Malware

What is “Win32/Filecoder.Redeemer.A”?

Malware Removal

The Win32/Filecoder.Redeemer.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.Redeemer.A virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Clears Windows events or logs
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Filecoder.Redeemer.A?


File Info:

name: E0F7C954A4F9610E44A7.mlw
path: /opt/CAPEv2/storage/binaries/dc65677e87876a902d0526bf4d77d7bd1e010988ad7ccbd38e4f35a66ffb29a6
crc32: C560843D
md5: e0f7c954a4f9610e44a7204f66f3e876
sha1: ccb65ef06b1bf4468b184ce863ba264096e9e3ce
sha256: dc65677e87876a902d0526bf4d77d7bd1e010988ad7ccbd38e4f35a66ffb29a6
sha512: 4c859af33aa71184f6db8197f429f3a31acc0235c223f692b8aeb0f0e62332135f7a371b965e92ef57268549c4e61bcc7430420131a009187d17aff7b7c7f144
ssdeep: 24576:SJI+lyaD8bifSARR2ZCjxmKiX5so0f60riuxi2PXPvRu0n1dlSkMGWy/fY:F+lQK1h8K0f0y0/xfP/U0UkIv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B552393AD90CB7AC3242A363473E93153BF4CE65908B66352D43B2B8E71F4A790E553
sha3_384: 54d06513c7ecaec8180b3c2840faff77d9c7f411c176b31871a3cabf02773efa3aaa91ef4ccd717e23ee1564545ed150
ep_bytes: 558bec81ec80010000535633db57895d
timestamp: 2007-03-31 15:09:36

Version Info:

0: [No Data]

Win32/Filecoder.Redeemer.A also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.e0f7c954a4f9610e
ALYacGen:Trojan.Malware.2DW@auloaBci
CylanceUnsafe
VIPREGen:Trojan.Malware.2DW@auloaBci
K7AntiVirusTrojan ( 0057e3f21 )
K7GWTrojan ( 0057e3f21 )
Cybereasonmalicious.4a4f96
CyrenW32/ABRisk.BUGT-2921
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Redeemer.A
APEXMalicious
KasperskyTrojan-Ransom.Win32.Redeemer.d
BitDefenderGen:Trojan.Malware.2DW@auloaBci
NANO-AntivirusTrojan.Win32.DelShad.jptcgz
MicroWorld-eScanGen:Trojan.Malware.2DW@auloaBci
AvastWin32:RansomX-gen [Ransom]
EmsisoftGen:Trojan.Malware.2DW@auloaBci (B)
DrWebTrojan.Siggen18.21892
McAfee-GW-EditionGenericRXRG-MN!54FF306E6683
SophosGeneric ML PUA (PUA)
IkarusTrojan-Ransom.FileCrypter
GDataGen:Trojan.Malware.2DW@auloaBci
JiangminTrojan.DelShad.bzy
AviraTR/FileCoder.hanvs
Antiy-AVLTrojan/Generic.ASMalwS.1D6F
ArcabitTrojan.Malware.ECD332
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Ransomware/Win.Redeemer.C4884098
McAfeeGenericRXRG-MN!54FF306E6683
MAXmalware (ai score=85)
VBA32Trojan.Zpevdo
MalwarebytesRansom.Redeemer
RisingRansom.Agent!8.6B7 (TFE:5:Qq1egkUli7T)
SentinelOneStatic AI – Malicious PE
BitDefenderThetaGen:NN.ZexaE.34606.2DW@auloaBci
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Filecoder.Redeemer.A?

Win32/Filecoder.Redeemer.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment