Malware

MSIL/Filecoder.AMT malicious file

Malware Removal

The MSIL/Filecoder.AMT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.AMT virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Filecoder.AMT?


File Info:

name: 42B34DD53BB36F601794.mlw
path: /opt/CAPEv2/storage/binaries/789f1c44d5665aaaae41cee1c9d4847b3f1c71bd420fc18af1cbed507d6149ff
crc32: 5799878E
md5: 42b34dd53bb36f60179474f258b81a4d
sha1: 6c8df43fd2c73c5069711da4cd87664e0679db7a
sha256: 789f1c44d5665aaaae41cee1c9d4847b3f1c71bd420fc18af1cbed507d6149ff
sha512: ffc5ace05d83c15bbc32fd3042d92206ae667e354b7c3884097092f7fbcd9cd60a5c8e56683ee063a63e95b8f4f193f2c3004a2ef207f94d79dd328fcdfaaacc
ssdeep: 768:AGipya+FD/Qi/amh83IWGRgYHegiMgYd2bYcr2:tipeR5/pW3RUdHeCdd2L2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14E031B5967A42427C63F40B944162380CF719F97B155EBEC3CAF305A6FB6B09431ABA3
sha3_384: 1ff43fe5cc1333564ce22219ed869394d800196471cdbbc092b80992f811682a2128492e1f6675d5ec4ad53dd990fa6a
ep_bytes: ff250020400000000000000000000000
timestamp: 2090-03-31 01:21:01

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WS32Locker
FileVersion: 1.0.0.0
InternalName: WS32Locker.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: WS32Locker.exe
ProductName: WS32Locker
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Filecoder.AMT also known as:

MicroWorld-eScanTrojan.GenericKD.38121501
FireEyeTrojan.GenericKD.38121501
ALYacTrojan.GenericKD.38121501
ZillyaTrojan.Filecoder.Win32.20785
AlibabaTrojan:MSIL/Filecoder.53dbd75d
ArcabitTrojan.Generic.D245B01D
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AMT
TrendMicro-HouseCallTROJ_GEN.R002H0AKK21
BitDefenderTrojan.GenericKD.38121501
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKD.38121501
EmsisoftTrojan.GenericKD.38121501 (B)
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1132606
MAXmalware (ai score=82)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.38121501
CynetMalicious (score: 99)
McAfeeArtemis!42B34DD53BB3
APEXMalicious
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/Filecoder.AMT!tr
AVGWin32:MalwareX-gen [Trj]

How to remove MSIL/Filecoder.AMT?

MSIL/Filecoder.AMT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment