Trojan

Should I remove “Trojan:MSIL/Seraph.RG!MTB”?

Malware Removal

The Trojan:MSIL/Seraph.RG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Seraph.RG!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:MSIL/Seraph.RG!MTB?


File Info:

name: F4AC970C331479CE654D.mlw
path: /opt/CAPEv2/storage/binaries/e95e46a7217483299e10072c90d63fb6d146bfda8d006e7075ad18fd424fd68e
crc32: 7E79A9A4
md5: f4ac970c331479ce654df74972fa3831
sha1: 77e38f67a2ac3621b9d2bcb643d1a1aaf7799c64
sha256: e95e46a7217483299e10072c90d63fb6d146bfda8d006e7075ad18fd424fd68e
sha512: f156bc43543e768cd40108b483c22064172c1add17cf6c9a4552c96f5342ca11989de2d195f7e33b56526b75e87c4ee95d7f2aa1df77d5e6e8e227c8c21400ab
ssdeep: 24576:hyHU5h2+09F+fdaDM0JjMR2vABU2IAnBi:UHU5k5DFJjMkvAFnB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124151247E6EC40B3D8B46B710AF642C30B36FD559B299603374EAD1E08736A4B13677A
sha3_384: 2b7e798d7c66d954b6acfc7fee3133fb3220a277ce6fc442f8a56753b756ca9800ebc65fdf2aecc8bfb535cc2519823e
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

Trojan:MSIL/Seraph.RG!MTB also known as:

LionicTrojan.Win32.Agent.Y!c
FireEyeGeneric.mg.f4ac970c331479ce
CAT-QuickHealTrojan.MSIL
McAfeeArtemis!F4AC970C3314
MalwarebytesGeneric.Trojan.Injector.DDS
VIPRETrojan.GenericKD.65331035
SangforTrojan.Msil.Agent.Vjm2
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:MSIL/Disabler.dcd75ace
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.Amadey-9986882-0
KasperskyUDS:Trojan.MSIL.Agent.gen
NANO-AntivirusTrojan.Win32.Disabler.juyluk
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.hg
DrWebTrojan.Siggen19.32857
TrendMicroTROJ_GEN.R002C0PBQ23
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.Agent.QS3HE7
GoogleDetected
AviraTR/Disabler.ooicl
Antiy-AVLTrojan/Win32.Sabsik
MicrosoftTrojan:MSIL/Seraph.RG!MTB
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.451744
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PBQ23
RisingTrojan.Kryptik!1.E349 (CLASSIC:bWQ1Og1hFSx6Nlh97w)
IkarusTrojan.Crypter
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Trojan:MSIL/Seraph.RG!MTB?

Trojan:MSIL/Seraph.RG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment