Malware

What is “MSIL/Filecoder.IV”?

Malware Removal

The MSIL/Filecoder.IV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.IV virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/Filecoder.IV?


File Info:

name: 367FE1C9582E752FE1E4.mlw
path: /opt/CAPEv2/storage/binaries/836356bf6ed464026561c2e3e1ab466a8830600328a2150937d835d94f83203b
crc32: 039A652F
md5: 367fe1c9582e752fe1e4021771ad6bb5
sha1: 0b6d6ca0ce728ed7deac49e37e0ce82da4c573dd
sha256: 836356bf6ed464026561c2e3e1ab466a8830600328a2150937d835d94f83203b
sha512: 873246f2d020a562ff5c7f8a22c3c1c11c3983abe614f9563b37514d0176a2fc2196d00317ff71ccd62d1cbfae063df7ce641d25e340b1f308175a0cc4e578b0
ssdeep: 3072:zQNxADg4ASBlpAMnr2m14jhW+8A/sYd3d7rA:z49SBlpAMaLQnosYd3dX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9B349D633E4AA63C34D5B35A1F213003B3AE1757B22E7474988513EACAF3D6AD49487
sha3_384: 66016e690b0ba5b6aa8c038601d0e4999b2f8d4d6bd8c20a3d452126b1dfae7733cb5706edff8cf0b7fcddef20b2b8b9
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-04-10 14:32:08

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Locker
FileVersion: 1.0.0.0
InternalName: Locker.exe
LegalCopyright: Copyright © 2017
LegalTrademarks:
OriginalFilename: Locker.exe
ProductName: Locker
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Filecoder.IV also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!367FE1C9582E
CylanceUnsafe
SangforTrojan.Win32.Gen.usrg
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRansom:Win32/Filecoder.9217d384
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9582e7
BitDefenderThetaGen:NN.ZemsilF.34646.gm0@aSF4Cjh
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.IV
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Gen.dnf
NANO-AntivirusTrojan.Win32.Fuery.eoqvpv
CynetMalicious (score: 99)
AvastWin32:Malware-gen
TencentWin32.Trojan.Gen.Hajl
SophosMal/Generic-S
ComodoMalware@#1h4nz69yelq3a
F-SecureHeuristic.HEUR/AGEN.1218045
DrWebTrojan.DownLoader25.11796
ZillyaTrojan.Gen.Win32.1212
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
APEXMalicious
JiangminTrojan.Gen.jj
AviraHEUR/AGEN.1218045
Antiy-AVLTrojan/Generic.ASMalwS.4A94
MicrosoftRansom:Win32/Genasom
ZoneAlarmTrojan-Ransom.Win32.Gen.dnf
GoogleDetected
MAXmalware (ai score=100)
RisingRansom.Locker!1.AC6C (CLASSIC)
IkarusTrojan-Ransom.Rokku
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gen.DNF!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove MSIL/Filecoder.IV?

MSIL/Filecoder.IV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment