Malware

Should I remove “Application.MSILPerseus.176664 (B)”?

Malware Removal

The Application.MSILPerseus.176664 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.MSILPerseus.176664 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Application.MSILPerseus.176664 (B)?


File Info:

name: 9BD1426358162414F6F6.mlw
path: /opt/CAPEv2/storage/binaries/1d525689c7c1246c0dec43834ed3d6d1a2c914f3d6d25b0a064df1b81669ee84
crc32: FF57FD7A
md5: 9bd1426358162414f6f60f7ef850cb0d
sha1: b5d62250614a9f3ae6f9e6fe1f42f05afac2c66f
sha256: 1d525689c7c1246c0dec43834ed3d6d1a2c914f3d6d25b0a064df1b81669ee84
sha512: c076688d141368ba4e32c455b6d99583a1e0a3c52683e822d0eb1f8bcb64d42178f9c8ba06b25fb61a28236a5a29247aa50239cac626b2e61c344223281a2c9c
ssdeep: 24576:5Q9EkcWo+u88frZwO4v1P4KWmPTLpeDkQWf1l:5GUWoZ88DZ92PomLLcGf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C625231661C97DA9D578037A7BB34BD2C7BACC1E8520EA5BA0D41EE9DC3E14339113E2
sha3_384: ce9e031405f72c4b55abf1857cdc83e5a912fb88ca04c23238a2a1ac2183097b7be2715cb9e7d27cea2f3f427b32b054
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-08-19 16:01:09

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: Tanılama Sorun Giderme Sihirbazı.exe
LegalCopyright: Copyright © 2018
OriginalFilename: Tanılama Sorun Giderme Sihirbazı.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Application.MSILPerseus.176664 (B) also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.9bd1426358162414
ALYacGen:Variant.Application.MSILPerseus.176664
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0054594c1 )
AlibabaTrojan:MSIL/Kryptik.2ce04b96
K7GWTrojan ( 0054594c1 )
Cybereasonmalicious.358162
CyrenW32/MSIL_Perseus.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QNZ
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Application.MSILPerseus.176664
MicroWorld-eScanGen:Variant.Application.MSILPerseus.176664
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Application.MSILPerseus.176664
SophosMal/Generic-S
DrWebTrojan.Hosts.45237
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKJ21
McAfee-GW-EditionRDN/Generic BackDoor
EmsisoftGen:Variant.Application.MSILPerseus.176664 (B)
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Application.MSILPerseus.176664
AviraHEUR/AGEN.1202938
ViRobotTrojan.Win32.Z.Kryptik.969216.T
MicrosoftBackdoor:Win32/Bladabindi!ml
AhnLab-V3Trojan/Win32.Agent.R237649
McAfeeRDN/Generic BackDoor
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002C0PKJ21
YandexTrojan.Hosts!nBTpB9AutAw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34084.7m0@aurlE7g
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Application.MSILPerseus.176664 (B)?

Application.MSILPerseus.176664 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment