Fake

MSIL/Hoax.FakeFilecoder.DU (file analysis)

Malware Removal

The MSIL/Hoax.FakeFilecoder.DU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Hoax.FakeFilecoder.DU virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine MSIL/Hoax.FakeFilecoder.DU?


File Info:

crc32: ECB0BFEF
md5: 0ea7a32007ed03fc767e4d01a521d919
name: danger.exe
sha1: 0fa89a1309e533cc24f1a9903d372ecebd01b319
sha256: 6171323b3420d533b5855f71dda960f47c32c7bf5f0bbb5f6912f35253715fcc
sha512: 5074a1f132015eb412b073837def2175941c995a38ad4b2c2db61c36944f61eeeb86c564d88f0137ffa46ee70e43a7e61bc1326c4adb8018020ddd4f5e1eb57b
ssdeep: 1536:VLHXkF7kbtXwxc+ILHXkFwystUlmFrsNGq/afp3oGLHXkF:pH0F78N2DgH0FwZgraCOH0F
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: WindowsApplication1.exe
FileVersion: 1.0.0.0
Comments: File Encryption
ProductName: John's Ransomware
ProductVersion: 1.0.0.0
FileDescription: John's Ransomware
OriginalFilename: WindowsApplication1.exe

MSIL/Hoax.FakeFilecoder.DU also known as:

MicroWorld-eScanTrojan.GenericKD.6032295
FireEyeTrojan.GenericKD.6032295
McAfeeRansom-JLocker!0EA7A32007ED
CylanceUnsafe
VIPREHoax.Win32.FakeRansom (not malicious)
AegisLabHacktool.Win32.Generic.3!c
SangforMalware
K7AntiVirusTrojan ( 005440141 )
BitDefenderTrojan.GenericKD.6032295
K7GWTrojan ( 005440141 )
Cybereasonmalicious.007ed0
TrendMicroTROJ_GEN.R06BC0PG620
SymantecTrojan.Gen
APEXMalicious
GDataTrojan.GenericKD.6032295
KasperskyHEUR:Hoax.Win32.Generic
AlibabaHoax:MSIL/FakeFilecoder.fd6bb9cb
NANO-AntivirusRiskware.Win32.FakeRansom.etcqwh
ViRobotTrojan.Win32.S.Ransom.1164288
RisingHoax.FakeRansom!8.EC4D (CLOUD)
Ad-AwareTrojan.GenericKD.6032295
EmsisoftTrojan.GenericKD.6032295 (B)
ComodoMalware@#3zwe96ob076j
F-SecureTrojan.TR/Redcap.iirhk
ZillyaTrojan.GenericKD.Win32.86622
Trapminesuspicious.low.ml.score
SophosGeneric PUA AP (PUA)
IkarusTrojan-Ransom.Hoax.John
JiangminHoax.FakeRansom.c
MaxSecureTrojan.Malware.10685503.susgen
AviraTR/Redcap.iirhk
MAXmalware (ai score=100)
Antiy-AVLHackTool[Hoax]/Win32.FakeRansom
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D5C0BA7
ZoneAlarmHEUR:Hoax.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.FakeRansom.C2185538
BitDefenderThetaGen:NN.ZemsilF.34132.hr0@aWNAi3o
ALYacTrojan.Ransom.JohnsLocker
TACHYONJoke/W32.DN-FakeRansom.1164288
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
ESET-NOD32MSIL/Hoax.FakeFilecoder.DU
TrendMicro-HouseCallTROJ_GEN.R06BC0PG620
TencentMalware.Win32.Gencirc.114d8314
YandexHoax.FakeFilecoder!
FortinetRiskware/FakeRansom
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Hoax.9ba

How to remove MSIL/Hoax.FakeFilecoder.DU?

MSIL/Hoax.FakeFilecoder.DU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment