Malware

Generic.MSIL.PasswordStealerA.5FC63CFB (file analysis)

Malware Removal

The Generic.MSIL.PasswordStealerA.5FC63CFB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.5FC63CFB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generic.MSIL.PasswordStealerA.5FC63CFB?


File Info:

crc32: 691A3858
md5: 612b53da813d4debb74a39b577b3ec5c
name: 612B53DA813D4DEBB74A39B577B3EC5C.mlw
sha1: 2cf55ce08a54fb428e468bdec387b5ba5109f6d0
sha256: 59a6a0edbbf6d4a6a98381fb013a1ff150411052f53ad92e1369a612fee5134b
sha512: b436a38fa06f975a3ff65170d805449ad62a621df805b2524e67f8dbe338b5a1f608655ae696cadbe0eb12db59e02503e80c5d0d76ce220e92fbd87e07aff1f0
ssdeep: 24576:riC4MROxnFt3/NrrcI0AilFEvxHPFooS:ruMijlrrcI0AilFEvxHP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2018 Discord Inc. All rights reserved.
InternalName: Discord.exe
FileVersion: 0.0.308
CompanyName: Discord Inc.
SquirrelAwareVersion: 1
ProductName: Discord
ProductVersion: 0.0.308
FileDescription: Discord
OriginalFilename: Discord.exe
Translation: 0x0409 0x04b0

Generic.MSIL.PasswordStealerA.5FC63CFB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader24.57377
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.5FC63CFB
FireEyeGeneric.mg.612b53da813d4deb
McAfeeBackDoor-FDJE!612B53DA813D
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGeneric.MSIL.PasswordStealerA.5FC63CFB
CrowdStrikewin/malicious_confidence_80% (D)
InvinceaML/PE-A + Troj/Orcusrot-A
BitDefenderThetaGen:NN.ZemsilF.34634.8m0@ai7j9wmi
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Packed.Passwordstealera-9752380-0
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
TencentMalware.Win32.Gencirc.11b0ff21
Ad-AwareGeneric.MSIL.PasswordStealerA.5FC63CFB
SophosTroj/Orcusrot-A
F-SecureHeuristic.HEUR/AGEN.1128549
ZillyaTrojan.Generic.Win32.1250126
TrendMicroBKDR_ORCUSRAT.SM
McAfee-GW-EditionBackDoor-FDJE!612B53DA813D
EmsisoftGeneric.MSIL.PasswordStealerA.5FC63CFB (B)
IkarusTrojan.MSIL.Agent
JiangminTrojanSpy.MSIL.sam
MaxSecureTrojan.Malware.11205094.susgen
AviraHEUR/AGEN.1128549
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftBackdoor:MSIL/Orcus.A!bit
ArcabitGeneric.MSIL.PasswordStealerA.5FC63CFB
ZoneAlarmHEUR:Trojan-Spy.MSIL.Agent.gen
GDataMSIL.Backdoor.Orcus.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/OrcusRAT.Exp
VBA32Trojan.Downloader
MAXmalware (ai score=86)
MalwarebytesBackdoor.Orcus
ESET-NOD32a variant of MSIL/Orcusrat.D
TrendMicro-HouseCallBKDR_ORCUSRAT.SM
RisingBackdoor.Orcus!1.BABC (CLASSIC)
YandexTrojan.Orcusrat!hVAd2OrnzH8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Generic.AP.F529E!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.a813d4
Qihoo-360HEUR/QVM03.0.3A86.Malware.Gen

How to remove Generic.MSIL.PasswordStealerA.5FC63CFB?

Generic.MSIL.PasswordStealerA.5FC63CFB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment