Malware

About “MSILPerseus.123117” infection

Malware Removal

The MSILPerseus.123117 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.123117 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Unusual version info supplied for binary

How to determine MSILPerseus.123117?


File Info:

name: DEBF6511FB1893DF7CBF.mlw
path: /opt/CAPEv2/storage/binaries/aea204524cfc84bbfd5846689a8e1b649dfbede2aae62e16ae60f905728da9af
crc32: 8A5F364A
md5: debf6511fb1893df7cbfd099df51257d
sha1: 79e84f63bf47a3bc263f10d91dd61c2d76471b5d
sha256: aea204524cfc84bbfd5846689a8e1b649dfbede2aae62e16ae60f905728da9af
sha512: 8223f64154c5baffd81ab914801050e3025bfc7802403c9a95f3ac4790f36986638c8ce21e34ec611fbcf183956e0481ac4a3f0903e6c85e05f2e56a93d48389
ssdeep: 1536:8u2r35lD1L533BbW3vwdWU+xVfc/E0SHOm7YK/pu4VauV1SV/SPjJ:72r35hTywdWLTfayOm0KRukao1SVcj
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13393E10457E89A3AC9294970E89792D02FBADD54CD3B074F27E8FA1E3E367A44442369
sha3_384: 7e190d37e68c437409973aac467ae49980cb54624bb083e078524193eb3e2fcbe156d6d4e8eea506303931128f7d6f2a
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-11-03 12:26:35

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows Defender Status Monitor
CompanyName: Mircosoft Corporation
FileDescription: Windows Defender Status Monitor
FileVersion: 1.0.0.0
InternalName: Windows Defender.exe
LegalCopyright: Copyright © Mircosoft Corporation 2010
OriginalFilename: Windows Defender.exe
ProductName: Windows Defender Status Monitor
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSILPerseus.123117 also known as:

LionicTrojan.Multi.Generic.4!c
ALYacGen:Variant.MSILPerseus.123117
SangforTrojan.MSIL.Agent.OFX
K7AntiVirusTrojan ( 0055e3e71 )
BitDefenderGen:Variant.MSILPerseus.123117
K7GWTrojan ( 0055e3e71 )
Cybereasonmalicious.1fb189
ArcabitTrojan.MSILPerseus.D1E0ED
BaiduMSIL.Trojan.Agent.bm
VirITTrojan.Win32.FakeAV.AJHY
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32MSIL/Agent.OFX
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.RiskGen.dkmoxc
MicroWorld-eScanGen:Variant.MSILPerseus.123117
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:ViXjrUz19kfXZWj+vUPs3g)
Ad-AwareGen:Variant.MSILPerseus.123117
EmsisoftGen:Variant.MSILPerseus.123117 (B)
F-SecureHeuristic.HEUR/AGEN.1241308
McAfee-GW-EditionGenericRXCV-JC!DEBF6511FB18
FireEyeGen:Variant.MSILPerseus.123117
SophosMal/MSIL-HL
IkarusTrojan.MSIL.Agent
JiangminTrojan.Generic.cvrnh
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1241308
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.MSILPerseus.123117
AhnLab-V3Trojan/Win32.Agent.R243232
McAfeeGenericRXCV-JC!DEBF6511FB18
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
YandexTrojan.Agent!qRXyFzb3+Ro
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Generic.DN.436636!tr
BitDefenderThetaGen:NN.ZemsilF.34638.fq0@auo5jOb
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove MSILPerseus.123117?

MSILPerseus.123117 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment