Malware

Ser.MSILPerseus.759 removal instruction

Malware Removal

The Ser.MSILPerseus.759 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.MSILPerseus.759 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients

How to determine Ser.MSILPerseus.759?


File Info:

name: 0B08EA3B83370CDF4F59.mlw
path: /opt/CAPEv2/storage/binaries/d2ae849cda3a8ef809f96c84f72735ede7c9da7e009a26c6418b7f7a0b51668c
crc32: 61A6D1DE
md5: 0b08ea3b83370cdf4f59b2542c4f7677
sha1: e1d38f73997e51660d76ac4cc636b1f0b76e9b0f
sha256: d2ae849cda3a8ef809f96c84f72735ede7c9da7e009a26c6418b7f7a0b51668c
sha512: 755e35f722fcf5d030228f55aadb77a63a2818bfff00cc62f4fc3a7fb1db371fb41523810115384737e704f0339c2aff05b327a532c6b8ac1ea24dc10bd41426
ssdeep: 12288:4qjjbtzEgDMEH3LpCrX9Jo67QF+uHl7eyZ6o6pAoAy:4Cj1fWXHo67QHlVZ0A5y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185A4F2A2254BC45CC56D463224DAB6C0FA76377A3F60CA2E719D072D7E3255EEB0132B
sha3_384: ddda46c162fb4958a3417369a1194bb4455177890800b50e4c5bab264ded77c4444259c85ff16999687ef54ae899e3c8
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-05-02 02:13:39

Version Info:

Comments:
CompanyName:
FileDescription: Device Association Service
FileVersion: 1.0.0.0
InternalName: letal.exe
LegalCopyright: Copyright © 2016
LegalTrademarks:
OriginalFilename: letal.exe
ProductName: DeviceAsssociationService
ProductVersion: 1.0.0.0
Assembly Version: 52.121.1.1
Translation: 0x0000 0x04b0

Ser.MSILPerseus.759 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.MSILPerseus.759
FireEyeGeneric.mg.0b08ea3b83370cdf
CAT-QuickHealTrojan.Smalo.G3
McAfeeFareit-FEJ!0B08EA3B8337
CylanceUnsafe
ZillyaTrojan.Chisburg.Win32.2149
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056ffef1 )
AlibabaTrojan:MSIL/Injector.b7f6db7d
K7GWTrojan ( 0056ffef1 )
Cybereasonmalicious.b83370
CyrenW32/MSIL_Injector.DN.gen!Eldorado
SymantecInfostealer.Limitail
ESET-NOD32a variant of MSIL/Injector.PCH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.MSILPerseus.759
NANO-AntivirusTrojan.Win32.Drop.ecbdqe
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastMSIL:Injector-NL [Trj]
TencentWin32.Trojan-qqpass.Qqrob.Eeq
EmsisoftGen:Variant.Ser.MSILPerseus.759 (B)
DrWebTrojan.MulDrop6.38633
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA000E416
McAfee-GW-EditionBehavesLike.Win32.Fareit.gc
SophosTroj/MSILInj-JU
IkarusTrojan.MSIL.Injector
JiangminTrojan.PSW.Chisburg.ov
AviraHEUR/AGEN.1118531
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.185EA13
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ser.MSILPerseus.759
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34182.Dm0@am7F6j
ALYacGen:Variant.Ser.MSILPerseus.759
MalwarebytesMachineLearning/Anomalous.96%
TrendMicro-HouseCallTROJ_FRS.0NA000E416
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.PCM!tr
AVGMSIL:Injector-NL [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Ser.MSILPerseus.759?

Ser.MSILPerseus.759 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment