Malware

Generic.MSIL.PasswordStealerA.26ADC53D (file analysis)

Malware Removal

The Generic.MSIL.PasswordStealerA.26ADC53D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.26ADC53D virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine Generic.MSIL.PasswordStealerA.26ADC53D?


File Info:

crc32: 67626609
md5: e5c9119ff3c6932e544c6434d70dda5f
name: E5C9119FF3C6932E544C6434D70DDA5F.mlw
sha1: 9325ddc9eaf29b1ddb4b0c50f9bfb30c72a3ee88
sha256: 0c3a1e4598b32bfcdf0226964c07af858c56e22c112fc4719f833738733958b8
sha512: 9ad208ea9373e16e3bf40a8690a4939dff5ab3776145fae077cd130551c77bafcf89cd112f96e9a32234e01f887400103315fb075d9b1abfd0bdb349684c9d82
ssdeep: 12288:agfe07KFML7iLMucoUe7dG1lFlWcYT70pxnnaaoawoRVcTqSA+9rZNrI0AilFEv:rtY4MROxnFJLqrZlI0AilFEvxHiZt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Riot Games
Assembly Version: 1.0.0.0
InternalName: League Skins
FileVersion: 2.0.0.0
CompanyName: Riot Games
LegalTrademarks: TM
Comments:
ProductName: League skins
ProductVersion: 4.0.0.0
FileDescription: Riot
OriginalFilename: Orcus.exe

Generic.MSIL.PasswordStealerA.26ADC53D also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.14206
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.26ADC53D
ALYacGeneric.MSIL.PasswordStealerA.26ADC53D
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005011a81 )
BitDefenderGeneric.MSIL.PasswordStealerA.26ADC53D
K7GWTrojan ( 005011a81 )
Cybereasonmalicious.ff3c69
BitDefenderThetaGen:NN.ZemsilF.34590.4m0@aGEzVZd
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Packed.Passwordstealera-9803747-0
KasperskyHEUR:Trojan-Spy.MSIL.Generic
RisingBackdoor.Orcus!1.B603 (CLASSIC)
Ad-AwareGeneric.MSIL.PasswordStealerA.26ADC53D
EmsisoftGeneric.MSIL.PasswordStealerA.26ADC53D (B)
ComodoTrojWare.MSIL.Orcusrat.D@8ftc87
F-SecureHeuristic.HEUR/AGEN.1128549
TrendMicroBKDR_ORCUSRAT.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.e5c9119ff3c6932e
SophosML/PE-A + Troj/Orcusrot-A
IkarusTrojan.MSIL.Agent
JiangminTrojan.Generic.awmpo
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1128549
MicrosoftWorm:Win32/Ainslot
GridinsoftTrojan.Win32.RemoteAccess.ka!ni
ArcabitGeneric.MSIL.PasswordStealerA.26ADC53D
ZoneAlarmHEUR:Trojan-Spy.MSIL.Generic
GDataMSIL.Backdoor.Orcus.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/OrcusRAT.Exp
McAfeeBackDoor-FDJE!E5C9119FF3C6
MAXmalware (ai score=83)
VBA32Trojan.Downloader
MalwarebytesQbot.Backdoor.Stealer.DDS
ESET-NOD32a variant of MSIL/Orcusrat.D
TrendMicro-HouseCallBKDR_ORCUSRAT.SM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMalwThreat!a325IV
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.8B12.Malware.Gen

How to remove Generic.MSIL.PasswordStealerA.26ADC53D?

Generic.MSIL.PasswordStealerA.26ADC53D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment