Ransom

About “Ransom:MSIL/FileCoder.AF!MTB” infection

Malware Removal

The Ransom:MSIL/FileCoder.AF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/FileCoder.AF!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Ransom:MSIL/FileCoder.AF!MTB?


File Info:

name: 5B1DE907E275300FFD9A.mlw
path: /opt/CAPEv2/storage/binaries/69bb81a8ff5522fddfa253b908babcb1d7b745fd2bc70e5cb85f38ee7ce24a1d
crc32: 31EC89AC
md5: 5b1de907e275300ffd9a931cf42d0e36
sha1: 89298fb65ea248a672656aa2b9830c3c76005b61
sha256: 69bb81a8ff5522fddfa253b908babcb1d7b745fd2bc70e5cb85f38ee7ce24a1d
sha512: 44acece4676d89500601894d984e797d802d2fd10c58d78bb93c92902884b9740fadcee1be4472395448f2be81bbf98971fbeb82e515aa0b130240ec64c21c43
ssdeep: 192:nSKrOKcn6Mtp6SnYJ/07a0aGi4N/qjkGyyLi9y8stYcFwVc03KY:ntrOd6Mtp6Swqi4NSjXyy29yptYcFwVY
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AC32D700A3E44531D9F726B62E76D245C735FBA75C269BAE388C911F2F7114287237B2
sha3_384: ad5370d1f8ee3ffac3f45d78df5e3742e5901ac2d6cf8ed3f09f847a261e86c8da623f57c0c7e905407dc9ff178be2db
ep_bytes: ff250020400000000000000000000000
timestamp: 2085-08-18 19:41:13

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ConsoleApp1
FileVersion: 1.0.0.0
InternalName: ConsoleApp1.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: ConsoleApp1.exe
ProductName: ConsoleApp1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ransom:MSIL/FileCoder.AF!MTB also known as:

LionicTrojan.MSIL.Encoder.j!c
MicroWorld-eScanTrojan.GenericKD.47610830
FireEyeTrojan.GenericKD.47610830
ALYacTrojan.GenericKD.47610830
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.21115
SangforRansom.MSIL.Encoder.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/FileCoder.f54a6aaf
K7GWTrojan ( 0058ba3f1 )
K7AntiVirusTrojan ( 0058ba3f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.ANC
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan-Ransom.MSIL.Encoder.gen
BitDefenderTrojan.GenericKD.47610830
TencentMsil.Trojan.Encoder.Svht
Ad-AwareTrojan.GenericKD.47610830
SophosMal/Generic-S
DrWebTrojan.Encoder.34700
TrendMicroRansom_Encoder.R06BC0PLC21
McAfee-GW-EditionRDN/Generic.cf
EmsisoftTrojan.GenericKD.47610830 (B)
Paloaltogeneric.ml
GDataTrojan.GenericKD.47610830
Antiy-AVLTrojan/Generic.ASMalwS.34EA9FE
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D67BCE
MicrosoftRansom:MSIL/FileCoder.AF!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4842023
McAfeeRDN/Generic.cf
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.Viper
TrendMicro-HouseCallRansom_Encoder.R06BC0PLC21
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Filecoder.ANC!tr.ransom
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A

How to remove Ransom:MSIL/FileCoder.AF!MTB?

Ransom:MSIL/FileCoder.AF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment