NANO-AntivirusTrojan.Win32.SchoolGirl.jpadgk
RisingRansom.Agent!8.6B7 (RDMK:cmRtazoF6K3//atXMYg)
Ad-AwareGen:Variant.Ransom.District.2
TACHYONTrojan/W32.SchoolGirl.311296
DrWebTrojan.Encoder.35158
VIPREGen:Variant.Ransom.District.2
McAfee-GW-EditionBehavesLike.Win32.NetLoader.fh
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Ransom.District.2 (B)
JiangminTrojan.SchoolGirl.nq
AviraHEUR/AGEN.1213039
Antiy-AVLTrojan/Generic.ASMalwS.4A07
GDataGen:Variant.Ransom.District.2
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5137809
McAfeeGenericRXSI-UI!81063E103630
MAXmalware (ai score=83)
VBA32BScope.Trojan.SchoolGirl
MalwarebytesMalware.AI.1812541523
TencentMalware.Win32.Gencirc.10d044f4
MaxSecureTrojan.Malware.73882111.susgen
FortinetW32/Filecoder.OKO!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34806.tuW@aqJlftm
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Filecoder.OKO?

Win32/Filecoder.OKO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment