Malware

MSILPerseus.203402 removal

Malware Removal

The MSILPerseus.203402 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.203402 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Harvests cookies for information gathering

How to determine MSILPerseus.203402?


File Info:

name: ADCD367D76F093C5D479.mlw
path: /opt/CAPEv2/storage/binaries/fc4cb5430b385c477aa7c2909e0e465e60c93787b45d41b1cc2372f50b93d081
crc32: AA0870AC
md5: adcd367d76f093c5d4795829dbd49d0a
sha1: 27eada16133f6c2bf49c0fe2c6faa0a2f1403478
sha256: fc4cb5430b385c477aa7c2909e0e465e60c93787b45d41b1cc2372f50b93d081
sha512: 87b547793b0588724b3ca2a3970e28f4f5ef412c50208b0518868a938918eee4075558e4330dd9afed132559659388e032f34a4d857f397c8130b64ef3592823
ssdeep: 384:l/23H5xVNSIxdVsrK7ftfVb73X8exjLdXD0LFQ4NAT6nU7LyL8R3dIi4zYY3koiz:xAOnN5U7LyLkdIi4zYY0b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16E829405B3E80919D1AF077BAA3B8A1B9275F907C511C5AE41CBD11B2E676C38D4CFB2
sha3_384: 0585c1b97fabf4fb50a902c95e82a9651fe0e49df64aa81f818050efadbb8197c6d831b50848a22913d549839e94c3e3
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-12 18:39:36

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Windows worker process
FileVersion: 1.0.0.0
InternalName: Setup.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: Setup.exe
ProductName: Windows worker process
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSILPerseus.203402 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Startun.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.203402
FireEyeGeneric.mg.adcd367d76f093c5
McAfeeArtemis!ADCD367D76F0
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0055c7841 )
AlibabaTrojan:MSIL/Startun.4410e068
K7GWSpyware ( 0055c7841 )
Cybereasonmalicious.d76f09
BitDefenderThetaGen:NN.ZemsilF.36308.bm0@aqXQSLn
CyrenW32/Keylogger.AG.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Spy.Keylogger.DQE
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Startun.gen
BitDefenderGen:Variant.MSILPerseus.203402
NANO-AntivirusTrojan.Win32.Startun.hkdrxt
AvastWin32:MalwareX-gen [Trj]
TencentMsil.Trojan.Startun.Zfow
SophosML/PE-A
DrWebTrojan.DownLoader30.52156
VIPREGen:Variant.MSILPerseus.203402
McAfee-GW-EditionArtemis
EmsisoftGen:Variant.MSILPerseus.203402 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.MSILPerseus.203402
GoogleDetected
AviraTR/Spy.KeyLogger.rrsdf
Antiy-AVLTrojan/MSIL.Startun
XcitiumMalware@#2zorx9aaus3j9
ArcabitTrojan.MSILPerseus.D31A8A
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C3752858
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.MSILPerseus.203402
MAXmalware (ai score=85)
Cylanceunsafe
RisingSpyware.Keylogger!8.12F (CLOUD)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.74629951.susgen
FortinetMSIL/Agent.DQE!tr
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSILPerseus.203402?

MSILPerseus.203402 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment