Malware

Generic.MSIL.PasswordStealerA.124DC958 (file analysis)

Malware Removal

The Generic.MSIL.PasswordStealerA.124DC958 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.124DC958 virus can do?

  • Authenticode signature is invalid
  • CAPE detected the QuasarStealer malware family

How to determine Generic.MSIL.PasswordStealerA.124DC958?


File Info:

name: A28F0F9018DD71918EF4.mlw
path: /opt/CAPEv2/storage/binaries/635c76db4a7898ac1eee72222e6d87f6a855d9b8a896eb2dd8eecee10261eaac
crc32: B423F6FA
md5: a28f0f9018dd71918ef4c88d733657a5
sha1: 65ace44c149e2328b0e3b81843838ba83eeb9d3e
sha256: 635c76db4a7898ac1eee72222e6d87f6a855d9b8a896eb2dd8eecee10261eaac
sha512: 57922e020f541d9323f4435138a84dec676588423c80b10dc9e4111175b90f36a98e0b698aaf5d2ddc75b04edb7b10a0a5d200058ccdb5f3a5aa36b6f67bf176
ssdeep: 49152:3vRuf2NUaNmwzPWlvdaKM7ZxTwygKstlKoGdGTHHB72eh2NT:3vsf2NUaNmwzPWlvdaB7ZxTwygKstw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEE54A1437F85E22E16BD2B3D5F0541363F1F82AF3A3EB0B6181A67E2C93B5158416A7
sha3_384: a9361a74a65d81bf3973322a7beb37015c0e18e7359a12f7c9379c668672c4fcdf8b53c8ad1b053606c8db54c4ed7707
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-03-12 16:16:39

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: solo
FileDescription: solo
FileVersion: 1.2.0.1
InternalName: solo
LegalCopyright: solo
LegalTrademarks:
OriginalFilename: solo
ProductName: solo
ProductVersion: 1.2.0.1
Assembly Version: 1.2.0.1

Generic.MSIL.PasswordStealerA.124DC958 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.TRFH927
McAfeeGenericRXMC-UD!A28F0F9018DD
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.MSIL_Heur.B
CyrenW32/MSIL_Troj.BTX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CLQ
APEXMalicious
ClamAVWin.Malware.Generic-9883083-0
KasperskyHEUR:Trojan.MSIL.Quasar.gen
BitDefenderGeneric.MSIL.PasswordStealerA.124DC958
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.124DC958
AvastMSIL:Quasar-A [Rat]
TencentTrojan.MSIL.Quasar.ka
EmsisoftGeneric.MSIL.PasswordStealerA.124DC958 (B)
F-SecureHeuristic.HEUR/AGEN.1305743
DrWebBackDoor.QuasarNET.3
VIPREGeneric.MSIL.PasswordStealerA.124DC958
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
FireEyeGeneric.mg.a28f0f9018dd7191
SophosML/PE-A
IkarusTrojan-Spy.Agent
JiangminTrojan.MSIL.aogzw
AviraHEUR/AGEN.1305743
Antiy-AVLTrojan/MSIL.Quasar
MicrosoftBackdoor:MSIL/Quasar!pz
ArcabitGeneric.MSIL.PasswordStealerA.124DC958
ZoneAlarmHEUR:Trojan.MSIL.Quasar.gen
GDataMSIL.Backdoor.Quasar.A
GoogleDetected
AhnLab-V3Backdoor/Win32.QuasarRAT.R341693
BitDefenderThetaGen:NN.ZemsilF.36722.hp0@aK6yZ7j
ALYacGeneric.MSIL.PasswordStealerA.124DC958
MAXmalware (ai score=82)
VBA32Trojan.MSIL.Quasar.Heur
Cylanceunsafe
RisingBackdoor.Quasar!1.E5F1 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BPH!tr
AVGMSIL:Quasar-A [Rat]
Cybereasonmalicious.c149e2
DeepInstinctMALICIOUS

How to remove Generic.MSIL.PasswordStealerA.124DC958?

Generic.MSIL.PasswordStealerA.124DC958 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment