Malware

About “MSILPerseus.175558” infection

Malware Removal

The MSILPerseus.175558 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.175558 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
0x01337.duckdns.org
a.tomx.xyz

How to determine MSILPerseus.175558?


File Info:

crc32: 299D3E60
md5: 01e9cd0d77e09e9c08ed87eb4a28f5d0
name: loader.exe
sha1: 2b1e8545132190612879a98cd643a4fa3ecb0896
sha256: 0fc373be6530fe0c7b1634e41e30cb393fc780d18184477e90aaa58f38a7f6ea
sha512: deb7bd774ed5df96595d42a938d57407f07291fe0e565016a199595f00bf0f61c4b9f2d6be9ef3e3dd1b91fa93e7f7be7652f9bad5149b56a46a79f9e92b1ade
ssdeep: 6144:JhIWhaROxOEpWqAee7dN5f9DasEhussJzdWpEMdagaQafmbtLMsECZbr8PxtPY/:JqWYUhWqDeV9chXEMdJaQ5FpDgJKU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSILPerseus.175558 also known as:

MicroWorld-eScanGen:Variant.MSILPerseus.175558
FireEyeGeneric.mg.01e9cd0d77e09e9c
ALYacGen:Variant.MSILPerseus.175558
CylanceUnsafe
BitDefenderGen:Variant.MSILPerseus.175558
Cybereasonmalicious.d77e09
BitDefenderThetaGen:NN.ZemsilF.34106.svW@ayiM13i
CyrenW32/NanoCore.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ClamAVWin.Trojan.Nanocore-5
GDataGen:Variant.MSILPerseus.175558
KasperskyHEUR:Backdoor.Win32.Generic
Endgamemalicious (high confidence)
EmsisoftGen:Variant.MSILPerseus.175558 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
Trapminemalicious.high.ml.score
SophosTroj/NanoCor-OC
SentinelOneDFI – Malicious PE
F-ProtW32/NanoCore.C.gen!Eldorado
JiangminBackdoor.Generic.bblq
eGambitTrojan.Generic
MicrosoftBackdoor:MSIL/Nanocore.S!MTB
ArcabitTrojan.MSILPerseus.D2ADC6
ZoneAlarmHEUR:Backdoor.Win32.Generic
McAfeeBackDoor-FDNS!01E9CD0D77E0
MAXmalware (ai score=88)
ESET-NOD32a variant of MSIL/NanoCore.B
RisingBackdoor.NanoCore!1.B6F9 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
Ad-AwareGen:Variant.MSILPerseus.175558
AVGWin32:CoinminerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.9E5F.Malware.Gen

How to remove MSILPerseus.175558?

MSILPerseus.175558 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment