Malware

MSILPerseus.148001 malicious file

Malware Removal

The MSILPerseus.148001 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.148001 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

Related domains:

z.whorecord.xyz
a.tomx.xyz
myp0nysite.ru

How to determine MSILPerseus.148001?


File Info:

crc32: C22ACA8B
md5: f8958a839b9672f687b65c8db2c8725c
name: F8958A839B9672F687B65C8DB2C8725C.mlw
sha1: f1d895220dab14fde1037788dacb17422b4b8b14
sha256: 02e6bcc6ba8a559c4d793920137903defae35ab8d32e4bc9b2f2068698a5e1db
sha512: 4cad07a7786f3501a45e0a3b3a4fd58d4c994aef9784e845d3512e2ae97441d90f9dce0d335389f1e9f4f945b4ad999ac554e975bd6cde9fdaef016bf0a116bc
ssdeep: 3072:6ouWZs4SROIXNZkLt3kysNdfbSIs4En8:64SROmN6Lt3ky8Vsln
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Tulfai.exe
FileVersion: 1.0.0.0
ProductName: Tulfai
ProductVersion: 1.0.0.0
FileDescription: Tulfai
OriginalFilename: Tulfai.exe

MSILPerseus.148001 also known as:

K7AntiVirusTrojan ( 0052aed51 )
LionicTrojan.Win32.Generic.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.MSILPerseus.148001
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1378603
SangforTrojan.Win32.Agent.nil
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0052aed51 )
Cybereasonmalicious.39b967
CyrenW32/Trojan.HVQY-7582
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NHX
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Generic
BitDefenderGen:Variant.MSILPerseus.148001
NANO-AntivirusTrojan.Win32.Udtuu.ezcrgh
MicroWorld-eScanGen:Variant.MSILPerseus.148001
TencentWin32.Trojan-spy.Generic.Eeqv
Ad-AwareGen:Variant.MSILPerseus.148001
SophosMal/Generic-S + Troj/MSIL-LHO
ComodoMalware@#2r9sgw4kh9rso
BitDefenderThetaGen:NN.ZemsilF.34266.im0@aiIg3Yb
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_FAREIT.CBQ
FireEyeGeneric.mg.f8958a839b9672f6
EmsisoftGen:Variant.MSILPerseus.148001 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Generic.adm
AviraHEUR/AGEN.1118528
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.250D216
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.MSILPerseus.D24221
GDataGen:Variant.MSILPerseus.148001
AhnLab-V3Trojan/Win32.CoinMiner.C2434331
McAfeePacked-FBZ!F8958A839B96
MAXmalware (ai score=98)
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_FAREIT.CBQ
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.NHX!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove MSILPerseus.148001?

MSILPerseus.148001 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment