Malware

MSIL/Filecoder.RB malicious file

Malware Removal

The MSIL/Filecoder.RB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.RB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/Filecoder.RB?


File Info:

crc32: CC8EC3FA
md5: c40ef72fe9ac1ffda0495112fbe71425
name: C40EF72FE9AC1FFDA0495112FBE71425.mlw
sha1: 4aa07f7203a230627ec5b0386ffc24d8072ac854
sha256: e7ba542b73af0fdf306992ea0d423754826f0151eabd4e0a21a6471637334361
sha512: e96db30447eb7c7a2add94237e524cd9f5a1318317ef3b3227647689582fe681bdcc538a9d4875d9f71397e85087fb7a6b5b67f1cd4dfaafeef8fd0af4d21d8f
ssdeep: 6144:m/fAhvV6B8ErzPZp5wdz753RSriX+tGrUHy9aVqA+Vw4:mfAv6B8azBwdmiX+tGAHc3e4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL/Filecoder.RB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00544f8f1 )
DrWebTrojan.MulDrop11.21259
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.MSIL.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:MSIL/Filecoder.4ebc598b
K7GWTrojan ( 00544f8f1 )
Cybereasonmalicious.fe9ac1
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Filecoder.RB
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Uztuby-6815912-0
KasperskyUDS:Trojan-Ransom.MSIL.Gen.gen
BitDefenderGen:Heur.Ransom.MSIL.1
NANO-AntivirusTrojan.Win32.Ransom.fmelme
MicroWorld-eScanGen:Heur.Ransom.MSIL.1
SophosMal/Generic-S
ComodoMalware@#2izup5o3gu2t9
BitDefenderThetaGen:NN.ZemsilF.34738.bm0@a4Bd17j
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fc
FireEyeGeneric.mg.c40ef72fe9ac1ffd
EmsisoftTrojan.FileCoder (A)
SentinelOneStatic AI – Suspicious PE
AviraTR/Agent.qmuak
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.331F68F
MicrosoftRansom:MSIL/Gansom.AA!MSR
ArcabitTrojan.Ransom.MSIL.1
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Gen.gen
GDataGen:Heur.Ransom.MSIL.1
AhnLab-V3Malware/Win32.Generic.C3535328
McAfeeArtemis!C40EF72FE9AC
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
IkarusTrojan.MSIL.BadJoke
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Filecoder.RB?

MSIL/Filecoder.RB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment