Ransom

Should I remove “MSIL/Filecoder.iRansom.A”?

Malware Removal

The MSIL/Filecoder.iRansom.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.iRansom.A virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Filecoder.iRansom.A?


File Info:

crc32: 6DA28159
md5: e1dc6a8b67b88c90719d27ecbbb24e64
name: E1DC6A8B67B88C90719D27ECBBB24E64.mlw
sha1: 5976b95372e54f6f5d3db68cb132a2718ff46141
sha256: 31975b3176e5f3994aa70c28109a3e33aba6346bc3c0de872d1551b55ec4a7bf
sha512: 06e384039385aa41bea967b1b6ee5b8cbb5828e156ba30631c38faaf48c3398c1a1f71d94e512ec855f4a33186e48ed50231eb604b903b82c63edd84008f6217
ssdeep: 1536:UFzlKcgPmUEVWIp+0JBjutLETFdkP4TMUz:UecgKoIpPJBjutLETFdkP4TMU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: iRansom.exe
FileVersion: 1.0.0.0
ProductName: iRansom
ProductVersion: 1.0.0.0
FileDescription: iRansom
OriginalFilename: iRansom.exe

MSIL/Filecoder.iRansom.A also known as:

K7AntiVirusTrojan ( 005159d71 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.13953
ALYacTrojan.Ransom.iRansom
CylanceUnsafe
K7GWTrojan ( 005159d71 )
Cybereasonmalicious.b67b88
SymantecRansom.Cryptolocker
ESET-NOD32a variant of MSIL/Filecoder.iRansom.A
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Razy-7602351-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.12203751
NANO-AntivirusTrojan.Win32.Encoder.esgnxo
MicroWorld-eScanTrojan.GenericKD.12203751
TencentWin32.Trojan.Generic.Akoy
Ad-AwareTrojan.GenericKD.12203751
SophosMal/Generic-R + Troj/iLocked-A
ComodoMalware@#f8c253upa5qj
BitDefenderThetaGen:NN.ZemsilF.34142.gm0@a8Dju6i
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_ILOCKED.B
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e1dc6a8b67b88c90
EmsisoftTrojan.Ransom.iRansom (A)
SentinelOneStatic AI – Malicious PE
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.12203751
McAfeeArtemis!E1DC6A8B67B8
MAXmalware (ai score=100)
VBA32CIL.HeapOverride.Heur
PandaTrj/CI.A
TrendMicro-HouseCallRansom_ILOCKED.B
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetGenerik.ELGPJBF!tr
AVGWin32:Malware-gen

How to remove MSIL/Filecoder.iRansom.A?

MSIL/Filecoder.iRansom.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment