Malware

What is “Generic.MSIL.PasswordStealerA.924F7BE4”?

Malware Removal

The Generic.MSIL.PasswordStealerA.924F7BE4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.924F7BE4 virus can do?

  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyip.akamai.com
whatismyip.everdot.org

How to determine Generic.MSIL.PasswordStealerA.924F7BE4?


File Info:

crc32: FC991503
md5: ed916335ff843b4efde777d7ec5c3e87
name: 5cffdc34c68196d6.exe
sha1: 58a4d582bbb8e2d58c30bfa41bc67a8a5bc465b9
sha256: 79933cf802a06ba23d9ee85dca229acd3463190a6df621663cf27021f497fe3d
sha512: cda9213939e46998d424e7b42a1a9dfe63da35bac7c38dbabcbde3df815612d4d20cab95e335d16fc7379c665a7589709f377e10f0d6ae6c83818d88735219b4
ssdeep: 384:lfQX4MI63cKWYvsA5wc5iv8TSQuX+Vd7er6LSYtvaUaLciMdMeqVwZ4yAXUbP:lfC4MX36YExoU+VI69vhiH84yAk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.MSIL.PasswordStealerA.924F7BE4 also known as:

MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4
CAT-QuickHealTrojanSpy.Usteal.D.mue
Qihoo-360Win32/Trojan.458
McAfeeTrojan-FBXH!ED916335FF84
CylanceUnsafe
VIPRETrojan-Spy.Win32.Usteal.da (v)
SangforMalware
K7AntiVirusTrojan ( 00012a951 )
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4
K7GWTrojan ( 00012a951 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTrojanSpy.Win32.USTEAL.SMTH
BitDefenderThetaAI:Packer.E5BFC2801F
F-ProtW32/Usteal.A.gen!Eldorado
SymantecInfostealer.Ldpinch!g2
APEXMalicious
AvastWin32:Agent-AVIF [Trj]
ClamAVWin.Trojan.Usteal-1
GDataDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Dorv.b930a2c4
NANO-AntivirusTrojan.Win32.Usteal.eriozk
AegisLabTrojan.Win32.Generic.ltoQ
TencentWin32.Trojan.Generic.Anph
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4
SophosMal/Anomaly-A
ComodoMalware@#190a74ix9810
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.PWS.UFR.3724
Invinceaheuristic
McAfee-GW-EditionTrojan-FBXH!ED916335FF84
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ed916335ff843b4e
EmsisoftDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4 (B)
IkarusTrojan-Spy.Win32.Usteal
CyrenW32/Usteal.A.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
Endgamemalicious (high confidence)
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Dorv.A
AhnLab-V3Trojan/Win32.Ruftar.R22332
Acronissuspicious
ALYacDeepScan:Generic.MSIL.PasswordStealerA.924F7BE4
MAXmalware (ai score=84)
VBA32TrojanPSW.UFR
ESET-NOD32a variant of Win32/Spy.Usteal.C
TrendMicro-HouseCallTrojanSpy.Win32.USTEAL.SMTH
RisingSpyware.Usteal!8.307 (CLOUD)
YandexTrojan.FruStealer.Gen.LG
SentinelOneDFI – Suspicious PE
FortinetW32/ZBOT.CDL!tr
AVGWin32:Agent-AVIF [Trj]
Cybereasonmalicious.5ff843
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.MSIL.PasswordStealerA.924F7BE4?

Generic.MSIL.PasswordStealerA.924F7BE4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment