Malware

Win32:Filecoder-AZ [Trj] information

Malware Removal

The Win32:Filecoder-AZ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Filecoder-AZ [Trj] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to remove evidence of file being downloaded from the Internet
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32:Filecoder-AZ [Trj]?


File Info:

crc32: B9B67423
md5: 60e2b87cfa88b07af531b4bb69e836c1
name: 60E2B87CFA88B07AF531B4BB69E836C1.mlw
sha1: cd3adedaec225d283344571de5c23e93d0e5d880
sha256: 57a02907d2e5732a09fb0b921d42697e00340c5d2888bc43571deaa4eba346f7
sha512: dbdc8b76ead674b27bbbc23d9b3a377dc45ca997d5d24f1088603c49db3b534d1133ae0fe597765c138a14698e5d53fe62197f958f94252d7725668c89554eeb
ssdeep: 1536:CnnnnZkb5J2nnnnoMX7KrpH2LRidC222D:TJ2G52gdC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:Filecoder-AZ [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005137001 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Sphinx.2
CynetMalicious (score: 100)
CAT-QuickHealRansom.Exxroute.A3
ALYacTrojan.GenericKDZ.38167
CylanceUnsafe
ZillyaTrojan.Spora.Win32.217
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Spora.6442362f
K7GWTrojan ( 005137001 )
Cybereasonmalicious.cfa88b
CyrenW32/Spora.D.gen!Eldorado
SymantecPacked.Generic.493
ESET-NOD32Win32/Filecoder.Spora.A
APEXMalicious
AvastWin32:Filecoder-AZ [Trj]
ClamAVWin.Ransomware.Cerber-6162277-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.38167
NANO-AntivirusTrojan.Win32.Kryptik.emagvd
MicroWorld-eScanTrojan.GenericKDZ.38167
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKDZ.38167
SophosMal/Generic-R + Mal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Satbrop.A@70jw07
BitDefenderThetaGen:NN.ZexaF.34628.emW@aWfOkipi
TrendMicroRansom_SPORA.F117C1
McAfee-GW-EditionBehavesLike.Win32.Generic.kh
FireEyeGeneric.mg.60e2b87cfa88b07a
EmsisoftTrojan.GenericKDZ.38167 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Spora.ez
WebrootTrojan.Dropper.Ransom.Gen
AviraHEUR/AGEN.1116787
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Spora.A
ArcabitTrojan.Generic.D9517
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.GenericKDZ.38167
AhnLab-V3Trojan/Win32.Cerber.R196098
Acronissuspicious
McAfeeRansomware-FMJ!60E2B87CFA88
MAXmalware (ai score=86)
VBA32Hoax.Gen
MalwarebytesTrojan.Ursnif
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_SPORA.F117C1
RisingTrojan.Kryptik!1.AF4D (CLOUD)
IkarusTrojan.Dalexis
FortinetW32/GenKryptik.CRPN!tr
AVGWin32:Filecoder-AZ [Trj]
Qihoo-360Win32/Ransom.Filecoder.HxQB8aQA

How to remove Win32:Filecoder-AZ [Trj]?

Win32:Filecoder-AZ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment