Malware

MSILPerseus.121013 malicious file

Malware Removal

The MSILPerseus.121013 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.121013 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
fbchat.sytes.net

How to determine MSILPerseus.121013?


File Info:

crc32: EB58D6A2
md5: e89e082796d4bef783b44c0fcf635a59
name: E89E082796D4BEF783B44C0FCF635A59.mlw
sha1: 718b4a58ce7acf00fe69591e9139d95607e2cb1b
sha256: de4e3ce0935eba94b056ab83d07aa72b3f2db8cb933806e9fb88040d57265a48
sha512: 8dbeb155ecc24a79b471c9f1989dd5b8357695bc0b42fb0f721c87b93fe796e51fd542330bf198b672e40ada20e1b95f0e641b6d19984f9d7fb587d606ff3844
ssdeep: 6144:9F6Mg+NB07CA8mKDg2UHSalio2pB5mNNzAm59AeE260UIIPhcRZ8wibK1bXX:9FgNj8PDOyAio2pQNkeE2uZ5C
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Microsof t Corpora tion .
FileDescription: Offline Files Migration Plugins.
Translation: 0x0415 0x04e4

MSILPerseus.121013 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.121013
FireEyeGeneric.mg.e89e082796d4bef7
ALYacGen:Variant.MSILPerseus.121013
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00496bd51 )
BitDefenderGen:Variant.MSILPerseus.121013
K7GWTrojan ( 00496bd51 )
Cybereasonmalicious.796d4b
BitDefenderThetaGen:NN.ZemsilF.34804.xm0@aiCZDSjG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.DBI
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Llac.eupyun
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Generic.Also
Ad-AwareGen:Variant.MSILPerseus.121013
EmsisoftGen:Variant.MSILPerseus.121013 (B)
ComodoMalware@#1nigf7w5hd0v6
F-SecurePacked:MSIL/SmartIL.A
DrWebTrojan.DownLoader9.710
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.eqn
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftVirTool:MSIL/Injector
ArcabitTrojan.MSILPerseus.D1D8B5
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.MSILPerseus.121013
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E89E082796D4
VBA32Trojan.Downloader
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
RisingTrojan.Injector!8.C4 (CLOUD)
IkarusBackdoor.Win32.DarkKomet
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.DBI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSILPerseus.121013?

MSILPerseus.121013 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment