Malware

suspected of Corrupted.Win32File.ILE malicious file

Malware Removal

The suspected of Corrupted.Win32File.ILE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What suspected of Corrupted.Win32File.ILE virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine suspected of Corrupted.Win32File.ILE?


File Info:

crc32: 68F08691
md5: 8cc16a6c72ce4a912b691c3a2308ba90
name: ob1.exe
sha1: 1d5ca0deae3725a17b9a15aa53cfa0d9d4bee8d6
sha256: 5684d58f646514c245099fbbc1fe9a13261e8feb09569c28a5ff800bf5f12e13
sha512: fee7fea10ecbc7df68c2477408c1afe8b5e1834d94f70b4a37fcb71d20426d2512a6895ffb84b310b6c56251e554e8cb22602c8b743f6db9318cbef235fbbda1
ssdeep: 12288:otuYzj5RYMFFzpR6tGncr/4zG+XJK3eJm3htKYBWU:oEYz1RYsFitGncrARZK3eJGL8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

suspected of Corrupted.Win32File.ILE also known as:

DrWebTrojan.PWS.Siggen2.43763
MicroWorld-eScanTrojan.GenericKD.33294240
CAT-QuickHealTrojan.Multi
McAfeeArtemis!8CC16A6C72CE
ALYacTrojan.GenericKD.33294240
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33294240
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.eae372
TrendMicroTROJ_GEN.R057C0GBQ20
BitDefenderThetaGen:NN.ZexaF.34108.6qW@aGI7cRd
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R057C0GBQ20
AvastWin32:Malware-gen
ClamAVWin.Malware.Ulise-7344017-0
GDataWin32.Trojan.Raccoon.A
KasperskyHEUR:Trojan-PSW.Win32.Racealer.vho
AlibabaTrojanPSW:Win32/Racealer.b33e342f
NANO-AntivirusTrojan.Win32.Racealer.hbexzt
AegisLabTrojan.Multi.Generic.4!c
RisingStealer.Raccoon!1.BD9D (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33294240 (B)
F-SecureHeuristic.HEUR/AGEN.1127993
ZillyaTrojan.Agent.Win32.1297961
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.8cc16a6c72ce4a91
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
CyrenW32/Trojan.YELJ-3968
JiangminTrojan.PSW.Racealer.abp
MaxSecureTrojan.Malware.1728101.susgen
AviraHEUR/AGEN.1127993
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D1FC07A0
ZoneAlarmHEUR:Trojan-PSW.Win32.Racealer.vho
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Detplock.R331727
Acronissuspicious
VBA32suspected of Corrupted.Win32File.ILE
MAXmalware (ai score=83)
Ad-AwareTrojan.GenericKD.33294240
MalwarebytesSpyware.RaccoonStealer
PandaTrj/CI.A
APEXMalicious
ESET-NOD32Win32/Spy.Agent.PQZ
TencentWin32.Trojan-qqpass.Qqrob.Eerh
YandexTrojanSpy.Agent!7PctGO7lMD8
SentinelOneDFI – Malicious PE
FortinetW32/Racealer.DEO!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.PSW.81f

How to remove suspected of Corrupted.Win32File.ILE?

suspected of Corrupted.Win32File.ILE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment