Malware

MSILPerseus.190132 (file analysis)

Malware Removal

The MSILPerseus.190132 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.190132 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine MSILPerseus.190132?


File Info:

name: CADA201A7620BDB44FAD.mlw
path: /opt/CAPEv2/storage/binaries/037cf7d05723becb869408339d724f33e964f17ccda7320cc3bf203bef1a607b
crc32: 6AE1A491
md5: cada201a7620bdb44fad9b25eb2f0aa7
sha1: e21dc211376119939a99f5a61f427313c81973d5
sha256: 037cf7d05723becb869408339d724f33e964f17ccda7320cc3bf203bef1a607b
sha512: 356be7174a351a9c52ea195186010ec734ddaa0ab0846114d3cfe89b8bba1507cf698e99015ef5040f101c6a9246035046a067fa6f4a6f058b80c25317de0ee8
ssdeep: 6144:dx7hbw23aXWdB+xupgEXYpFbxMlEZMcpNGPy1brPTUKwTCbSfQ+DDDDDDDDDDiTH:dxNwCaXWdB+xupgEXYpFbxMlEZMcpNG4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4345F8126AF2A5DE27822772271D0C093E7D8121312EB29ED9C3359FDEED459F71386
sha3_384: 87272ace28bb65d99a5072f863f490c8a90730e4aa97c00f9ef467c7741401d7895ba0f4daac1864e5badd1fee1c111c
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-06-10 19:13:57

Version Info:

Translation: 0x0000 0x04b0
FileDescription: 美丽成功丽丽丽的丽美复制制功的
FileVersion: 1
InternalName: 美丽成功丽丽丽的丽美复制制功的.exe
LegalCopyright:
OriginalFilename: 美丽成功丽丽丽的丽美复制制功的.exe
ProductVersion: 1
Assembly Version: 1.0.0.0

MSILPerseus.190132 also known as:

LionicTrojan.MSIL.Hallaj.4!c
MicroWorld-eScanGen:Variant.MSILPerseus.190132
FireEyeGeneric.mg.cada201a7620bdb4
ALYacGen:Variant.MSILPerseus.190132
CylanceUnsafe
SangforTrojan.Win32.Kryptik.kmndu
K7AntiVirusTrojan ( 005244661 )
BitDefenderGen:Variant.MSILPerseus.190132
K7GWTrojan ( 005244661 )
Cybereasonmalicious.a7620b
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.MJW
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Msilperseus-7012239-0
KasperskyHEUR:Backdoor.MSIL.Hallaj.gen
AlibabaBackdoor:MSIL/Hallaj.dc34f4dc
NANO-AntivirusTrojan.Win32.Hallaj.friucj
RisingMalware.Obfus/MSIL@AI.97 (RDM.MSIL:QpWFkLqroFHNzqJjRugI4Q)
Ad-AwareGen:Variant.MSILPerseus.190132
SophosMal/Generic-S
DrWebTrojan.PackedNET.162
ZillyaTrojan.Kryptik.Win32.1672837
McAfee-GW-EditionGenericRXHU-DF!CADA201A7620
EmsisoftGen:Variant.MSILPerseus.190132 (B)
IkarusTrojan.MSIL9
AviraHEUR/AGEN.1222968
MAXmalware (ai score=99)
MicrosoftTrojan:MSIL/Bladabindi
GDataGen:Variant.MSILPerseus.190132
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Bladabindi.C3293202
McAfeeGenericRXHU-DF!CADA201A7620
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TencentMsil.Backdoor.Hallaj.Tccg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.MJW!tr
BitDefenderThetaGen:NN.ZemsilF.34638.oq0@aWIT6lg
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSILPerseus.190132?

MSILPerseus.190132 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment