Malware

MSIL/Filecoder.AOH removal instruction

Malware Removal

The MSIL/Filecoder.AOH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.AOH virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Filecoder.AOH?


File Info:

name: 2CF67758FF8E234ACCB1.mlw
path: /opt/CAPEv2/storage/binaries/2bfab47ab5a0bb105285e07a5bc823709cf3e76e41edc5d75465d49eb83a7226
crc32: B417A300
md5: 2cf67758ff8e234accb1e549cd79820a
sha1: b6c2b5ab485e8f2c8830f3ef147c0c969814f4a9
sha256: 2bfab47ab5a0bb105285e07a5bc823709cf3e76e41edc5d75465d49eb83a7226
sha512: e546066886e0d966e519b2f4306b81a7db71808cdf9c198be87315ae0548cf4e24d5fef41b41d8ecfc33a280e216733e2c009d1a5213d606c5284293a32cd00d
ssdeep: 384:LLptNq6PzjfGLptNq6PzjfGLptNq6PzjfGLptNq6PzjfGLptNq6Pzjf:LLZbjfGLZbjfGLZbjfGLZbjfGLZbjf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B933E81C63E8C625F5BE477A5D7222816370F5839C3A876F218A631B3E3179489D3F62
sha3_384: 3d0b62236e0a8f4ba4daccf4e894980a180c5b67370c3f19bd477584c94826598f7e5a18f92d049d28717742b7c12e32
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-11 07:20:07

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Virus.win32RozbehStrike
FileVersion: 1.0.8076.42003
InternalName: Virus.win32RozbehStrike.exe
LegalCopyright: Copyright 2022
OriginalFilename: Virus.win32RozbehStrike.exe
ProductName: Virus.win32RozbehStrike
ProductVersion: 1.0.8076.42003
Assembly Version: 1.0.8076.42003

MSIL/Filecoder.AOH also known as:

LionicRiskware.Win32.Malicious.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38951292
FireEyeGeneric.mg.2cf67758ff8e234a
McAfeeGenericRXRT-NV!2CF67758FF8E
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058e5021 )
K7GWTrojan ( 0058e5021 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AOH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
BitDefenderTrojan.GenericKD.38951292
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKD.38951292
EmsisoftTrojan.GenericKD.38951292 (B)
DrWebTrojan.Encoder.34949
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
GDataTrojan.GenericKD.38951292
AviraTR/Ransom.vmqwh
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.352B99E
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D252597C
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Encoder.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4968345
BitDefenderThetaGen:NN.ZemsilF.34212.dm3@aS@50wo
ALYacTrojan.GenericKD.38951292
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MultiDropper
TrendMicro-HouseCallTROJ_GEN.R002H0CBE22
RisingTrojan.Generic/MSIL@AI.91 (RDM.MSIL:2m7P2CGMJtNzVSjbHzappQ)
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Filecoder.AOH!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.b485e8
PandaTrj/CI.A

How to remove MSIL/Filecoder.AOH?

MSIL/Filecoder.AOH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment