Malware

MSILPerseus.203335 (B) malicious file

Malware Removal

The MSILPerseus.203335 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.203335 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSILPerseus.203335 (B)?


File Info:

name: DDA676233A24ED4ECE4E.mlw
path: /opt/CAPEv2/storage/binaries/afa9ab0429a7b75eebc8567f5eb94a0d90a08a519b4f749f6d2e7ad9f5483c9d
crc32: ED3E8F96
md5: dda676233a24ed4ece4e05a0a239db9c
sha1: 18011da7febaedf9f9941c1beb1260bce9c49631
sha256: afa9ab0429a7b75eebc8567f5eb94a0d90a08a519b4f749f6d2e7ad9f5483c9d
sha512: 527cbe91cc27b189c6d9fac9df447b55882b25d523a0a9eb5fb562c6240eff73a1c8f20c5be75ef4141f252165d85de324cc53bd4f6414c61a2d188812f6c2fb
ssdeep: 98304:pwlXbHd5zpwTzgItHdMZB5JgVVPr/hmb:ilXPK3GJ0Dg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4F5338D75FB9297D3D1063890E603BE633C64203962776B74C41CEDBBA9BCDA25C291
sha3_384: 1c042b22c6116a2fb2021230d01cda39589274e0cd9bd69bd9e2cb6798ab7105549a9095a2067b4559d7224ffd96780f
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-04-21 22:47:19

Version Info:

Translation: 0x0000 0x04b0
Comments: Copyright © Microsoft 2021
CompanyName: Copyright © Microsoft 2021
FileDescription: Windows Loader
FileVersion: 2.2.2.2
InternalName: Windows Loader.exe
LegalCopyright: Copyright © Microsoft 2021
LegalTrademarks: Windows Loader
OriginalFilename: Windows Loader.exe
ProductName: Windows Loader
ProductVersion: 2.2.2.2
Assembly Version: 2.2.2.2

MSILPerseus.203335 (B) also known as:

LionicTrojan.Win32.Perseus.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.203335
FireEyeGeneric.mg.dda676233a24ed4e
McAfeeGenericRXAA-FA!DDA676233A24
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Zegost.76430c7c
K7GWTrojan ( 004de9b41 )
K7AntiVirusTrojan ( 004de9b41 )
BitDefenderThetaGen:NN.ZemsilF.34182.kp0@aG60wI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.CGN
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Zegost.gen
BitDefenderGen:Variant.MSILPerseus.203335
AvastWin32:DropperX-gen [Drp]
TencentMsil.Backdoor.Zegost.Wvas
EmsisoftGen:Variant.MSILPerseus.203335 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.fija
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.335176C
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.MSILPerseus.203335
AhnLab-V3Malware/Win32.RL_Generic.C3613626
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.MSILPerseus.203335
MalwarebytesBackdoor.Farfli
RisingTrojan.Generic/MSIL@AI.90 (RDM.MSIL:VL7ayfEVHHQUY3kx8XkjaA)
YandexTrojan.DR.Agent!JptluXt2CMY
IkarusTrojan-Dropper.MSIL.Agent
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.CGN!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.33a24e
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.73796429.susgen

How to remove MSILPerseus.203335 (B)?

MSILPerseus.203335 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment