Malware

How to remove “FileRepMetagen [Malware]”?

Malware Removal

The FileRepMetagen [Malware] file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What FileRepMetagen [Malware] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • The sample wrote data to the system hosts file.
  • Collects information to fingerprint the system

How to determine FileRepMetagen [Malware]?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: DeepScan:Generic.MSIL.PasswordStealerD.2B35556A (B)

File Info:

Name: 2020.exe

Size: 327680

Type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

MD5: 89cfd747c8f05f8bacbbad3196662377

SHA1: 2f031bf08ff5752675e85e65bb96f1de77142a4d

SH256: c65fca681836bfa3a15a88e1d0bd1efba388b8d7055ca61d67d756854578edf7

Version Info:

[No Data]

FileRepMetagen [Malware] also known as:

ALYacDeepScan:Generic.MSIL.PasswordStealerD.2B35556A
APEXMalicious
AVGFileRepMetagen [Malware]
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerD.2B35556A
AegisLabTrojan.Win32.DeepScan.4!c
AhnLab-V3Trojan/Win32.AgentTesla.C3450450
AlibabaTrojanPSW:MSIL/Agensla.2a4bdd4f
Antiy-AVLTrojan/Win32.Wacatac
ArcabitDeepScan:Generic.MSIL.PasswordStealerD.2B35556A
AvastFileRepMetagen [Malware]
AviraTR/Dropper.Gen
BitDefenderDeepScan:Generic.MSIL.PasswordStealerD.2B35556A
BitDefenderThetaAI:Packer.0B9C437920
CAT-QuickHealTrojan.Wacatac
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.7c8f05
CylanceUnsafe
CyrenW32/Trojan.RINM-1129
ESET-NOD32a variant of MSIL/Spy.Agent.AES
EmsisoftDeepScan:Generic.MSIL.PasswordStealerD.2B35556A (B)
Endgamemalicious (high confidence)
F-ProtW32/MSIL_Troj.RC.gen!Eldorado
F-SecureTrojan.TR/Dropper.Gen
FireEyeGeneric.mg.89cfd747c8f05f8b
FortinetMSIL/Agent.AES!tr.spy
GDataDeepScan:Generic.MSIL.PasswordStealerD.2B35556A
IkarusTrojan.MSIL.Spy
Invinceaheuristic
K7AntiVirusSpyware ( 004bf53c1 )
K7GWSpyware ( 004bf53c1 )
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
MAXmalware (ai score=100)
MalwarebytesSpyware.AgentTesla.MSIL
MaxSecureTrojan.Malware.300983.susgen
McAfeeGenericRXII-SF!89CFD747C8F0
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerD.2B35556A
MicrosoftBackdoor:MSIL/Remcos!MTB
NANO-AntivirusTrojan.Win32.Mlw.gfscwh
Paloaltogeneric.ml
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.PWS.d75
RisingSpyware.AgentTesla!1.B864 (CLASSIC)
SentinelOneDFI – Malicious PE
SophosMal/Generic-S
SymantecTrojan.Gen.MBT
Trapminemalicious.moderate.ml.score
TrendMicroTROJ_GEN.R002C0PK419
TrendMicro-HouseCallTROJ_GEN.R002C0PK419
VIPRETrojan.Win32.Generic!BT
WebrootW32.Trojan.Gen
ZillyaTrojan.Agent.Win32.1167353
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
eGambitUnsafe.AI_Score_99%

How to remove FileRepMetagen [Malware]?

FileRepMetagen [Malware] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment