Malware

What is “MSIL/Filecoder.YQ”?

Malware Removal

The MSIL/Filecoder.YQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Filecoder.YQ virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine MSIL/Filecoder.YQ?


File Info:

crc32: 34FCFCD6
md5: ef6ffe7dcf8b03bc45f0c5db2e8b5efd
name: EF6FFE7DCF8B03BC45F0C5DB2E8B5EFD.mlw
sha1: d6256c0adba4c2afae4ddf42b6a05942e483589c
sha256: 935faf22f44af34fc970f49b16d29cb336918c121c3ca2c7bd3a1cf89dc642d1
sha512: 8dfc3532421d6460a1fed2fbde6f533fd61c4ba835851cfe042b72ecc107cc659fcbebbb2d08c5e4b7edc78dddff3a477776669a09447908fb792c15e608b5db
ssdeep: 49152:dwBA9vgGXN8X/aZ0hZm1pDycxh0oSkDbZm1HtZSAtE:dOogG+rZmbDyyjDbZmgAt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: fuck rats antivirus.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: fuck rats antivirus
ProductVersion: 1.0.0.0
FileDescription: fuck rats antivirus
OriginalFilename: fuck rats antivirus.exe

MSIL/Filecoder.YQ also known as:

MicroWorld-eScanGen:Heur.Ransom.RTH.1
FireEyeGen:Heur.Ransom.RTH.1
MalwarebytesMachineLearning/Anomalous.97%
SangforTrojan.Win32.Save.a
BitDefenderGen:Heur.Ransom.RTH.1
BitDefenderThetaGen:NN.ZemsilF.34608.Xn0@aCK82Hb
APEXMalicious
AvastWin32:Trojan-gen
Ad-AwareGen:Heur.Ransom.RTH.1
SophosMal/DotNet-L
EmsisoftGen:Heur.Ransom.RTH.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Ransom.RTH.1
MAXmalware (ai score=81)
ArcabitTrojan.Ransom.RTH.1
ESET-NOD32a variant of MSIL/Filecoder.YQ
ALYacGen:Heur.Ransom.RTH.1
AVGWin32:Trojan-gen
Cybereasonmalicious.dcf8b0

How to remove MSIL/Filecoder.YQ?

MSIL/Filecoder.YQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment