Malware

Win32/Filecoder.XRatLocker.A removal tips

Malware Removal

The Win32/Filecoder.XRatLocker.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Filecoder.XRatLocker.A virus can do?

  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Filecoder.XRatLocker.A?


File Info:

crc32: DF639D36
md5: 7a89699117938390874f658556d4d808
name: 7A89699117938390874F658556D4D808.mlw
sha1: 531afda0f5c839795909e7bf0b7c083b23f7654a
sha256: 75a9c6108cdee4faebeb882aa1d535ca03a0c75034e1e7f4d8ddc4c8e5bca416
sha512: eeda480c3b977ea9be999e6b8c339a67cc60c0d945b485a49ee0be0844c41716bec83922426693ad18275d49dbcb75fd5e8c672836c0813642ce84b0fdda1dc0
ssdeep: 24576:Bm4hcuoNvTg5Xk1ABXeSdeZrKuhfD8q6xMpDCiiYUMa:BmPLhf16xMpDCiiYU
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Filecoder.XRatLocker.A also known as:

K7AntiVirusTrojan ( 004f9af11 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.6333
ALYacTrojan.Patched.SAP.Gen
CylanceUnsafe
ZillyaTrojan.Xpan.Win32.4
AlibabaRansom:Win32/XRatLocker.cf35451c
K7GWTrojan ( 004f9af11 )
Cybereasonmalicious.117938
SymantecRansom.Xpan
ESET-NOD32Win32/Filecoder.XRatLocker.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Xpan.a
BitDefenderTrojan.Patched.SAP.Gen
NANO-AntivirusTrojan.Win32.Xpan.egpctb
MicroWorld-eScanTrojan.Patched.SAP.Gen
TencentTrojan-Ransom.Win32.XratLocker.a
Ad-AwareTrojan.Patched.SAP.Gen
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34126.GLW@a85SaDi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-PFQ!7A8969911793
FireEyeGeneric.mg.7a89699117938390
EmsisoftTrojan.Patched.SAP.Gen (B)
JiangminTrojan.Xpan.a
Antiy-AVLTrojan/Generic.ASMalwS.1BE2D7E
MicrosoftRansom:Win32/Xpan.A
ArcabitTrojan.Patched.SAP.Gen
ZoneAlarmTrojan-Ransom.Win32.Xpan.a
GDataTrojan.Patched.SAP.Gen
McAfeeGenericR-PFQ!7A8969911793
MAXmalware (ai score=88)
VBA32Hoax.Xpan
PandaTrj/Ransom.CD
YandexTrojan.GenAsa!5Mpmstx0OeQ
IkarusTrojan-Ransom.Xratlocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/XRatLocker.A!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Filecoder.XRatLocker.A?

Win32/Filecoder.XRatLocker.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment