Malware

What is “Generic.MSIL.PasswordStealerA.494BEA5E”?

Malware Removal

The Generic.MSIL.PasswordStealerA.494BEA5E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.494BEA5E virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the QuasarRAT malware family
  • Binary file triggered YARA rule

How to determine Generic.MSIL.PasswordStealerA.494BEA5E?


File Info:

name: 785403F3F5598E31668A.mlw
path: /opt/CAPEv2/storage/binaries/b8c73725434ef932337053115883c9cb73c2808c228ade9fbc4326906ffce50a
crc32: D69E2FC3
md5: 785403f3f5598e31668a65557788ca2d
sha1: bf2d1f35a9c915ee1b570750e797fc2e9cd9b6b0
sha256: b8c73725434ef932337053115883c9cb73c2808c228ade9fbc4326906ffce50a
sha512: c1f1aaf30196a804aabc28558d50227645aa3fbe6c217ba00f956287e71c37460951a613b7add3dd6edaf84b9234b8cbc612b76e2c8774a4d0e1faff8dc3a546
ssdeep: 6144:216bPXhLApfpn4MT5IIIIIoiThWbh2SkHqfA7NBJ2:2mhAp2MToS2SkKfSN72
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171748D13B7E4E63BD1FE1B3AE13206055BB0D483B616E38B5A5855F82D133868E593B3
sha3_384: dff6f963cdfc4628f2bf68dfdb04a467862c73a1fb2c93818521cc1efd68cbfd375efce56f70d2714364a93501e3b25f
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-04-11 10:30:24

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.3.0.0
InternalName: Client.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Client.exe
ProductName:
ProductVersion: 1.3.0.0
Assembly Version: 1.3.0.0

Generic.MSIL.PasswordStealerA.494BEA5E also known as:

BkavW32.AIDetectMalware.CS
ElasticWindows.Trojan.Quasarrat
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.494BEA5E
FireEyeGeneric.mg.785403f3f5598e31
SkyhighBehavesLike.Win32.Generic.fh
McAfeePWS-FCOI!785403F3F559
Cylanceunsafe
ZillyaTrojan.Agent.Win32.2530512
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/Quasar.85648e5d
K7GWTrojan ( 00521dab1 )
K7AntiVirusTrojan ( 00521dab1 )
VirITTrojan.Win32.MSIL_Heur.B
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.AES
APEXMalicious
AvastMSIL:Rat-B [Trj]
KasperskyTrojan.MSIL.Agent.foww
BitDefenderGeneric.MSIL.PasswordStealerA.494BEA5E
SUPERAntiSpywareTrojan.Agent/Gen-PasswordStealer
TencentTrojan.MSIL.Agent.hc
EmsisoftGeneric.MSIL.PasswordStealerA.494BEA5E (B)
F-SecureTrojan:w32/QuasarRAT.A1
DrWebTrojan.DownLoader27.59888
VIPREGeneric.MSIL.PasswordStealerA.494BEA5E
TrendMicroTSPY_TINCLEX.SM1
Trapminemalicious.moderate.ml.score
SophosATK/Zaquar-D
JiangminTrojan.Generic.ajfvk
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1307329
MAXmalware (ai score=86)
Antiy-AVLTrojan/MSIL.Agent
Kingsoftmalware.kb.c.1000
MicrosoftBackdoor:MSIL/Quasar.GG!MTB
ArcabitGeneric.MSIL.PasswordStealerA.494BEA5E
ViRobotTrojan.Win.Z.Agent.356352.IH
ZoneAlarmTrojan.MSIL.Agent.foww
GDataMSIL.Backdoor.Quasar.D
VaristW32/MSIL_Mintluks.A.gen!Eldorado
AhnLab-V3Trojan/Win32.Subti.R285137
VBA32Trojan.MSIL.Quasar.Heur
ALYacGeneric.MSIL.PasswordStealerA.494BEA5E
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_TINCLEX.SM1
RisingBackdoor.xRAT!1.D01D (CLASSIC)
IkarusBackdoor.QuasarRat
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Emotet.5C62!tr
BitDefenderThetaGen:NN.ZemsilF.36802.vm0@a4kH3rl
AVGMSIL:Rat-B [Trj]
DeepInstinctMALICIOUS
alibabacloudBackdoor:MSIL/Quasar.server

How to remove Generic.MSIL.PasswordStealerA.494BEA5E?

Generic.MSIL.PasswordStealerA.494BEA5E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment