Threat Database Trojans Trojan.MSIL.Perseus.AJ

Trojan.MSIL.Perseus.AJ

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: January 4, 2024
Last Seen: January 14, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Perseus.AJ on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system. Understanding the nature of this threat is crucial in mitigating its effects and securing your computer against future vulnerabilities.

What Is Trojan.MSIL.Perseus.AJ?

Trojan.MSIL.Perseus.AJ is identified as a Trojan-type threat. Trojans are malicious programs that can cause harm to your computer system by allowing unauthorized access to your system, stealing data, or installing additional malware. The name suggests it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic, object-oriented programming language used by the.NET Framework. This implies that the malware can potentially run on any system that supports the.NET Framework, making it versatile and potentially widespread.

How Trojan.MSIL.Perseus.AJ Operates

Like other Trojans, Trojan.MSIL.Perseus.AJ operates by disguising itself as legitimate software to gain entry into a system. Once inside, it can perform a variety of malicious actions, including but not limited to, data theft, installation of additional malware, and creation of backdoors for remote access by attackers. The specific operations of Trojan.MSIL.Perseus.AJ can vary, but its primary goal is to compromise the security and integrity of the infected system for malicious purposes.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as slow performance, frequent crashes, or pop-ups and unwanted software installations. Additionally, if your antivirus software is disabled or your firewall settings are altered without your knowledge, it could be a sign of a Trojan infection. Since Trojans can act as backdoors, the presence of unauthorized access or unexpected network activity could also signal an infection.

  • Unexplained changes in system settings or files
  • Appearance of unknown or suspicious programs
  • Increased network activity without apparent cause
  • System crashes or instability

How to Remove Trojan.MSIL.Perseus.AJ

  1. Boot into Safe Mode with Networking: This will limit the malware's ability to run and make it easier to remove. To do this, restart your computer and repeatedly press the F8 key until the Advanced Boot Options menu appears. Select Safe Mode with Networking and press Enter.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions before scanning.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or unfamiliar. Be cautious and only uninstall programs you are sure are malicious or unnecessary.
  4. Reset Your Browser Settings: If your browser settings have been altered, reset them to their default state. This can usually be done through the browser's settings or options menu. For Chrome, Firefox, and Edge, you can find these options under their respective settings menus.
  5. Reboot and Re-scan: After removal and cleanup, reboot your system and perform another full scan to ensure all remnants of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Perseus.AJ requires careful and systematic steps to ensure the malware is completely eradicated from your system. It's crucial to stay vigilant and maintain good security practices to prevent future infections. Keeping your operating system, software, and security tools up to date, avoiding suspicious downloads, and using strong, unique passwords can significantly reduce the risk of malware infections. If you're unsure about any part of the removal process, consider consulting with a security professional to ensure your system is thoroughly cleaned and protected.

Analysis Report

General information

Family Name: Trojan.MSIL.Perseus.AJ
Signature status: No Signature

Known Samples

MD5: 54fedbf5b1967529b49b9ea6dbc3fa7e
SHA1: 26f63a08efd886a9121d13b26766dcf3c341a9ab
SHA256: 474BD6D9A899EFE56C55D41F0EAD73E04B5D79A48E2A2C501C1B0B8C4C0BB548
File Size: 21.50 KB, 21504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description Resolvedor de problemas
File Version 1.0.0.0
Internal Name Resolvedor de problemas.exe
Legal Copyright Copyright © 2023
Original Filename Resolvedor de problemas.exe
Product Name Resolvedor de problemas
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 44
Potentially Malicious Blocks: 11
Whitelisted Blocks: 18
Unknown Blocks: 15

Visual Map

? ? ? ? ? ? ? ? 0 ? 0 0 0 0 x ? 0 x 0 0 0 0 x ? 0 x x ? ? x 0 x x 0 x 0 0 0 x 0 x ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\downloads\requisitos.zip Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • getaddrinfo
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetNetworkParams

Related Posts

Trending

Most Viewed

Loading...