Malware

About “MSIL/Filecoder.AP” infection

Malware Removal

The MSIL/Filecoder.AP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.AP virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

router.bittorrent.com
router.utorrent.com
bench.utorrent.com

How to determine MSIL/Filecoder.AP?


File Info:

crc32: A4DE3148
md5: 3a37931a0c7f2c8ec5c38b04380c69e1
name: 3A37931A0C7F2C8EC5C38B04380C69E1.mlw
sha1: 61ac0d9783a744dfc02f4b6dd880c82e24a274b0
sha256: c71c26bf894feb5dbedb2cf2477258f3edf3133a3c22c68ab378ba65ecf251d3
sha512: 9be09704ae50a657793ddee577e69967483858aa42c92eb3403c79a195c2d11a6f84f274cb6c5e8e357b9e8627ae347d9a11a39d1549a15690765dcf1f3579da
ssdeep: 49152:Ga8FL30rOQwir2OUXnfgwHrTi4UtqaAR1hbpTye21OR+jFlpuEKD:GaSL3KvSRnfX6qa61FdaOR6lpm
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Filecoder.AP also known as:

K7AntiVirusTrojan ( 004dc8531 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.AVKill.61261
CynetMalicious (score: 100)
CAT-QuickHealRansom.CryptoHost.A3
ALYacGen:Trojan.Mardom.MN.21
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.2294
SangforRansom.MSIL.Manamecrypt.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/Manamecrypt.49135452
K7GWTrojan ( 004dc8531 )
Cybereasonmalicious.a0c7f2
SymantecRansom.CryptoHost
ESET-NOD32MSIL/Filecoder.AP
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Mardom.MN.21
NANO-AntivirusTrojan.Win32.Filecoder.eajarw
MicroWorld-eScanGen:Trojan.Mardom.MN.21
TencentWin32.Trojan.Generic.Ljud
Ad-AwareGen:Trojan.Mardom.MN.21
SophosML/PE-A + Troj/Ransom-CWK
ComodoTrojWare.MSIL.Agent.GLE@6facx5
BitDefenderThetaGen:NN.ZemsilF.34266.zoY@aywevmm
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTOHOST.A
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.3a37931a0c7f2c8e
EmsisoftGen:Trojan.Mardom.MN.21 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.qptp
WebrootW32.Malware.Gen
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.171A5FC
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:MSIL/Manamecrypt.A
GDataGen:Trojan.Mardom.MN.21
McAfeeArtemis!3A37931A0C7F
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CRYPTOHOST.A
YandexTrojan.Agent!djlZsy21yGg
IkarusTrojan.MSIL.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.YII!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Filecoder.AP?

MSIL/Filecoder.AP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment