Categories: Malware

About “Win32/Filecoder.Q” infection

The Win32/Filecoder.Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Q virus can do?

  • The executable is compressed using UPX
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Win32/Filecoder.Q?


File Info:

crc32: 1B176430md5: b3e769ee6f6a8c7235e6a334970b4be7name: B3E769EE6F6A8C7235E6A334970B4BE7.mlwsha1: 874efec4089e2b06d5c2d513e23ff4956338f778sha256: b78f9b3825807e15b54214ed17bfda2936786424aaac396b9cd88e36c1fe4b2dsha512: 8712f39b7ea9f2c56ceee6eca1e5fde9339fc6320658d226c19328830ab49a11e081e51283653b0c9bc045817bce57930c2010d2f64c36f17fa5d5ac149d9672ssdeep: 3072:OUQfoiWi/0bKmewYsPoFXwKKRLCGFO2jU3:ugiWi/0bKme7O+SFFO2ctype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Filecoder.Q also known as:

Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Ransom.AIG
FireEye Generic.mg.b3e769ee6f6a8c72
CAT-QuickHeal Trojan.Ransom.FO4
Qihoo-360 Malware.Radar01.Gen
ALYac Trojan.Ransom.Xorist
Cylance Unsafe
VIPRE Trojan.Win32.Ransom.fo (v)
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005451b81 )
BitDefender Trojan.Ransom.AIG
K7GW Trojan ( 005451b81 )
BitDefenderTheta Gen:NN.ZexaF.34590.gmGfailPs0li
Cyren W32/Filecoder.Y.gen!Eldorado
Symantec Ransom.CryptoTorLocker
ESET-NOD32 a variant of Win32/Filecoder.Q
Baidu Win32.Trojan.Filecoder.g
APEX Malicious
Avast FileRepMalware
ClamAV Win.Trojan.CryptoTorLocker2015-1
Kaspersky Trojan-Ransom.Win32.Xorist.ln
NANO-Antivirus Trojan.Win32.Xorist.dxuuhl
ViRobot Trojan.Win32.A.Xorist.1268736[UPX]
Tencent Trojan.Win32.CryptoTorLocker2015.a
Ad-Aware Trojan.Ransom.AIG
Emsisoft Trojan.Ransom.AIG (B)
Comodo TrojWare.Win32.Kryptik.ER@4o1ar2
F-Secure Trojan.TR/Ransom.Xorist.EJ
DrWeb Trojan.Encoder.94
Zillya Trojan.Ransom.Win32.919
TrendMicro Ransom_XORIST.SMA
McAfee-GW-Edition BehavesLike.Win32.Pluto.cm
Sophos Mal/Generic-R + Troj/Ransom-EY
Ikarus Trojan-Ransom.Xorist
Jiangmin Trojan/Xorist.js
Webroot W32.Trojan.Ransom
Avira TR/Ransom.Xorist.EJ
MAX malware (ai score=100)
Antiy-AVL Trojan[Ransom]/Win32.Xorist
Microsoft Ransom:Win32/Sorikrypt
Arcabit Trojan.Ransom.AIG
AhnLab-V3 Trojan/Win32.Xorist.R25524
ZoneAlarm Trojan-Ransom.Win32.Xorist.ln
GData Win32.Trojan-Ransom.Xorist.D
Cynet Malicious (score: 100)
TotalDefense Win32/Ransom.A!generic
McAfee Artemis!B3E769EE6F6A
VBA32 Hoax.Xorist
Malwarebytes Ransom.Xorist
Panda Trj/RansomXor.A
TrendMicro-HouseCall Ransom_XORIST.SMA
Rising Ransom.Sorikrypt!8.8822 (CLOUD)
Yandex Trojan.GenAsa!/o0pq2Faa4I
SentinelOne Static AI – Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Xorist.DD8C!tr.ransom
AVG FileRepMalware
Cybereason malicious.e6f6a8
Paloalto generic.ml
MaxSecure Trojan.Malware.121218.susgen

How to remove Win32/Filecoder.Q?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Should I remove “Trojan.Generic.35772264”?

The Trojan.Generic.35772264 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

Malware.AI.988235226 malicious file

The Malware.AI.988235226 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

Malware.AI.2099319323 information

The Malware.AI.2099319323 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Backdoor.GenericFC.S20328115 removal guide

The Backdoor.GenericFC.S20328115 is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

How to remove “PWS:Win32/Lmir.JJ”?

The PWS:Win32/Lmir.JJ is considered dangerous by lots of security experts. When this infection is active,…

58 mins ago

Malware.AI.263066098 malicious file

The Malware.AI.263066098 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago