FileCoder.BD is a file-encrypting ransomware variant that belongs to the broader FileCoder family of malicious programs designed to lock victims out of their own data. Once it infiltrates a system, this threat systematically encrypts documents, images, databases, and other personal files using strong cryptographic algorithms, then demands payment—typically in cryptocurrency—for the decryption key. Like most modern ransomware, FileCoder.BD doesn't just encrypt files; it often attempts to delete shadow copies and disable system recovery options to prevent victims from restoring their data without paying the ransom.

FileCoder.BD Ransomware — cybersecurity illustration
Photo by Antoni Shkraba on Pexels

This particular variant has been observed targeting both individual users and small business networks, with infections typically resulting from email phishing campaigns, malicious downloads, or exploitation of unpatched software vulnerabilities. The financial and operational impact can be severe, especially for businesses lacking proper backup procedures. Understanding how this ransomware operates and how to respond is critical for anyone who suspects an infection or wants to protect their systems from this persistent threat.

Think you're infected right now? Immediately disconnect from your network (unplug Ethernet, disable Wi-Fi) to prevent the ransomware from spreading to other machines or network shares. Do NOT attempt to restart your computer or delete files randomly—you may destroy forensic evidence or damage recovery options. Call us at (770) 637-1435 for emergency assistance. Our technicians can assess the damage, attempt recovery options, and prevent further encryption while the threat is still active.

Threat Profile

AttributeDetails
Threat TypeRansomware (file encryptor)
FamilyFileCoder family
Variant Designation.BD (multiple sub-variants exist)
PlatformWindows (XP through 11, primarily targeting 7/10/11)
Encryption AlgorithmTypically AES-256 or RSA-2048 (varies by sub-variant)
File Extension AddedVaries by version; common extensions include .locked, .coded, .encrypted, or custom alphanumeric strings
Ransom Note FilenameVaries; commonly README.txt, HOW_TO_DECRYPT.html, or RECOVERY_INSTRUCTIONS.txt
Distribution MethodsPhishing emails, malicious email attachments, exploit kits, RDP brute-force, drive-by downloads
Persistence MechanismRegistry Run keys, scheduled tasks, startup folder entries
CapabilitiesFile encryption, shadow copy deletion, process termination (database/backup software), network enumeration
Network BehaviorMay attempt lateral movement on local networks; contacts command-and-control servers for key exchange
Typical Ransom Demand$300–$1,500 USD equivalent in Bitcoin or other cryptocurrency (varies by target)
Removal DifficultyModerate (the malware itself can be removed, but file decryption without the key is typically impossible)

How It Spreads

FileCoder.BD primarily reaches victims through social engineering tactics combined with technical exploitation. The most common infection vector is phishing emails crafted to appear legitimate—invoices from vendors, shipping notifications, tax documents, or urgent security alerts from well-known companies. These emails contain either malicious attachments (often disguised as PDFs or Word documents with macros) or links to compromised websites hosting exploit kits that silently install the ransomware when visited.

Beyond email, this ransomware has been distributed through malicious advertising (malvertising) on legitimate websites, bundled with pirated software or key generators downloaded from file-sharing sites, and through exploitation of unpatched vulnerabilities in common software like Adobe Reader, Java, or Flash Player. Some variants have been observed spreading through compromised Remote Desktop Protocol (RDP) connections, where attackers use brute-force attacks or stolen credentials to gain access to business networks and manually deploy the ransomware across multiple machines.

Common distribution methods include:

  • Phishing email attachments — malicious Office documents with macro scripts, or JavaScript files disguised as invoices/receipts
  • Malicious links in emails or text messages — directing users to exploit kit landing pages or direct downloads
  • Drive-by downloads — automatic downloads triggered by visiting compromised legitimate websites
  • Software bundling — packaged with free software installers, especially from unofficial download sites
  • RDP exploitation — attackers gaining access through weak or default passwords on exposed RDP ports
  • Malvertising — malicious advertisements on otherwise legitimate websites that redirect to exploit kits
  • Fake software updates — disguised as Flash Player updates, codec installers, or system utilities

What It Does On Your Machine

Upon execution, FileCoder.BD typically begins by establishing persistence to ensure it can complete its encryption routine even if the system is restarted. It creates registry entries in the Windows Run keys and may install a scheduled task to maintain its presence. The malware often performs an initial system survey, checking for security software that might interfere with its operation and attempting to terminate processes associated with antivirus programs, backup software, and database applications that might keep files locked and unavailable for encryption.

The ransomware then methodically scans all accessible drives—including local hard drives, external USB drives, mapped network shares, and cloud storage folders synced to the local system. It targets specific file types based on an internal list that typically includes documents, spreadsheets, databases, images, videos, archives, and source code files. As it encrypts each file using strong cryptographic algorithms, it often renames them with a unique extension and creates ransom notes in each affected directory. The encryption process is designed to be fast enough to complete before users notice, but selective enough to avoid encrypting system files that would prevent Windows from booting (which would prevent victims from accessing the ransom note and payment instructions).

To maximize leverage over victims, FileCoder.BD variants commonly attempt to delete Windows Shadow Copies using commands similar to `vssadmin Delete Shadows /All /Quiet`, preventing easy recovery through built-in Windows restore functionality. Some versions also search for and disable Windows Startup Repair features and clear system restore points. The ransomware may display a full-screen ransom note immediately after completing encryption, or it may operate silently and only reveal itself when users attempt to open their now-encrypted files.

Typical filesystem artifacts and commands (example paths)
C:\Users\[Username]\AppData\Local\Temp\[random].exe ← Initial dropper location C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sysupdate.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run → "SystemUpdate" = "C:\Users\[Username]\AppData\Roaming\sysupdate.exe" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run → "CryptoLocker" = "C:\ProgramData\[GUID]\encrypt.exe" vssadmin.exe Delete Shadows /All /Quiet ← Deletes shadow copies wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0 ← Removes Windows backup catalog bcdedit /set {default} recoveryenabled No ← Disables recovery mode Desktop, Documents, Downloads (all directories): README_TO_DECRYPT.txt All encrypted files: filename.ext.locked or filename.ext.[random-ID]

Manual Removal — Step by Step

01

Isolate the Infected System Immediately

Disconnect the computer from all networks by unplugging the Ethernet cable and disabling Wi-Fi. This prevents the ransomware from spreading to other machines on your network or encrypting files on mapped network drives. Do not skip this step—many ransomware variants actively seek out network shares and will continue encrypting accessible files as long as network connectivity exists. If you're dealing with a business network, consider shutting down file servers until the infection is contained.

02

Boot into Safe Mode with Networking

Restart your computer and repeatedly press F8 during boot (on Windows 7) or use the advanced startup options (Windows 10/11: hold Shift while clicking Restart, then navigate to Troubleshoot > Advanced Options > Startup Settings > Restart > press 4 or F4). Safe Mode loads only essential Windows components, which prevents most malware from loading automatically. Select "Safe Mode with Networking" so you can download tools and updates if needed, but remember to keep the Ethernet cable unplugged initially until you've completed the next steps.

03

Identify and Terminate Malicious Processes

Press Ctrl+Shift+Esc to open Task Manager. Look for suspicious processes—unfamiliar names, processes running from Temp directories or AppData folders, or executables with random character names. Note the file location of any suspicious process (right-click > Open File Location), then right-click the process and select End Task. Be cautious not to terminate critical Windows processes. If you're unsure, write down the process name and location but wait to terminate it until you're certain it's malicious.

04

Remove Persistence Mechanisms

Press Windows+R, type msconfig, and press Enter. Go to the Startup tab (or in Windows 10/11, it will direct you to Task Manager's Startup tab). Disable any suspicious startup entries. Next, press Windows+R again, type regedit, and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Look for entries pointing to suspicious executable files in AppData, ProgramData, or Temp folders, and delete those entries. Also check Task Scheduler (type taskschd.msc in Windows+R) for suspicious scheduled tasks and delete them.

05

Delete the Malware Executable and Associated Folders

Navigate to the file locations you identified in Step 3. Common locations include %TEMP%, %APPDATA%, %LOCALAPPDATA%, and %PROGRAMDATA% folders. Delete the entire folder containing the ransomware executable. You may need to enable viewing of hidden files and folders (File Explorer > View > Options > Change folder and search options > View tab > Show hidden files, folders, and drives). Empty the Recycle Bin afterward. Some variants create randomly-named folders with GUIDs—delete these entire directories.

06

Run Comprehensive Anti-Malware Scans

Download and install Malwarebytes (free version is sufficient) from a clean computer if possible, transfer it via USB drive, and install it in Safe Mode. Run a full system scan—this may take one to three hours depending on your drive size. After Malwarebytes completes, also run a scan with your primary antivirus software (updated to the latest definitions). Consider running a second-opinion scanner like HitmanPro or Emsisoft Emergency Kit. Quarantine or delete all detected threats. These tools may find remnants or additional components that manual removal missed.

07

Restore System Settings and Check for Decryption Options

If the ransomware disabled Windows Defender or System Restore, re-enable them through Windows Security settings and System Properties. Visit the "No More Ransom" project website (from a different, clean device) to see if a free decryption tool exists for your specific FileCoder variant—identifying features include the ransom note wording and the file extension added to encrypted files. Apply any available decryptor according to its instructions. Be aware that for most modern ransomware variants, no decryption tool exists, and encrypted files can only be recovered from backups.

08

Reset Web Browsers to Default Settings

While FileCoder.BD primarily focuses on file encryption, some variants may install browser extensions or modify settings. Open each installed browser (Chrome, Firefox, Edge) and reset it to default settings. In Chrome: Settings > Advanced > Reset settings. In Firefox: Help > More troubleshooting information > Refresh Firefox. In Edge: Settings > Reset settings. This removes any potentially malicious extensions and clears cached data that might harbor remnants of the infection.

09

Change All Passwords from a Clean Device

Assume that any passwords entered while the system was infected may have been compromised. From a known-clean computer or smartphone, change passwords for all important accounts—email, banking, cloud storage, social media, and any work-related systems. Enable two-factor authentication wherever possible. If the infected computer was used for business purposes, notify your IT department or security team immediately so they can assess whether additional accounts or systems were compromised.

10

Reboot Normally and Monitor System Behavior

Restart your computer in normal mode and observe its behavior for several hours. Check that no suspicious processes reappear in Task Manager, verify that startup items remain clean, and confirm that no new files are being encrypted. Run another quick scan with Malwarebytes. If everything appears clean and stable for 24-48 hours, you can cautiously begin restoring data from clean backups. Scan any restored files with antivirus software before opening them. Consider creating a full system image backup of the cleaned system before reconnecting to your network.

Prevention

  1. Maintain regular, offline backups — Follow the 3-2-1 rule: three copies of your data, on two different media types, with one copy stored offline or offsite. Disconnect external backup drives immediately after backing up. Cloud backups are helpful but insufficient alone, as some ransomware can encrypt cloud-synced folders.
  2. Keep all software updated and patched — Enable automatic updates for Windows, your web browser, Java, Adobe Reader, and all other installed software. Most ransomware infections exploit known vulnerabilities that have available patches. Remove software you don't regularly use, especially outdated plugins like Flash Player or old versions of Java.
  3. Deploy comprehensive security software — Use reputable antivirus/anti-malware software with real-time protection enabled. Consider solutions that include behavior-based detection and ransomware-specific shields. Windows Defender (now Microsoft Defender) has improved significantly and includes Controlled Folder Access, which can prevent unauthorized applications from modifying protected folders.
  4. Exercise extreme caution with email attachments and links — Never open attachments or click links from unknown senders. Even if an email appears to come from someone you know, verify legitimacy through a separate communication channel if the message is unexpected. Be especially suspicious of Office documents that prompt you to "Enable Macros" or "Enable Editing"—legitimate documents rarely require this.
  5. Disable macros in Office applications by default — In Word, Excel, and PowerPoint, go to File > Options > Trust Center > Trust Center Settings > Macro Settings, and select "Disable all macros with notification." Only enable macros for documents from verified, trusted sources, and only when absolutely necessary.
  6. Limit user account privileges — Use a standard user account for daily activities rather than an administrator account. Ransomware running under a limited user account has restricted ability to modify system settings, install itself persistently, or access files belonging to other users. Create administrator accounts only for software installation and system maintenance.
  7. Secure Remote Desktop Protocol access — If you use RDP, never expose it directly to the internet. Use a VPN for remote access instead. If RDP must be internet-facing, require strong passwords (minimum 15 characters with complexity), enable Network Level Authentication, implement account lockout policies, and use non-standard ports combined with IP address whitelisting.
  8. Train all users on security awareness — For businesses, regular security training is essential. Employees should understand common phishing tactics, know how to verify email sender authenticity, recognize social engineering attempts, and understand whom to contact if they suspect a security incident. Conduct periodic simulated phishing tests to reinforce training.
Our 90-Day Warranty — When Computer Repair Roswell removes ransomware or any other malware from your system, we back our work with a comprehensive 90-day warranty. If the same infection returns within that period, we'll remove it again at no additional charge. We also provide guidance on backup strategies and preventive measures tailored to your specific situation, whether you're protecting a home computer or a small business network.

Bring It In

Dealing with ransomware is stressful, especially when important files, family photos, or business documents are locked away behind encryption you can't break. While the manual removal steps above can eliminate the malware itself, they don't address the critical question of data recovery—and attempting recovery incorrectly can permanently destroy your chances of getting files back. Our technicians at Computer Repair Roswell have experience with various ransomware families, access to specialized recovery tools, and the expertise to determine whether decryption is possible for your specific variant. We can also examine your backup situation and, in some cases, recover files from shadow copies or other sources you might not know exist.

We're located right here in Roswell at 1662 Mulkey Road, Suite D, and we're ready to help. Call us at (770) 637-1435 to discuss your situation—if you're currently dealing with an active infection, we can prioritize your case and often accommodate same-day service. For business infections or situations where multiple computers are affected, we offer on-site service to contain the spread and minimize downtime. Don't pay the ransom without exploring all legitimate recovery options first—bring your computer in or give us a call, and let's see what we can recover together.