Malware

Should I remove “MSIL/ShellcodeRunner.AF”?

Malware Removal

The MSIL/ShellcodeRunner.AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/ShellcodeRunner.AF virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine MSIL/ShellcodeRunner.AF?


File Info:

name: 506CDD482DEC20A02D46.mlw
path: /opt/CAPEv2/storage/binaries/d6ea0390c0d1e4336e20f3a8f9596cd5c654089111f24e7841ce82f624be1454
crc32: 10DFB92D
md5: 506cdd482dec20a02d469da0b5b39ecb
sha1: 0cad824a036521a3c55bdd484b9119179115f7b3
sha256: d6ea0390c0d1e4336e20f3a8f9596cd5c654089111f24e7841ce82f624be1454
sha512: 6bb71af4c397c477b4cc26dade658c00667aa0a4a9e3e3eeb3b0e687ef7a353e915c38e3296f80bc7d512ed3ce19ab66bfcf5da69a30293af06f6cd90b7c8427
ssdeep: 192:eO6lQpN96sMPYhyFDOehUnI/bQ0K9DXVc03KYO:/gQpNdehUIa9LVc03KN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11572BC4301EE222FE4F71FB39BF1B5E9C3DBE1A5582A29FD208815860B12D54DA33576
sha3_384: 45e3a056072dc34e26e0e111b7952111b3849c34e3a0abb67e46be6f712badff29bd12987c2d50971e6e3618d0957af8
ep_bytes: ff25b84c400000000000000000008c4c
timestamp: 2022-07-31 13:47:21

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.7.0
InternalName: Client.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Client.exe
ProductName:
ProductVersion: 1.0.7.0
Assembly Version: 1.0.7.0

MSIL/ShellcodeRunner.AF also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.61115787
ALYacTrojan.GenericKD.61115787
VIPRETrojan.GenericKD.61115787
SangforSuspicious.Win32.Save.a
AlibabaTrojan:MSIL/ShellcodeRunner.c8dd4fe2
Cybereasonmalicious.a03652
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ShellcodeRunner.AF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Enigmaprotector-9874743-0
BitDefenderTrojan.GenericKD.61115787
AvastWin32:BackdoorX-gen [Trj]
Ad-AwareTrojan.GenericKD.61115787
EmsisoftTrojan.GenericKD.61115787 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.lt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.506cdd482dec20a0
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.61115787
AviraTR/Redcap.eroix
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.5B67
ArcabitTrojan.Generic.D3A48D8B
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!506CDD482DEC
MalwarebytesBackdoor.Agent.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002H0CH222
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:yevRDH3RHIlmnLmBMwFviA)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Rozena.T!tr
BitDefenderThetaGen:NN.ZemsilF.34582.bm0@aOe3VVe
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/Chgt.AD
CrowdStrikewin/malicious_confidence_70% (W)

How to remove MSIL/ShellcodeRunner.AF?

MSIL/ShellcodeRunner.AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment