Malware

How to remove “MSILPerseus.237439 (B)”?

Malware Removal

The MSILPerseus.237439 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.237439 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine MSILPerseus.237439 (B)?


File Info:

crc32: 7AC1CE39
md5: 60ece7983b52efb4afcda75e1c7577b3
name: upload_file
sha1: 120db235d27b25f14d63a5100300cd09ec87e0c0
sha256: aa7140aa9e404fcab5e45ba552de89669da4446c6a3474f307def1a75a3d37e0
sha512: bb2f378cf52afdb4682ba3f97f146b4c444d378278963ed1e614228c618ccdfecaf1bff6958dcd8fb9e60b5386900cbaa708db332986efb5474c06075115598b
ssdeep: 12288:tE65s5X0V7qdNsoJCTinpIpmxepLUBaiwpWTvyWXNaYdQD1BIzgN:tczsoIenigI6Fwp8dXcYyD1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015 Sofeon
Assembly Version: 5.0.0.0
InternalName: PNgS.exe
FileVersion: 5.0.4.0
CompanyName: Sofeon
LegalTrademarks:
Comments:
ProductName: Warehouse Management System
ProductVersion: 5.0.4.0
FileDescription: Warehouse Management System
OriginalFilename: PNgS.exe

MSILPerseus.237439 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.237439
McAfeeArtemis!60ECE7983B52
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.MSILPerseus.237439
ArcabitTrojan.MSILPerseus.D39F7F
CyrenW32/MSIL_Kryptik.BXI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 90)
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
AlibabaBackdoor:MSIL/Kryptik.81d97899
Ad-AwareGen:Variant.MSILPerseus.237439
EmsisoftGen:Variant.MSILPerseus.237439 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen7
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Fareit.hc
SentinelOneDFI – Malicious PE
AviraTR/Dropper.MSIL.Gen7
MAXmalware (ai score=83)
MicrosoftTrojanSpy:MSIL/Stelega.RIA!MTB
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
GDataGen:Variant.MSILPerseus.237439
BitDefenderThetaGen:NN.ZemsilF.34570.Km0@ayPCjvp
ALYacGen:Variant.MSILPerseus.237439
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.MalPack.PNG.Generic
ESET-NOD32a variant of MSIL/Kryptik.YET
FortinetMSIL/Kryptik.YET!tr
AVGFileRepMalware
Cybereasonmalicious.5d27b2
Qihoo-360HEUR/QVM03.0.9E15.Malware.Gen

How to remove MSILPerseus.237439 (B)?

MSILPerseus.237439 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment