Trojan

Trojan:MSIL/Seraph.RG!MTB removal instruction

Malware Removal

The Trojan:MSIL/Seraph.RG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Seraph.RG!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:MSIL/Seraph.RG!MTB?


File Info:

name: F355AD09D7A3B776C2BB.mlw
path: /opt/CAPEv2/storage/binaries/9fb38e1b47fe8c0125691deb9a9fdcef4e2f068d125f4ed673adaf1f5b575388
crc32: 66909929
md5: f355ad09d7a3b776c2bbb03f78142c9e
sha1: 0e71512215269c50e6b4c0b4ebb7e73dea50273d
sha256: 9fb38e1b47fe8c0125691deb9a9fdcef4e2f068d125f4ed673adaf1f5b575388
sha512: 6448f058dd40ff2e80850adfb4fb5075a6de6e55031dfabab47a4f037177ae99d518dd2b4f8c013d6dc03ab6e309c62bf17e12a11f49096b58ebc25e299a908f
ssdeep: 6144:KQy+bnr+rp0yN90QEyp3G+OYsd0ggZsCqIBXp3eJGUO4cG892V6tTKBIYkBdP:wMrzy90etOY5ggKCXJCO4NKeK/dP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F84F10BF6EC8032E9B1177019F306C30A36BD615B7543AB274FB95E58726B4A63172B
sha3_384: 470402194d2994cdc4f3e6f287f7e02352355361cf2f9666745fb52b84b66df878c79a75a10e86c5330036c179a1ccaf
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

Trojan:MSIL/Seraph.RG!MTB also known as:

LionicTrojan.Win32.Stealer.12!c
FireEyeGeneric.mg.f355ad09d7a3b776
CAT-QuickHealTrojan.MSIL
McAfeeArtemis!F355AD09D7A3
MalwarebytesGeneric.Trojan.Injector.DDS
VIPRETrojan.GenericKD.65331035
SangforTrojan.Msil.Agent.Vcw1
K7AntiVirusTrojan ( 0059e3df1 )
AlibabaTrojanSpy:Win32/Stealer.471cc0f5
K7GWTrojan ( 0059e3df1 )
Cybereasonmalicious.9d7a3b
VirITTrojan.Win32.MSIL.EY
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Disabler-9987080-0
KasperskyUDS:Trojan.MSIL.Agent.gen
NANO-AntivirusTrojan.Win32.Disabler.juwzeh
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.hg
DrWebTrojan.Siggen19.32857
TrendMicroTROJ_GEN.R002C0PBP23
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.PSE.95OW7Y
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Sabsik
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Seraph.RG!MTB
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.65736375
TrendMicro-HouseCallTROJ_GEN.R002C0PBP23
RisingTrojan.Kryptik!1.E349 (CLASSIC:bWQ1Og1hFSx6Nlh97w)
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan.MSIL.Disabler
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AD
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/Seraph.RG!MTB?

Trojan:MSIL/Seraph.RG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment