Trojan

Trojan:MSIL/Seraph.SPDF!MTB removal guide

Malware Removal

The Trojan:MSIL/Seraph.SPDF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Seraph.SPDF!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:MSIL/Seraph.SPDF!MTB?


File Info:

name: 798A8E4674B0B57BBD49.mlw
path: /opt/CAPEv2/storage/binaries/3391b9805b7f30b340579a491baef5a3fdea01843cc3af7c181e9410a2176ecd
crc32: 4A99FA83
md5: 798a8e4674b0b57bbd4968327f635397
sha1: b439298942c095903c9a2eeffd74038d88fca1ed
sha256: 3391b9805b7f30b340579a491baef5a3fdea01843cc3af7c181e9410a2176ecd
sha512: 083c29a3f988bf811a2ec15ca418c7cb06f40b14d8fe07dcfce7991fc5e912e474c06c952f17cd650184a876cfa5f05cd6053573fa4dcc3a86902dbf55bef1ce
ssdeep: 3072:0a30BUpGvtvEx76J5XFyTZ460asEBNSn3BjB8ec:Rto+76J5XFyTZ460asEBMxme
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111C3286D4BB9C56BD2ED07BEF4DA0CC05F30EC01A287DB8AEBD4B17954B2341944266B
sha3_384: c5fc258ecd180e33b47892df55a946073b25948f2fcbbdf0a53f9e30e05f7cf92748963995675b2e5b83b2db13df2632
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-12-12 15:06:53

Version Info:

Translation: 0x0000 0x04b0
Comments: PDFescape Desktop
CompanyName: Red Software
FileDescription: PDFescape Desktop
FileVersion: 4.0.24.4617
InternalName: Yqktybo.exe
LegalCopyright: Copyright 2019 Red Software. All rights reserved.
LegalTrademarks:
OriginalFilename: Yqktybo.exe
ProductName: PDFescape Desktop
ProductVersion: 4.0.24.4617
Assembly Version: 4.0.24.4617

Trojan:MSIL/Seraph.SPDF!MTB also known as:

BkavW32.AIDetectMalware.CS
DrWebTrojan.DownLoaderNET.887
MicroWorld-eScanGen:Variant.MSILHeracles.129919
SkyhighRDN/Generic.grp
McAfeeRDN/Generic.grp
MalwarebytesTrojan.Downloader.MSIL
ArcabitTrojan.MSILHeracles.D1FB7F
SymantecMSIL.Downloader!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik_AGen.BPP
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.MSILHeracles.129919
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.MSILHeracles.129919 (B)
F-SecureTrojan.TR/Redcap.mbvpd
VIPREGen:Variant.MSILHeracles.129919
FireEyeGen:Variant.MSILHeracles.129919
VaristW32/MSIL_Agent.HCH.gen!Eldorado
AviraTR/Redcap.mbvpd
MAXmalware (ai score=86)
Antiy-AVLTrojan/MSIL.Kryptik
MicrosoftTrojan:MSIL/Seraph.SPDF!MTB
GDataGen:Variant.MSILHeracles.129919
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.C5563506
ALYacGen:Variant.MSILHeracles.129919
PandaTrj/GdSda.A
RisingBackdoor.Remcos!8.B89E (C64:YzY0Og3YmXbxUv5eZg)
MaxSecureTrojan.Malware.221575369.susgen
FortinetMSIL/GenKryptik.GPVQ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan:MSIL/Seraph.SPDF!MTB?

Trojan:MSIL/Seraph.SPDF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment