Malware

MSIL/Filecoder.ATX removal instruction

Malware Removal

The MSIL/Filecoder.ATX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.ATX virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Chaos malware family

How to determine MSIL/Filecoder.ATX?


File Info:

name: A6B9B1AAD31145F93E2A.mlw
path: /opt/CAPEv2/storage/binaries/87a9a8afbead2e58521d8db46d50ef5f008c28227ca908676d1b8d05e6c6109d
crc32: 58170415
md5: a6b9b1aad31145f93e2af7e6dfc9cec6
sha1: cac5d7866d2ad707eb019eebb20f682219d5fc38
sha256: 87a9a8afbead2e58521d8db46d50ef5f008c28227ca908676d1b8d05e6c6109d
sha512: 7110fc2d6b629cf6bc755d915c515841a570ee520a55d2f314cb8467fd6abd4fbf64c5e9f7cc7bdd3240a324e7b66f3b2d6259417ffc480978dc10741bdf85cf
ssdeep: 12288:X7dXLnDymw67o6c80IhHaV0h4v5f/us3GDiICQRmgUOBalZb:L8KQ0hlMQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T129943B343AFB5019B273EFA55FE4B9ABDA6FF7333606A45D1041034A0623941DED263A
sha3_384: 482e8c645037990abee6116dd232e91524c245f7b98e35999d1a06c5611e6ad8f55a862b858704ed0b23cb233bb691a8
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-07-29 04:17:02

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Server.exe
LegalCopyright:
OriginalFilename: Server.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/Filecoder.ATX also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.24983
FireEyeGeneric.mg.a6b9b1aad31145f9
MalwarebytesNeshta.Virus.FileInfector.DDS
SangforRansom.Win32.Save.a
K7AntiVirusRansomware ( 005a8b921 )
BitDefenderIL:Trojan.MSILZilla.24983
K7GWRansomware ( 005a8b921 )
Cybereasonmalicious.ad3114
CyrenW32/S-ee2ef6fa!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Filecoder.ATX
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Hydracrypt-9878672-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
TencentTrojan-Ransom.Win32.Agent.16000623
SophosTroj/Ransom-GUR
DrWebTrojan.Encoder.35905
TrendMicroRansom.MSIL.CHAOS.SMRA14
McAfee-GW-EditionBehavesLike.Win32.Generic.gt
Trapminemalicious.high.ml.score
EmsisoftIL:Trojan.MSILZilla.24983 (B)
GDataIL:Trojan.MSILZilla.24983
GoogleDetected
ArcabitIL:Trojan.MSILZilla.D6197
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:MSIL/Filecoder.PK!MSR
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.FTD.C4597900
Acronissuspicious
VBA32Trojan.MSIL.DelShad.Heur
MAXmalware (ai score=88)
Cylanceunsafe
APEXMalicious
RisingRansom.Destructor!1.B060 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Encoder.4D0C!tr.ransom
BitDefenderThetaAI:Packer.39984F921F
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MSIL/Filecoder.ATX?

MSIL/Filecoder.ATX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment