Malware

Generic.MSIL.PasswordStealerA.7C929756 removal guide

Malware Removal

The Generic.MSIL.PasswordStealerA.7C929756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.7C929756 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.MSIL.PasswordStealerA.7C929756?


File Info:

crc32: B194EC73
md5: 3f6eac5e302d3ab1afea43f7082ecd38
name: 3F6EAC5E302D3AB1AFEA43F7082ECD38.mlw
sha1: 81b0296d3b7d26c5f49b37efb16f4ef629a4515a
sha256: d92ee183633151e24c7ab0e670f8cd15f41defcf9b927780176d9b7bbe3c97f1
sha512: 5b7dbe9db064c2f395617f960d0ee5043f235d207d0d95fc8a0cc4e3399e01755b7be29d3e558c1fa7b9ea0d60edf03e8e587b21678732d67a696de22b5bc58b
ssdeep: 12288:rL1gSBMAwLgF5Vk37dG1lFlWcYT70pxnnaaoawylBa2Ley+trZNrI0AilFEvxHv:e6w4MROxnFzay6rZlI0AilFEvxHifh
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Orcus.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: Orcus.exe

Generic.MSIL.PasswordStealerA.7C929756 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S17035747
McAfeeBackDoor-FDJE!3F6EAC5E302D
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005011a81 )
AlibabaWorm:Win32/Ainslot.aa69b389
K7GWTrojan ( 005011a81 )
Cybereasonmalicious.e302d3
BitDefenderThetaGen:NN.ZemsilF.34688.!m0@aafvHfp
CyrenW32/MSIL_Injector.KK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Orcusrat.D
TrendMicro-HouseCallBKDR_ORCUSRAT.SM
Paloaltogeneric.ml
ClamAVWin.Packed.Passwordstealera-9803747-0
KasperskyHEUR:Trojan-Spy.MSIL.Generic
BitDefenderGeneric.MSIL.PasswordStealerA.7C929756
SUPERAntiSpywareTrojan.Agent/Gen-Injector
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.7C929756
Ad-AwareGeneric.MSIL.PasswordStealerA.7C929756
SophosMal/Generic-R + Troj/Orcusrot-A
ComodoMalware@#1bjj8ogqxzt2d
F-SecureHeuristic.HEUR/AGEN.1128549
DrWebTrojan.DownLoader24.65022
TrendMicroBKDR_ORCUSRAT.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.3f6eac5e302d3ab1
EmsisoftBackdoor.Orcus (A)
APEXMalicious
JiangminTrojan.Generic.awmpo
AviraHEUR/AGEN.1128549
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/MSIL.Orcus
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftWorm:Win32/Ainslot
GridinsoftTrojan.Win32.RemoteAccess.ka!ni
ArcabitGeneric.MSIL.PasswordStealerA.7C929756
AegisLabTrojan.MSIL.Generic.l!c
ZoneAlarmHEUR:Trojan-Spy.MSIL.Generic
GDataMSIL.Backdoor.Orcus.A
SentinelOneStatic AI – Malicious PE
AhnLab-V3Win-Trojan/OrcusRAT.Exp
VBA32Trojan.Downloader
ALYacGeneric.MSIL.PasswordStealerA.7C929756
MalwarebytesBackdoor.Orcus
ZonerTrojan.Win32.75536
RisingBackdoor.Orcus!1.B603 (CLASSIC)
IkarusTrojan.MSIL.Agent
eGambitUnsafe.AI_Score_97%
FortinetMSIL/Generic.AP.F529E!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.Spy.c29

How to remove Generic.MSIL.PasswordStealerA.7C929756?

Generic.MSIL.PasswordStealerA.7C929756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment