Malware

MSIL/Filecoder.EvilNominatus.E removal instruction

Malware Removal

The MSIL/Filecoder.EvilNominatus.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.EvilNominatus.E virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Filecoder.EvilNominatus.E?


File Info:

name: BB56E6007B0A2A353D9F.mlw
path: /opt/CAPEv2/storage/binaries/fd742348359c4b18b9754069b37dc4d7e566164a38a420e03a67570368bd5aea
crc32: 0C1C4DF4
md5: bb56e6007b0a2a353d9f1ec2732e9854
sha1: a3c1ab43580101e7916ea0cd8f59addbf6738928
sha256: fd742348359c4b18b9754069b37dc4d7e566164a38a420e03a67570368bd5aea
sha512: 927e7a06f4cc78fca81ae306167a12d44764931c87fe92ee289dc188f0513cd0b6d9fe8c67e03c3a9a732f569ae1a5298dc67c21f389d7e108653daaaa9d5182
ssdeep: 768:QZKIo7Uwx6rsq0+/DZvjjK91+h6iCje1TL:JfP6r8Eju91E6iCjYL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186238E143BFCC71AD1FF9BB9997161504B71F993A861DB4E168011CE1A72B80CA91B73
sha3_384: da10b9a3c274074f733e811e7c440ae59ba6c4754998f83341ac699ddb1c3606f6866a07484a6b3589cbbe5233673395
ep_bytes: ff250020000000000000000000000000
timestamp: 2022-02-17 07:21:10

Version Info:

Translation: 0x0000 0x04b0
FileDescription: TRS
FileVersion: 1.0.8082.42035
InternalName: EvilNominatusCrypto.exe
LegalCopyright: Copyright 2022
OriginalFilename: EvilNominatusCrypto.exe
ProductName: TRS
ProductVersion: 1.0.8082.42035
Assembly Version: 1.0.8082.42035

MSIL/Filecoder.EvilNominatus.E also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.DelShad.4!c
MicroWorld-eScanIL:Trojan.MSILZilla.12204
FireEyeIL:Trojan.MSILZilla.12204
ALYacTrojan.Ransom.Filecoder
MalwarebytesRansom.EvilNominatus
ZillyaTrojan.Filecoder.Win32.22631
SangforRansom.MSIL.NominatusCrypto.PA
K7AntiVirusTrojan ( 0058e7ee1 )
AlibabaRansom:MSIL/NominatusCrypto.9bf303b2
K7GWTrojan ( 0058e7ee1 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Filecoder.EvilNominatus.E
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.DelShad.gen
BitDefenderIL:Trojan.MSILZilla.12204
NANO-AntivirusTrojan.Win32.DelShad.jqhblm
AvastWin32:RansomX-gen [Ransom]
TencentMsil.Trojan.Delshad.Agow
Ad-AwareIL:Trojan.MSILZilla.12204
EmsisoftIL:Trojan.MSILZilla.12204 (B)
F-SecureTrojan.TR/AD.RansomHeur.aexed
DrWebTrojan.Encoder.10598
VIPREIL:Trojan.MSILZilla.12204
McAfee-GW-EditionRDN/Ransom
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataIL:Trojan.MSILZilla.12204
WebrootW32.Ransom.Evilnaminatus
AviraTR/AD.RansomHeur.aexed
Antiy-AVLTrojan/Generic.ASMalwS.67F5
ArcabitIL:Trojan.MSILZilla.D2FAC
ZoneAlarmHEUR:Trojan.MSIL.DelShad.gen
MicrosoftRansom:MSIL/NominatusCrypto.PA!MTB
GoogleDetected
AhnLab-V3Trojan/Win.EvilNominatus.C4926015
McAfeeRDN/Ransom
MAXmalware (ai score=87)
VBA32Trojan.Encoder
CylanceUnsafe
RisingRansom.EvilNominatus!8.136A4 (CLOUD)
YandexTrojan.DelShad!CXTUuVFQGl8
IkarusTrojan-Ransom.Evilnominatus
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.VLA!tr
BitDefenderThetaGen:NN.ZemsilF.34646.dm0@am6gWVi
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Filecoder.EvilNominatus.E?

MSIL/Filecoder.EvilNominatus.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment