Malware

Should I remove “MSIL/Filecoder.Fantom.D”?

Malware Removal

The MSIL/Filecoder.Fantom.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.Fantom.D virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Filecoder.Fantom.D?


File Info:

crc32: 62B8BA0F
md5: da5051d98b6a7dd94b5ad6a9b7c1040e
name: DA5051D98B6A7DD94B5AD6A9B7C1040E.mlw
sha1: ee32ab775675a3b302139de56ecd56ee307e4f2e
sha256: cbb37b3d057e07c7329f16e1be13044015adf048c42d28d121e3bccbe229bb48
sha512: 328ab9a8a5a1495333e23eeb75001d9a64771ca9b045a68c0cc4a4daef089e693080d527f810181b1d6083bba419e4d7cb9c15e5bdb58742cf9e5b69aa703013
ssdeep: 384:rH9ofHmZnschWN63+Ka3b+ZNLpvp8BTNrvBPEZS5hoXjKZ4ECXETyWPWuou:jhW8O7LoR8F1JnkoxX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright Claster xa9 2016
Assembly Version: 2.3.0.2
InternalName: sombrd.exe
FileVersion: 2.3.0.2
CompanyName: Claster
LegalTrademarks: Zolder corporation xa9
Comments: hiro
ProductName: genetic 32ty
ProductVersion: 2.3.0.2
FileDescription: Zolder hiro
OriginalFilename: sombrd.exe

MSIL/Filecoder.Fantom.D also known as:

K7AntiVirusTrojan ( 00501a5e1 )
LionicTrojan.Win32.Diztakun.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.13062
ALYacGen:Heur.Ransom.RTH.1
CylanceUnsafe
ZillyaTrojan.Diztakun.Win32.3284
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 00501a5e1 )
Cybereasonmalicious.98b6a7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.Fantom.D
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Diztakun.aubg
BitDefenderGen:Heur.Ransom.RTH.1
NANO-AntivirusTrojan.Win32.Diztakun.ekoode
MicroWorld-eScanGen:Heur.Ransom.RTH.1
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Heur.Ransom.RTH.1
SophosTroj/Fantom-D
BitDefenderThetaGen:NN.ZemsilF.34110.bm0@amdHL9d
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_FANTOMCRYPT.F117AH
McAfee-GW-EditionGeneric.awh
FireEyeGeneric.mg.da5051d98b6a7dd9
EmsisoftGen:Heur.Ransom.RTH.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Diztakun.bxj
WebrootW32.Trojan.Gen]
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASMalwS.1E2CDE0
MicrosoftRansom:Win32/Avaddon.P!MSR
ArcabitTrojan.Ransom.RTH.1
GDataGen:Heur.Ransom.RTH.1
McAfeeGeneric.awh
MAXmalware (ai score=80)
VBA32Trojan.Diztakun
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_FANTOMCRYPT.F117AH
IkarusTrojan.MSIL.Filecoder
FortinetW32/Diztakun.AUBG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Filecoder.Fantom.D?

MSIL/Filecoder.Fantom.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment