Trojan:Win32/Perkesh.A

What is Trojan:Win32/Perkesh.A infection?

In this post you will discover about the meaning of Trojan:Win32/Perkesh.A as well as its unfavorable effect on your computer. Such ransomware are a kind of malware that is specified by online scams to require paying the ransom money by a sufferer.

Most of the situations, Trojan:Win32/Perkesh.A infection will certainly advise its sufferers to launch funds move for the purpose of reducing the effects of the modifications that the Trojan infection has actually presented to the sufferer’s gadget.

Trojan:Win32/Perkesh.A Summary

These modifications can be as follows:

  • Expresses interest in specific running processes;
  • Unconventionial language used in binary resources: Chinese (Simplified);
  • The binary likely contains encrypted or compressed data.;
  • The executable is compressed using UPX;
  • Attempts to stop active services;
  • Network activity detected but not expressed in API logs;
  • Ciphering the documents situated on the target’s hard disk — so the sufferer can no more utilize the information;
  • Preventing regular accessibility to the sufferer’s workstation;

Trojan:Win32/Perkesh.A

One of the most regular channels through which Trojan:Win32/Perkesh.A Ransomware Trojans are injected are:

  • By ways of phishing emails;
  • As a consequence of individual ending up on a resource that hosts a malicious software;

As soon as the Trojan is effectively injected, it will either cipher the data on the target’s PC or avoid the gadget from working in an appropriate manner – while also positioning a ransom note that points out the requirement for the targets to effect the repayment for the function of decrypting the papers or recovering the file system back to the initial condition. In most circumstances, the ransom note will certainly come up when the client reboots the PC after the system has already been damaged.

Trojan:Win32/Perkesh.A distribution channels.

In different edges of the world, Trojan:Win32/Perkesh.A grows by leaps and also bounds. Nevertheless, the ransom notes and also techniques of obtaining the ransom amount may differ depending upon specific regional (regional) setups. The ransom money notes and techniques of extorting the ransom amount might vary depending on particular regional (regional) setups.

Ransomware injection

As an example:

    Faulty signals concerning unlicensed software application.

    In certain locations, the Trojans typically wrongfully report having actually discovered some unlicensed applications allowed on the victim’s tool. The alert then demands the customer to pay the ransom money.

    Faulty statements concerning illegal web content.

    In nations where software program piracy is much less preferred, this technique is not as efficient for the cyber fraudulences. Additionally, the Trojan:Win32/Perkesh.A popup alert might incorrectly assert to be stemming from a law enforcement institution as well as will certainly report having located kid porn or other unlawful information on the gadget.

    Trojan:Win32/Perkesh.A popup alert may wrongly claim to be obtaining from a legislation enforcement establishment and also will certainly report having situated child porn or other prohibited data on the gadget. The alert will similarly contain a need for the individual to pay the ransom money.

Technical details

File Info:

crc32: 962049E0md5: 196e1c8774ceb18d1f3460d4d67eaf04name: 196E1C8774CEB18D1F3460D4D67EAF04.mlwsha1: 70ec21de517384821ae3a3ab6c0e45d589799238sha256: b3cca4bbfe1a62c1012a9796d43122d74916d4cfdeb62558fca56aaa64ebccdfsha512: 64706f5503c1096b46a1364ffdc32a842605d6a27ab99c1b6fdd8cfaa95384181a9bd6b60b5e2270c46ba23a0eef7b8f49d2775dc96e5b361cc10edd0e57b97fssdeep: 768:Vz8pvO4VcXJ/w9S7yW5i4VYMxuOR7r9rD5SfnN:VopG2cpv5j/xuORf9rDwtype: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/Perkesh.A also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan-Downloader ( 0055e3da1 )
Lionic Trojan.Win32.LibPatcher.l3fx
Elastic malicious (high confidence)
DrWeb Trojan.Inject1.24442
Cynet Malicious (score: 100)
CAT-QuickHeal Trojan.Perkesh.A5
ALYac Generic.Malware.WVg.151EE6FD
Cylance Unsafe
Zillya Backdoor.Agent.Win32.5941
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_80% (D)
Alibaba TrojanDownloader:Win32/LibPatcher.5f6e6298
K7GW Trojan-Downloader ( 0055e3da1 )
Cybereason malicious.774ceb
Baidu Win32.Rootkit.Agent.ar
Cyren W32/Perkesh.B.gen!Eldorado
Symantec Trojan.Dropper
ESET-NOD32 multiple detections
APEX Malicious
Avast FileRepMalware
ClamAV Win.Trojan.Agent-35382
Kaspersky Trojan-Downloader.Win32.LibPatcher.ke
BitDefender Generic.Malware.WVg.151EE6FD
NANO-Antivirus Trojan.Win32.Agent.bvwwzj
ViRobot Trojan.Win32.KillAV.30720.B
MicroWorld-eScan Generic.Malware.WVg.151EE6FD
Tencent Malware.Win32.Gencirc.10c2569b
Ad-Aware Generic.Malware.WVg.151EE6FD
Sophos Mal/Behav-112
Comodo TrojWare.Win32.Agent.~LZ@120w7
BitDefenderTheta AI:Packer.42D4D6241F
VIPRE Trojan.Win32.Generic!BT
TrendMicro TROJ_KILLAV.SMEA
McAfee-GW-Edition BehavesLike.Win32.Generic.nc
FireEye Generic.mg.196e1c8774ceb18d
Emsisoft Generic.Malware.WVg.151EE6FD (B)
SentinelOne Static AI – Malicious PE
Jiangmin Backdoor/Agent.bldw
Webroot Trojan:Win32/Perkesh.A
Avira BDS/Agent.uyt
Antiy-AVL Trojan/Generic.ASMalwS.31303F
Kingsoft Win32.Troj.VundoT.ai.(kcloud)
Microsoft Trojan:Win32/Perkesh.A
GData Generic.Malware.WVg.151EE6FD
AhnLab-V3 Trojan/Win32.Agent.C53214
McAfee Artemis!196E1C8774CE
MAX malware (ai score=94)
VBA32 BScope.Trojan-Spy.Zbot
Panda Generic Malware
TrendMicro-HouseCall TROJ_KILLAV.SMEA
Rising Trojan.Killav!1.66BF (CLASSIC)
Yandex Trojan.GenAsa!2psSOfhM8tY
Ikarus Rootkit.Win32.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/KillAV.DSO!tr
AVG FileRepMalware
Paloalto generic.ml

How to remove Trojan:Win32/Perkesh.A virus?

Unwanted application has ofter come with other viruses and spyware. This threats can steal account credentials, or crypt your documents for ransom.
Reasons why I would recommend GridinSoft1

Run the setup file.

Run Setup.exe
GridinSoft Anti-Malware Setup

Press “Install” button.

GridinSoft Anti-Malware Install

Once installed, Anti-Malware will automatically run.

GridinSoft Anti-Malware Splash-Screen

Wait for the Anti-Malware scan to complete.

GridinSoft Anti-Malware Scanning

Click on “Clean Now”.

GridinSoft Anti-Malware Scan Result

Are Your Protected?

Full version of GridinSoft

If the guide doesn’t help you to remove Trojan:Win32/Perkesh.A you can always ask me in the comments for getting help.

References

    About the author

    Robert Bailey

    Security engineer focused on malware behavior, removal workflows, and Windows hardening. Robert reviews threat articles for practical accuracy, checking detection names, symptoms, and cleanup steps before publication.

    Leave a Comment