Malware

MSIL/Packed.Confuser.AD removal guide

Malware Removal

The MSIL/Packed.Confuser.AD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Packed.Confuser.AD virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine MSIL/Packed.Confuser.AD?


File Info:

name: D759652AF2B9A448C57F.mlw
path: /opt/CAPEv2/storage/binaries/cce94077fd093eed9c989e32abfb0ea8e08b1730bc2df9d813ebe86dda5ae263
crc32: D0DBF3AE
md5: d759652af2b9a448c57fbfbca537921a
sha1: 0a0b6f176f4f710ab659d72c9f279183762d4016
sha256: cce94077fd093eed9c989e32abfb0ea8e08b1730bc2df9d813ebe86dda5ae263
sha512: d2f6ee0cc84ea6c7bc1218ea82e893b77934ebd15d9d870a41d21cc113c47258bf7049b8698c554f233a3a3c8ba2228dfd9e45d9aea5bdb0d0b617aa3ea364a8
ssdeep: 98304:VKoVyhPUjDLPMHVmWNmYxs53EBoRsZV5UImQ2PV:V9V1DLPM13ISs53EssBUx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15906238EB29300F2D63119717C2BD2299B3FBC795A15A60F1AB05B6DD7B00536361BE3
sha3_384: fe13a7c10de40db58ef5e6f58dc936ee3a2dcf6662835f82b19f886d97cbed9e7261c1358709390a9bba8c446dc7e47c
ep_bytes: e88a040000e98efeffff3b0db8a14300
timestamp: 2017-08-11 13:54:06

Version Info:

0: [No Data]

MSIL/Packed.Confuser.AD also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.6191809
FireEyeGeneric.mg.d759652af2b9a448
ALYacTrojan.GenericKD.6191809
CylanceUnsafe
SangforTrojan.MSIL.Confuser.AD
K7AntiVirusUnwanted-Program ( 004d38111 )
BitDefenderTrojan.GenericKD.6191809
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.D5E7AC1
CyrenW32/MSIL_Kryptik.DGQ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Packed.Confuser.AD
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Uztuby-6815912-0
KasperskyUDS:Trojan.MSIL.Disfa.mkfm
AlibabaTrojan:MSIL/Ainslot.df285cee
NANO-AntivirusTrojan.Win32.Disfa.euwing
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:Nhj5BQUGco3j34cDapnwvg)
Ad-AwareTrojan.GenericKD.6191809
SophosMal/Generic-S (PUA)
DrWebTrojan.DownLoader25.57753
VIPRETrojan.GenericKD.6191809
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.6191809 (B)
IkarusWorm.Win32.Ainslot
AviraTR/Agent.xactf
MAXmalware (ai score=76)
Antiy-AVLTrojan/Generic.ASBOL.38BB
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
GDataTrojan.GenericKD.6191809
GoogleDetected
McAfeeArtemis!D759652AF2B9
MalwarebytesBackdoor.Bladabindi
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic!tr
BitDefenderThetaGen:NN.ZexaF.34592.QBZ@au!pn6dO
AVGWin32:Malware-gen
Cybereasonmalicious.af2b9a
AvastWin32:Malware-gen

How to remove MSIL/Packed.Confuser.AD?

MSIL/Packed.Confuser.AD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment