Trojan

Trojan:Win32/Pierogi!MSR malicious file

Malware Removal

The Trojan:Win32/Pierogi!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pierogi!MSR virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Pierogi!MSR?


File Info:

name: 3296B51479C754033123.mlw
path: /opt/CAPEv2/storage/binaries/d08e7464fa8650e669012056548383fbadcd29a093a28eb7d0c2ba4e9036eb07
crc32: BC72F45B
md5: 3296b51479c7540331233f47ed7c38dd
sha1: 4107f9c36c3a5ce66f8365140901cd15339aa66c
sha256: d08e7464fa8650e669012056548383fbadcd29a093a28eb7d0c2ba4e9036eb07
sha512: fde66fcba07f3ce68a215dce86560e711b5c8ec8be14d27b40a23d90663285eedfb77256fc2ee85585a24da78d2adc38b7ea287a786797c8bf0de381ab71d1a6
ssdeep: 49152:T2o6gV9poV+EoslTYEyModH7AqvLrafKAJlEF+EGitxZa9HJlrSq:6r2pM/TYEy8fKAJqyuxZag
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109A51926B723C11BC8733BB1874B85C11EA5EB242922E8D732D86F8EAB75B513F15507
sha3_384: cbf0c72b2cea771260f95d5cc8e6e7707cd876f6058ae2253427bb410218d221b6e1108d832a48668fc5a7de5542654f
ep_bytes: c60540e5560000b900905e00ba04905e
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Pierogi!MSR also known as:

LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Variant.Ser.Strictor.772
ClamAVWin.Trojan.Micropsia-9811765-0
FireEyeGeneric.mg.3296b51479c75403
ALYacTrojan.Agent.Occamy.A
CylanceUnsafe
VIPREGen:Variant.Ser.Strictor.772
SangforTrojan.Win32.Agent.uppyg
K7AntiVirusSpyware ( 0055f3df1 )
AlibabaTrojanSpy:Win32/GnatSpy.88ea34b7
K7GWSpyware ( 0055f3df1 )
Cybereasonmalicious.479c75
VirITTrojan.Win32.Injector.CBB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Delf.QWY
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Dropper.Win32.Agent.vho
BitDefenderGen:Variant.Ser.Strictor.772
NANO-AntivirusTrojan.Win32.Delf.hctomq
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.1201f25c
Ad-AwareGen:Variant.Ser.Strictor.772
EmsisoftGen:Variant.Ser.Strictor.772 (B)
F-SecureHeuristic.HEUR/AGEN.1211980
ZillyaDropper.Agent.Win32.411784
TrendMicroTROJ_GEN.R002C0PGQ22
McAfee-GW-EditionPWS-FCNB!3296B51479C7
SophosMal/Generic-S + Troj/Agent-BDPD
GDataGen:Variant.Ser.Strictor.772
JiangminTrojanDropper.Agent.gjiv
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1211980
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.6
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Ser.Strictor.772
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.vho
MicrosoftTrojan:Win32/Pierogi!MSR
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2735872
McAfeePWS-FCNB!3296B51479C7
VBA32BScope.TrojanDropper.Agent
MalwarebytesTrojan.MalPack.DLF.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PGQ22
RisingBackdoor.[APT-C-23]Micropsia!1.C3A9 (CLASSIC)
YandexTrojan.GenAsa!CArowKoEJrg
IkarusTrojan.GnatSpy
MaxSecureTrojan.Malware.74459655.susgen
FortinetRiskware/Agent
BitDefenderThetaGen:NN.ZexaCO.34606.aEW@aGKJCZmi
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Pierogi!MSR?

Trojan:Win32/Pierogi!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment