Trojan

Trojan:MSIL/Perseus.RW!MTB removal guide

Malware Removal

The Trojan:MSIL/Perseus.RW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Perseus.RW!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • The following process appear to have been packed with Themida: 8C9B0FD73F047B2243F46B0AC4EFA9D5.mlw
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/Perseus.RW!MTB?


File Info:

crc32: DB09A08E
md5: 8c9b0fd73f047b2243f46b0ac4efa9d5
name: 8C9B0FD73F047B2243F46B0AC4EFA9D5.mlw
sha1: be534bc2323c32067df20ecfd4cd2d61ca5f766e
sha256: 583c189b3d8bc98c7a9e22ba2ad1fce8210222fa636287f8fa3fd7b291cd778c
sha512: cd4c1ee1e1144cf244d7623d971e51a6bd6bb6f9c7c3a8e2cb4b0482d508a2e2c09b9c303f8b0cfe821761beca8e19c34a9a1357770214390ecf8203b2b52d0f
ssdeep: 49152:B+RSCa8HEYbMMM6KnJjp/S9kVAUrIbgXMT41KVEwqZ6R5Tjut9dPbMx9/Rd0CTy:B+HjMMMVnJj1kkVl8s4htgXoB//2ju
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: Eternity Launcher.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Eternity Launcher
ProductVersion: 1.0.0.0
FileDescription: Eternity Launcher
OriginalFilename: Eternity Launcher.exe

Trojan:MSIL/Perseus.RW!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Hynamer
ALYacTrojan.GenericKD.37377616
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/SuspectCRC.b33acf2f
K7GWTrojan ( 005809421 )
K7AntiVirusTrojan ( 005809421 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.NFYDAGT
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.37377616
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanTrojan.GenericKD.37377616
Ad-AwareTrojan.GenericKD.37377616
ComodoMalware@#2g3vniyl8w7vd
BitDefenderThetaGen:NN.ZexaF.34058.8F0@aqfLJ1gi
TrendMicroTrojanSpy.MSIL.PERSEUS.USASHHA21
FireEyeGeneric.mg.8c9b0fd73f047b22
EmsisoftTrojan.GenericKD.37377616 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:MSIL/Perseus.RW!MTB
GridinsoftTrojan.Heur!.032104A1
GDataTrojan.GenericKD.37377616
McAfeeArtemis!8C9B0FD73F04
MAXmalware (ai score=82)
VBA32BScope.Trojan.Occamy
MalwarebytesMalware.AI.4146339773
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.MSIL.PERSEUS.USASHHA21
RisingTrojan.Generic@ML.100 (RDMK:11MPAoY8Jod1RNyNTvb7Mg)
YandexTrojan.Agent!GEc8cCukO58
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxMBFBsB

How to remove Trojan:MSIL/Perseus.RW!MTB?

Trojan:MSIL/Perseus.RW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment