Malware

MSILPerseus.8349 malicious file

Malware Removal

The MSILPerseus.8349 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILPerseus.8349 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSILPerseus.8349?


File Info:

crc32: 40EB3DCF
md5: b64f3d5421d5822d9fce08fe8cd86559
name: B64F3D5421D5822D9FCE08FE8CD86559.mlw
sha1: fdc6c62184632071e9542f27956bcd2dcd61d7f3
sha256: 2fda3322cf8725dfaf2bec15182cce6c8b304f6bb56dc94698a568f58aede162
sha512: 033fda780faa67a53eb772e143b5327db4f2b50ed22772fbfae2eb22fa43b0730e163b980a34024a371e51e55ca31fb0d2b178fc370d4a5fe211da07ad4ecc62
ssdeep: 3072:eTzpSpo4RCbhif3MKGxsc5FYXCO4Bmk5KP:k9if3MIqP5K
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Clown 2012
Assembly Version: 8.9.6.2
InternalName: Clown.exe
FileVersion: 8.9.6.2
CompanyName: Clown
Comments: Clown
ProductName: Clown
ProductVersion: 8.9.6.2
FileDescription: Clown
OriginalFilename: Clown.exe

MSILPerseus.8349 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.8349
FireEyeGeneric.mg.b64f3d5421d5822d
ALYacGen:Variant.MSILPerseus.8349
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Banbra.7!c
SangforMalware
K7AntiVirusTrojan ( 004cb0851 )
BitDefenderGen:Variant.MSILPerseus.8349
K7GWTrojan ( 004cb0851 )
Cybereasonmalicious.421d58
BitDefenderThetaGen:NN.ZemsilF.34804.gm0@aWP7T1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.AVW
APEXMalicious
AvastWin32:Downloader-RWD [Trj]
ClamAVWin.Trojan.2590-3
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Injector.994965a2
NANO-AntivirusTrojan.Win32.FakeAV.dklprr
ViRobotTrojan.Win32.A.Banbra.103424.A
RisingTrojan.Injector!8.C4 (TFE:C:KuNoaqkUO7E)
Ad-AwareGen:Variant.MSILPerseus.8349
SophosMal/Generic-S
ComodoTrojWare.MSIL.Injector.AVW@4t3iy1
F-SecureTrojan.TR/Dropper.MSIL.Gen8
DrWebWorm.Siggen.6967
ZillyaTrojan.Banbra.Win32.18035
TrendMicroTROJ_SPNR.11AE13
McAfee-GW-EditionGenericRXHY-MY!B64F3D5421D5
EmsisoftGen:Variant.MSILPerseus.8349 (B)
IkarusBackdoor.Win32.Fynloski
JiangminTrojan/Banker.Banbra.qft
WebrootW32.Rogue.Gen
AviraTR/Dropper.MSIL.Gen8
MAXmalware (ai score=100)
Antiy-AVLTrojan[Banker]/Win32.Banbra
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Malagent
ArcabitTrojan.MSILPerseus.D209D
SUPERAntiSpywareTrojan.Agent/Gen-Enola
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.MSILPerseus.8349
CynetMalicious (score: 85)
McAfeeGenericRXHY-MY!B64F3D5421D5
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Banker
PandaTrj/Agent.MIZ
TrendMicro-HouseCallTROJ_SPNR.11AE13
TencentWin32.Trojan-banker.Banbra.Pefv
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Dropper.HQP!tr
AVGWin32:Downloader-RWD [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM03.0.3F21.Malware.Gen

How to remove MSILPerseus.8349?

MSILPerseus.8349 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment