Malware

MSILPerseus.96205 (file analysis)

Malware Removal

The MSILPerseus.96205 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.96205 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSILPerseus.96205?


File Info:

crc32: 3602399E
md5: 322799961ece27de166237bc8b2c957a
name: 322799961ECE27DE166237BC8B2C957A.mlw
sha1: 21e8a799abc14382b32b9f573a7dad7403b9d8ed
sha256: bcac568d4913b85065b90784d0e56a7bf986f8f7a1f0af915f3c1a4b8bee829a
sha512: 4c5be43dafdf11122ba0dbd8b3a0c36a039e0d8737a62cae16dd6126a7d93a287376e320711b98031dcec018791956d34710845f87d3f49535978fb1fa4022b7
ssdeep: 1536:TnHNglMhLKso7Z2jVqoMe5Ubliyc+Hzl0XIN:D6lMhGlGzMkUblQ+TQ8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Showtex 2011
Assembly Version: 1.5.0.1
InternalName: BehringerX32Administrator.exe
FileVersion: 1.3.0.5
CompanyName: Showtec
ProductName: LedPAR Hooker
ProductVersion: 1.3.0.5
FileDescription: ledparhooker
OriginalFilename: BehringerX32Administrator.exe

MSILPerseus.96205 also known as:

K7AntiVirusTrojan ( 0041ea9f1 )
LionicTrojan.Win32.HmBlocker.j!c
DrWebTrojan.KillProc.22104
CynetMalicious (score: 99)
ALYacGen:Variant.MSILPerseus.96205
ZillyaTrojan.HmBlocker.Win32.3946
AlibabaTrojan:MSIL/LockScreen.2cbda035
K7GWTrojan ( 0041ea9f1 )
Cybereasonmalicious.61ece2
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/LockScreen.CR
APEXMalicious
AvastMSIL:LockScreen-U [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILPerseus.96205
NANO-AntivirusTrojan.Win32.HmBlocker.cqokeg
MicroWorld-eScanGen:Variant.MSILPerseus.96205
TencentWin32.Trojan.Hmblocker.szv
Ad-AwareGen:Variant.MSILPerseus.96205
SophosMal/Generic-S
ComodoMalware@#15smwxp1w1cpg
BitDefenderThetaGen:NN.ZemsilF.34050.dm0@aWvJY!c
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.322799961ece27de
EmsisoftGen:Variant.MSILPerseus.96205 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1127586
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.182B84
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.MSILPerseus.96205
McAfeeArtemis!322799961ECE
MAXmalware (ai score=88)
YandexTrojan.HmBlocker!gtcpVobXWM8
IkarusTrojan.MSIL.LockScreen
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/LockScreen.CR
AVGMSIL:LockScreen-U [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwMAEpsA

How to remove MSILPerseus.96205?

MSILPerseus.96205 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment