Malware

MSIL/Filecoder.PadCrypt.F information

Malware Removal

The MSIL/Filecoder.PadCrypt.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.PadCrypt.F virus can do?

    How to determine MSIL/Filecoder.PadCrypt.F?

    
    

    File Info:

    crc32: 08F291DC
    md5: 671bef81158df7f25422a1b8bf381aae
    name: 671BEF81158DF7F25422A1B8BF381AAE.mlw
    sha1: bf7be06e4c507d47192afa7e5eb71429b95db2dd
    sha256: 8cd3c876217a3f7a3026a6fd9ca4a41d140d764b2a5a122e4c08fb8561b528d7
    sha512: 68100df87af4d687dd8e71d29f76f7c40e8da4c505045a4dcc5cd880203820b935f9cf360ddfd50c6af8457fe8f593c51c737de2b2dfe9a362d4f9085cebd661
    ssdeep: 12288:ILCMimNzfwSk1fIZp8NBo4UgxDASDcuXL3PIItJ:cIp1c8NBolgBdDfb3
    type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

    Version Info:

    Translation: 0x0000 0x04b0
    LegalCopyright: Copyright xa9 2016
    Assembly Version: 11.37.0.0
    InternalName: ptsks.exe
    FileVersion: 11.37.0.0
    CompanyName: Microsoft Corporation
    LegalTrademarks:
    Comments:
    ProductName: Microsoft
    ProductVersion: 11.37.0.0
    FileDescription: Windows Driver Service
    OriginalFilename: ptsks.exe

    MSIL/Filecoder.PadCrypt.F also known as:

    K7AntiVirusTrojan ( 700000121 )
    Elasticmalicious (high confidence)
    DrWebTrojan.DownLoader24.10310
    CynetMalicious (score: 90)
    ALYacTrojan.Ransom.PadCrypt
    CylanceUnsafe
    ZillyaTrojan.Filecoder.Win32.7573
    SangforTrojan.Win32.Save.a
    CrowdStrikewin/malicious_confidence_100% (W)
    AlibabaTrojan:MSIL/Filecoder.0f537a77
    K7GWTrojan ( 700000121 )
    Cybereasonmalicious.1158df
    SymantecRansom.PadCrypt
    ESET-NOD32a variant of MSIL/Filecoder.PadCrypt.F
    APEXMalicious
    AvastMSIL:Ransom-N [Trj]
    KasperskyHEUR:Trojan.Win32.Generic
    BitDefenderGen:Variant.Ransom.PadCrypt.14
    NANO-AntivirusTrojan.Win32.Filecoder.engpph
    SUPERAntiSpywareRansom.Cryptor/Variant
    MicroWorld-eScanGen:Variant.Ransom.PadCrypt.14
    TencentMalware.Win32.Gencirc.10bc01a3
    Ad-AwareGen:Variant.Ransom.PadCrypt.14
    SophosML/PE-A
    ComodoMalware@#3q3nu8evhz12u
    BitDefenderThetaGen:NN.ZemsilF.34608.Rn0@aScl!oi
    VIPRETrojan.Win32.Generic!BT
    TrendMicroRansom_CRYDAP.SMQ
    McAfee-GW-EditionGenericRXBC-MI!671BEF81158D
    FireEyeGeneric.mg.671bef81158df7f2
    EmsisoftGen:Variant.Ransom.PadCrypt.14 (B)
    WebrootW32.Ransomware.Gen
    AviraTR/FileCoder.bzuyf
    eGambitUnsafe.AI_Score_99%
    MicrosoftTrojan:Win32/Skeeyah.A!rfn
    AegisLabTrojan.Win32.Generic.4!c
    GDataGen:Variant.Ransom.PadCrypt.14
    AhnLab-V3Trojan/Win32.Dynamer.C1879386
    McAfeeGenericRXBC-MI!671BEF81158D
    MAXmalware (ai score=100)
    VBA32TScope.Trojan.MSIL
    MalwarebytesTrojan.Dropper
    PandaTrj/GdSda.A
    TrendMicro-HouseCallRansom_CRYDAP.SMQ
    RisingRansom.FileCryptor!8.1A7 (CLOUD)
    YandexTrojan.Agent!wNcfgF3Lh1k
    SentinelOneStatic AI – Malicious PE
    FortinetMSIL/Generic.AP.9D47C!tr
    AVGMSIL:Ransom-N [Trj]
    Paloaltogeneric.ml
    Qihoo-360Win32/Ransom.Filecoder.HwMAevkA

    How to remove MSIL/Filecoder.PadCrypt.F?

    MSIL/Filecoder.PadCrypt.F removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment