Malware

MSILPerseus.238122 removal instruction

Malware Removal

The MSILPerseus.238122 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.238122 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine MSILPerseus.238122?


File Info:

name: 3B512C1E9D2FC9C3B821.mlw
path: /opt/CAPEv2/storage/binaries/425a4f9fd65a2bc2b76d5ae62f1c7ba6128f50aab578c9db291316c527e4ddb4
crc32: D8BD38E6
md5: 3b512c1e9d2fc9c3b821c111968e26ed
sha1: 32d1ee45cfd35a1eebebd33e9fec856fc2d9d4e0
sha256: 425a4f9fd65a2bc2b76d5ae62f1c7ba6128f50aab578c9db291316c527e4ddb4
sha512: 8c4086749cd02f73c930df48e7aa96bd49925b6a22fc8b572efcc266089e776110e8b9cbce4406ab327479432408db6c8d6fb4ff256c794e323ea66090c1bcc5
ssdeep: 3072:7gejvgZE+s4hEuYXMD8baRYX2JHIxCLsVmFlYbuB1XKNgmTQ9CysZeLr+1onaRko:Hv3+sCEe+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1951542BE14882A7CDBFBD37422E2440783A589D0D342DEDC2E9413BB5BA6447B7126DD
sha3_384: 01e5b659e256d1ac2b11683d89fa706dbf7b0f41e8a698696eb30b965750cdebe4bd2cf340480bc18492c91e27e8ccc4
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-13 20:42:06

Version Info:

Translation: 0x0000 0x04b0
FileDescription: WindowsApplication1
FileVersion: 1.0.0.0
InternalName: WindowsApplication1.exe
LegalCopyright: Copyright © 2022
OriginalFilename: WindowsApplication1.exe
ProductName: WindowsApplication1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSILPerseus.238122 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.MSILPerseus.238122
FireEyeGeneric.mg.3b512c1e9d2fc9c3
McAfeeArtemis!3B512C1E9D2F
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005377071 )
BitDefenderGen:Variant.MSILPerseus.238122
K7GWTrojan ( 005377071 )
Cybereasonmalicious.5cfd35
ArcabitTrojan.MSILPerseus.D3A22A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.TTT
APEXMalicious
ClamAVWin.Dropper.Zusy-7619646-0
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusTrojan.Win32.Agent.elgxdg
CynetMalicious (score: 100)
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:hAe6BpCTIOkVBE+4cdgJug)
Ad-AwareGen:Variant.MSILPerseus.238122
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebTrojan.MulDrop6.42253
VIPREGen:Variant.MSILPerseus.238122
TrendMicroTROJ_GEN.R014C0WJE22
McAfee-GW-EditionArtemis
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.MSILPerseus.238122 (B)
IkarusTrojan-Dropper.MSIL.Agent
AviraTR/Dropper.MSIL.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataMSIL.Trojan.Agent.AUM
GoogleDetected
Acronissuspicious
VBA32OScope.TrojanDropper.MSIL.Agent
ALYacGen:Variant.MSILPerseus.238122
MAXmalware (ai score=88)
MalwarebytesBackdoor.Bladabindi.MSIL
TrendMicro-HouseCallTROJ_GEN.R014C0WJE22
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.SHW!tr
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSILPerseus.238122?

MSILPerseus.238122 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment