Malware

MSILPerseus.161194 removal guide

Malware Removal

The MSILPerseus.161194 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.161194 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process was set to shut the system down when terminated
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSILPerseus.161194?


File Info:

crc32: 385155D6
md5: 3fda8064d23bab581da2a55f08d1aee3
name: 15747490591.jpg
sha1: d4df893e39d3f1a86958123b07f65054fe1c768d
sha256: 6fce062559323df71306b77dc2c6a468c90fb1187496b51fd1dfb02799cc86c4
sha512: abbd46e0d579f8fb80898c2492e8037d03356163722fcc2808393c206dc0db9037d93b82678bdcf6ce81735b15a315fcfe78db4fe6f97c695ea2a8b446a8c3b1
ssdeep: 384:9e8OuAn0zIqnFaAbt9zTUJS+TfogzhDElzCNJElmN5KLro3YVwE5vT:xOuA0laAb3PuHz9kINn+wE5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSILPerseus.161194 also known as:

MicroWorld-eScanGen:Variant.MSILPerseus.161194
FireEyeGeneric.mg.3fda8064d23bab58
CAT-QuickHealTrojan.Generic
McAfeeRDN/Generic BackDoor
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.miOe
SangforMalware
K7AntiVirusTrojan ( 0053d0b81 )
BitDefenderGen:Variant.MSILPerseus.161194
K7GWTrojan ( 0053d0b81 )
Cybereasonmalicious.4d23ba
TrendMicroTROJ_GEN.R01FC0PKT19
F-ProtW32/MSIL_Troj.QB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.MSILPerseus.161194
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Generic.b3f69fb2
NANO-AntivirusTrojan.Win32.AbsoluteRat.gkeuyv
ViRobotTrojan.Win32.Z.Agent.25600.AYF
RisingBackdoor.LimeRat!1.B863 (CLASSIC)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Gen8
DrWebBackDoor.AbsoluteRat.1
ZillyaTrojan.Agent.Win32.1213029
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
EmsisoftGen:Variant.MSILPerseus.161194 (B)
IkarusTrojan.MSIL.Agent
CyrenW32/MSIL_Troj.QB.gen!Eldorado
JiangminTrojan.Generic.ejdaq
AviraTR/Spy.Gen8
Antiy-AVLTrojan/Win32.Dynamer
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.MSILPerseus.D275AA
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Bladabindi.C202592
Acronissuspicious
ALYacGen:Variant.MSILPerseus.161194
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.AntiVM
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.BPK
TrendMicro-HouseCallTROJ_GEN.R01FC0PKT19
YandexTrojan.Agent!KZg21VsO4O4
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Generic.BPK!tr
Ad-AwareGen:Variant.MSILPerseus.161194
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.db6

How to remove MSILPerseus.161194?

MSILPerseus.161194 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment