Malware

How to remove “MSILPerseus.132493”?

Malware Removal

The MSILPerseus.132493 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.132493 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Sniffs keystrokes
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine MSILPerseus.132493?


File Info:

name: 2B687904E27EB4C1F9DF.mlw
path: /opt/CAPEv2/storage/binaries/6f32fdc86140a84cea018e08359afc2d2fed27bfc0066185aaf39425b3a4721e
crc32: DDC18C2D
md5: 2b687904e27eb4c1f9dfed6b37446957
sha1: c154c551c79ce3a728699aceb6145c4feee60f53
sha256: 6f32fdc86140a84cea018e08359afc2d2fed27bfc0066185aaf39425b3a4721e
sha512: 4cb2ac9589f3c1b84e6e64c0beb9c0c434c079e4754bd6e856aab21d69c4c314e610452a8d22cb1cedf6aeac8a5905405268432fe99d6d53aa315edd729c081b
ssdeep: 1536:w1xclhthuTQJGbXSbFPxYUXI15KEu4C8+UWuNp6SNzbTAbiJyDHJ8SE:wjkhthuTOJPxpXI15KEu4CRUW8pHNzbJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18EA3D76DE29A0F71DF9C123048A61A15E33284579243F73F509D06E029B3FDA5B5E8EB
sha3_384: f8f28bc0b1d88e592367cbbe86745681d24c533f99c81f24cb8c29563d1032c10cb98e513f15d5c9f62c3b91ca9657f8
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-11-27 09:45:09

Version Info:

0: [No Data]

MSILPerseus.132493 also known as:

BkavW32.AIDetectNet.01
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.MSILPerseus.132493
FireEyeGeneric.mg.2b687904e27eb4c1
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004754a11 )
K7GWTrojan ( 004754a11 )
Cybereasonmalicious.4e27eb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Autorun.Agent.BW
APEXMalicious
ClamAVWin.Packed.Barys-7008062-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILPerseus.132493
AvastWin32:WormX-gen [Wrm]
Ad-AwareGen:Variant.MSILPerseus.132493
SophosML/PE-A
DrWebTrojan.MulDrop20.15452
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.MSILPerseus.132493 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILPerseus.132493
AviraTR/Spy.Gen
ArcabitTrojan.MSILPerseus.D2058D
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Spyware/Win.Generic.C5180947
BitDefenderThetaGen:NN.ZemsilF.34742.fm1@auTG!zj
MAXmalware (ai score=80)
RisingTrojan.Generic/MSIL@AI.94 (RDM.MSIL:3ysDFD9VMjwNhozbR5lgEg)
YandexTrojan.Agent!kugjWo6K3JU
IkarusVirTool.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:WormX-gen [Wrm]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (D)

How to remove MSILPerseus.132493?

MSILPerseus.132493 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment