Malware

Generic.MSIL.PasswordStealerA.787B0EFA (file analysis)

Malware Removal

The Generic.MSIL.PasswordStealerA.787B0EFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.787B0EFA virus can do?

  • Network activity detected but not expressed in API logs
  • Unusual version info supplied for binary

How to determine Generic.MSIL.PasswordStealerA.787B0EFA?


File Info:

crc32: DE7A1D00
md5: 4cd5f412f60f1ce0df998f6bd6982094
name: tmp.bin
sha1: 334a4fd8c76254a6860be689531bf708a5e0f6bf
sha256: a8725eb31a1bc74be415ae4290bdde4fb524c4e6002c35b98ddd279df3bdfb95
sha512: 55ebf6a39a0292ace7a3a4478bc5b4746aa321d601dba567e0bc019da76709e29a332ba1a5e02b3d2aa6f988b1e0a2cec43f989b27d2b61f504c0f1b49be2d01
ssdeep: 49152:W4y0Xd8YgEgPWrSRuRyfjCe26IFSxza32ehyfTnD:W4Bt8edbRyfOiD
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 10.0.18362.836
InternalName: ntoskrnl
FileVersion: 10.0.18362.836
CompanyName: ntoskrnl
LegalTrademarks: ntoskrnl
Comments:
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.18362.836
FileDescription: NT Kernel & System
OriginalFilename: ntoskrnl

Generic.MSIL.PasswordStealerA.787B0EFA also known as:

MicroWorld-eScanGeneric.MSIL.PasswordStealerA.787B0EFA
FireEyeGeneric.mg.4cd5f412f60f1ce0
McAfeeGenericRXKZ-ZO!4CD5F412F60F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Downeks.l!c
BitDefenderGeneric.MSIL.PasswordStealerA.787B0EFA
Cybereasonmalicious.2f60f1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CQF
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.Downeks-6898097-0
KasperskyHEUR:Trojan-Spy.MSIL.Downeks.gen
AlibabaTrojanSpy:MSIL/Perseus.72ac6dd0
RisingSpyware.Downeks!8.E248 (CLOUD)
Ad-AwareGeneric.MSIL.PasswordStealerA.787B0EFA
EmsisoftGeneric.MSIL.PasswordStealerA.787B0EFA (B)
F-SecureHeuristic.HEUR/AGEN.1135947
DrWebBackDoor.QuasarNET.3
MaxSecureTrojan.Malware.300983.susgen
TrendMicroTROJ_GEN.R002C0DGO20
FortinetMSIL/Agent.CQF!tr
AviraHEUR/AGEN.1135947
MAXmalware (ai score=81)
ArcabitGeneric.MSIL.PasswordStealerA.787B0EFA
ZoneAlarmHEUR:Trojan-Spy.MSIL.Downeks.gen
MicrosoftTrojan:MSIL/Perseus.AKR!MTB
CynetMalicious (score: 85)
AhnLab-V3Spyware/Win32.Quasar.C4157501
ALYacGeneric.MSIL.PasswordStealerA.787B0EFA
PandaTrj/GdSda.A
TencentMsil.Trojan-spy.Downeks.Phgv
GDataGeneric.MSIL.PasswordStealerA.787B0EFA
BitDefenderThetaGen:NN.ZemsilF.34138.Uo0@au@BfDe
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generic.MSIL.PasswordStealerA.787B0EFA?

Generic.MSIL.PasswordStealerA.787B0EFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment