Malware

MSIL/Filecoder.AMJ malicious file

Malware Removal

The MSIL/Filecoder.AMJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.AMJ virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Filecoder.AMJ?


File Info:

name: BD4B01C3F6443A851E39.mlw
path: /opt/CAPEv2/storage/binaries/67f73519708d76c7c7b1a748af3808698bc104a0c459f8b197c1c150e5181d68
crc32: 96678D53
md5: bd4b01c3f6443a851e39f226cc7ec6fb
sha1: de7d79e141ea0f2905df2369df8ad819f450a713
sha256: 67f73519708d76c7c7b1a748af3808698bc104a0c459f8b197c1c150e5181d68
sha512: 92d3bee076d032ba7b3331a639d16550c5e351ee200fe135a756913b555babc76b7a9a2d5cfee6417293277af0063c0c209891e62b56fab499f62d004fac4a85
ssdeep: 384:gA6V/KaqKsWMCaeSCzhihc51rcj5Us6vCIXYQPhYVDrgHa/Dw1Im7HPxGZ7XSj9j:gTHzM1Qhihc51f2Kwk1IGpG89yW4xW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B823920227E64114F5B64A35AD76C2300B37BD59AE32C62E15CCAD8F3BB7B144D92B63
sha3_384: 720a76b0043a5df401369f60adcbeffed4d4250baa91018b766b635d4fe778e40be9030d017c4a310f87856e1bd889b7
ep_bytes: ff250020400000000000000000000000
timestamp: 2076-10-28 23:57:48

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ruby
FileVersion: 3.0.0.0
InternalName: ruby.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: ruby.exe
ProductName: ruby
ProductVersion: 3.0.0.0
Assembly Version: 3.0.0.0

MSIL/Filecoder.AMJ also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.10519
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacIL:Trojan.MSILZilla.10519
CylanceUnsafe
K7AntiVirusTrojan ( 0058a1241 )
K7GWTrojan ( 0058a1241 )
ESET-NOD32MSIL/Filecoder.AMJ
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderIL:Trojan.MSILZilla.10519
AvastWin32:Malware-gen
Ad-AwareIL:Trojan.MSILZilla.10519
DrWebTrojan.Hosts.48820
FireEyeGeneric.mg.bd4b01c3f6443a85
EmsisoftIL:Trojan.MSILZilla.10519 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.MSIL.bybu
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.34D6802
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitIL:Trojan.MSILZilla.D2917
GDataIL:Trojan.MSILZilla.10519
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Malware-gen.C4657579
McAfeeGenericRXAA-FA!BD4B01C3F644
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.PasswordStealer
TencentMalware.Win32.Gencirc.10cf8c18
YandexTrojan.Filecoder!caIyKU9t5hg
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.UH!tr
BitDefenderThetaGen:NN.ZemsilF.34294.dm1@aWOPkNo
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove MSIL/Filecoder.AMJ?

MSIL/Filecoder.AMJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment