Malware

How to remove “Generic.MSIL.PasswordStealerA.486422DB”?

Malware Removal

The Generic.MSIL.PasswordStealerA.486422DB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.486422DB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the OrcusRAT malware family

How to determine Generic.MSIL.PasswordStealerA.486422DB?


File Info:

name: 0D226130F3A954C872EE.mlw
path: /opt/CAPEv2/storage/binaries/d97f7ff3f9fa3d766252951149fc6d5ac3852de028b4a2ca7afdbedca9a0d4b3
crc32: 9104CB51
md5: 0d226130f3a954c872ee11ae303e0936
sha1: 269a9b6d6146a2439b768e87b8e63283b57997a7
sha256: d97f7ff3f9fa3d766252951149fc6d5ac3852de028b4a2ca7afdbedca9a0d4b3
sha512: 2a8173ea16d01437568c3fc8d051ae0e85ca2c44c266a972192d372827c8f00ec2eb956e08e55f4798dc3a01313767b12817681b27a3019b0c455a7ac28b6cdf
ssdeep: 24576:Pj54MROxnFj3dBukhrrcI0AilFEvxHP0ooX:PyMi1KqrrcI0AilFEvxHP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B15BF013FACBD47C1BE3679B7731ACA07B8E90A6052FB4E085451AE1D9BB01BD16367
sha3_384: 082f6fc6daf891bed6250c4bd2479dca7b76314352f2d250ac92fc325f8961fff3d48d6608612ed5bf7c2c842c7b7c3e
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-05-25 00:03:39

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Orcus.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Orcus.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Generic.MSIL.PasswordStealerA.486422DB also known as:

LionicTrojan.Win32.Generic.4!c
AVGWin32:CrypterX-gen [Trj]
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.486422DB
FireEyeGeneric.mg.0d226130f3a954c8
CAT-QuickHealTrojan.MsilFC.S6059605
ALYacGeneric.MSIL.PasswordStealerA.486422DB
Cylanceunsafe
ZillyaTrojan.Orcusrat.Win32.1963
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005011a81 )
K7GWTrojan ( 005011a81 )
Cybereasonmalicious.0f3a95
VirITTrojan.Win32.Dnldr25.VFT
CyrenW32/Orcus.A.gen!Eldorado
SymantecTrojan.Sorcurat
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Orcusrat.D
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Generic-9805849-0
KasperskyHEUR:Trojan-Spy.MSIL.Generic
BitDefenderGeneric.MSIL.PasswordStealerA.486422DB
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:CrypterX-gen [Trj]
TencentBackdoor.MSIL.Orcusrat.ha
SophosTroj/OrcusRAT-A
F-SecureHeuristic.HEUR/AGEN.1352044
DrWebTrojan.DownLoader28.34223
VIPREGeneric.MSIL.PasswordStealerA.486422DB
TrendMicroBKDR_ORCUSRAT.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminesuspicious.low.ml.score
EmsisoftBackdoor.Orcus (A)
IkarusTrojan.MSIL.Orcusrat
JiangminTrojanSpy.MSIL.sam
WebrootW32.Trojan.MSIL
AviraHEUR/AGEN.1352044
Antiy-AVLTrojan[Spy]/MSIL.Agent
XcitiumTrojWare.MSIL.Orcusrat.D@8ftc87
ArcabitGeneric.MSIL.PasswordStealerA.D76C16DB
ZoneAlarmHEUR:Trojan-Spy.MSIL.Generic
GDataMSIL.Backdoor.Orcus.A
GoogleDetected
AhnLab-V3Win-Trojan/OrcusRAT.Exp
Acronissuspicious
McAfeeBackDoor-FDJE!0D226130F3A9
MAXmalware (ai score=87)
VBA32Trojan.MSIL.InfoStealer.gen
MalwarebytesCrypt.Trojan.MSIL.DDS
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ORCUSRAT.SM
RisingBackdoor.Orcus!1.B603 (CLASSIC)
YandexTrojan.Agent!EK6I3Utgth8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.ASJ!tr
BitDefenderThetaGen:NN.ZemsilF.36196.4m0@aeyUdkn
ZonerTrojan.Win32.88032
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.PasswordStealerA.486422DB?

Generic.MSIL.PasswordStealerA.486422DB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment