Malware

MSILPerseus.169335 removal tips

Malware Removal

The MSILPerseus.169335 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.169335 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
xmrpool.eu

How to determine MSILPerseus.169335?


File Info:

crc32: 5FF76031
md5: 4cc00acb938c415323d624d9bd261c88
name: 4CC00ACB938C415323D624D9BD261C88.mlw
sha1: 746600d2913fede3080eae464accf932d844ff64
sha256: 237dee141ad9a567576aa7639c8c711d621fbf4ade722c8d62f7a58ed0665455
sha512: 0a038dd71e19f1cea908411b31b9c96fe4b9442d1902dbbeb6219f199cbeb552c327320f8985b003d81e324c001fc37b0b29b73dbda2b01846639911897543ed
ssdeep: 24576:ZQGbQGz30lINd4wrYLOlc7LwLlJ5eAZlzB7ZX:ZTbQG70lI1qKc78LlJ5eAZzZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2002-2017
Assembly Version: 4.6.0.0
InternalName: CLIStart.exe
FileVersion: 4.6.0.0
CompanyName: Advanced Micro incriedables
LegalTrademarks:
Comments: CCC applications
ProductName: CLIStart CCC
ProductVersion: 4.6.0.0
FileDescription:
OriginalFilename: CLIStart.exe

MSILPerseus.169335 also known as:

K7AntiVirusTrojan ( 0053fc4c1 )
LionicTrojan.MSIL.Coins.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.MSILPerseus.169335
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1524168
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanPSW:MSIL/Coins.ff10a917
K7GWTrojan ( 0053fc4c1 )
Cybereasonmalicious.b938c4
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.PYV
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-PSW.MSIL.Coins.gen
BitDefenderGen:Variant.MSILPerseus.169335
NANO-AntivirusTrojan.Win32.Coins.ixqimt
MicroWorld-eScanGen:Variant.MSILPerseus.169335
TencentMsil.Trojan-qqpass.Qqrob.Pgwu
Ad-AwareGen:Variant.MSILPerseus.169335
SophosMal/Generic-S
ComodoMalware@#ccj26tdoz47g
BitDefenderThetaGen:NN.ZemsilF.34294.Bn0@a4K16Si
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.4cc00acb938c4153
EmsisoftGen:Variant.MSILPerseus.169335 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.fhy
AviraHEUR/AGEN.1120303
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.MSILPerseus.D29577
GDataGen:Variant.MSILPerseus.169335
AhnLab-V3Malware/RL.Generic.R241806
McAfeePacked-FOI!4CC00ACB938C
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.BPM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove MSILPerseus.169335?

MSILPerseus.169335 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment