Ransom

Ransom:MSIL/FileCoder!MTB (file analysis)

Malware Removal

The Ransom:MSIL/FileCoder!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/FileCoder!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom:MSIL/FileCoder!MTB?


File Info:

crc32: A1052392
md5: 68e79d26e4276efb489cfe9f297b92a3
name: 68E79D26E4276EFB489CFE9F297B92A3.mlw
sha1: f6ca84c12b4af6106dac8dfe2372cc6729c75e98
sha256: b621f1f8982275608b48ba66fb69fdc6a1dfd9292b9725daf5f45b25493c4680
sha512: eba96b499ec1da15db5e60b3f4c4bdd1ff50f0a3bf2930fc7dd930fda7bffeb17923ac993ca25ba63c58bb2e46ab357212f1d8077de02f4eb6fa95667294b001
ssdeep: 768:n+JdkR7l/NWmbrbAHFJ073Ypeori9HNKHa:cWJ/fbrbo073YIoW9HNKHa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: ENVY-6542B-54.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: ENVY-6542B-54.exe

Ransom:MSIL/FileCoder!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.559943
FireEyeGeneric.mg.68e79d26e4276efb
CAT-QuickHealTrojan.MSIL
Qihoo-360Generic/Trojan.21a
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1681725
AegisLabTrojan.MSIL.Crypt.4!c
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Razy.559943
K7GWTrojan ( 700000121 )
Cybereasonmalicious.6e4276
CyrenW32/Azorult.D.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Ursu-9802322-0
KasperskyHEUR:Trojan-Ransom.MSIL.Gen.gen
AlibabaRansom:MSIL/FileCoder.c33e29b8
ViRobotTrojan.Win32.S.Ransom.32768
TencentMsil.Trojan.Gen.Wsap
Ad-AwareGen:Variant.Razy.559943
EmsisoftGen:Variant.Razy.559943 (B)
ComodoMalware@#1iikh6t2sr3cb
F-SecureHeuristic.HEUR/AGEN.1129970
DrWebTrojan.MulDrop11.26182
TrendMicroRansom_FileCoder.R002C0DAH21
McAfee-GW-EditionBehavesLike.Win32.Trojan.nm
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
JiangminTrojan.MSIL.tvkc
AviraHEUR/AGEN.1129970
MAXmalware (ai score=99)
Antiy-AVLTrojan[Ransom]/MSIL.BlackHeart
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:MSIL/FileCoder!MTB
GridinsoftRansom.Filecoder.B.vl!yf
ArcabitTrojan.Razy.D88B47
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
GDataGen:Variant.Razy.559943
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C3477542
McAfeeRansomware-FTD!68E79D26E427
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.Crimson
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Agent.TET
TrendMicro-HouseCallRansom_FileCoder.R002C0DAH21
RisingRansom.Epsilon!1.D178 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Agent.TET!tr
BitDefenderThetaGen:NN.ZemsilF.34780.cm0@aqg2KOc
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:MSIL/FileCoder!MTB?

Ransom:MSIL/FileCoder!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment