Malware

Generic.MSIL.PasswordStealerA.A08B9A47 removal guide

Malware Removal

The Generic.MSIL.PasswordStealerA.A08B9A47 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.A08B9A47 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Creates a copy of itself
  • Deletes executed files from disk
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system

How to determine Generic.MSIL.PasswordStealerA.A08B9A47?


File Info:

name: 0734E0C4FB42910E80B1.mlw
path: /opt/CAPEv2/storage/binaries/91b11fcfacea86c59e211e2308245430e1e1ac915c4a695cafa294033551be05
crc32: 1ED576FB
md5: 0734e0c4fb42910e80b17ac2dcdfcba9
sha1: 6eeeac52f50b1691e242ab201ac74fe51b0f6dcf
sha256: 91b11fcfacea86c59e211e2308245430e1e1ac915c4a695cafa294033551be05
sha512: 2c667e74949d78e6d2dce67e535622c9ae37a326b2e6218b90c3a7edc86c4eff129b32f5c503f505b46a6d6ff07009eb3ea8be4151cc799ecfedac2e85d6147d
ssdeep: 768:UTbhDIAZZcInthEAicuvGqd2LUI/I9AxKSfd0+D2//RlvZlZJ8ElWzlO49P7:2hHHqcuvGhhIWd10e2/Dr8ElWzz9P7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0932A0933498927D69CB6F6046942818AB96CBB8510D30F24F0FE993779B9BCC255FF
sha3_384: 9d3cde72ec80ea9899f160c4369e94e011d0c0ef834572017bf8b2cf59d0a30378dd46dc9a3d493522b9a63ab4e95e2f
ep_bytes: ff250020400000000000000000000000
timestamp: 2011-12-20 19:33:12

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Server.exe
LegalCopyright:
OriginalFilename: Server.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Generic.MSIL.PasswordStealerA.A08B9A47 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.ls0t
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.A08B9A47
FireEyeGeneric.mg.0734e0c4fb42910e
CAT-QuickHealTrojan.Generic.5264
ALYacGeneric.MSIL.PasswordStealerA.A08B9A47
MalwarebytesTrojan.Agent
ZillyaBackdoor.Ubot.Win32.17
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaBackdoor:MSIL/Mintluks.69e36879
K7GWTrojan ( 700000121 )
Cybereasonmalicious.4fb429
VirITTrojan.Win32.DownLoader11.BGNO
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.PK
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Bladabindi-7194433-0
KasperskyBackdoor.MSIL.Ubot.b
BitDefenderGeneric.MSIL.PasswordStealerA.A08B9A47
NANO-AntivirusTrojan.Win32.AVKill.dcmcqn
AvastMSIL:Agent-BJ [Trj]
TencentMsil.Backdoor.Ubot.Duq
Ad-AwareGeneric.MSIL.PasswordStealerA.A08B9A47
EmsisoftGeneric.MSIL.PasswordStealerA.A08B9A47 (B)
ComodoTrojWare.MSIL.PSW.Agent.ah@4pijgw
DrWebTrojan.DownLoader32.51776
VIPREGeneric.MSIL.PasswordStealerA.A08B9A47
TrendMicroTSPY_KEYLOG.SMIC
McAfee-GW-EditionGeneric PWS.ny
Trapminesuspicious.low.ml.score
SophosML/PE-A + Mal/MSIL-DR
SentinelOneStatic AI – Malicious PE
GDataGeneric.MSIL.PasswordStealerA.A08B9A47
JiangminBackdoor.MSIL.brio
WebrootW32.Backdoor.Gen
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.37E8
ArcabitGeneric.MSIL.PasswordStealerA.A08B9A47
ZoneAlarmBackdoor.MSIL.Ubot.b
MicrosoftPWS:MSIL/Mintluks.A
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Inject.C63895
Acronissuspicious
McAfeeGeneric PWS.ny
MAXmalware (ai score=100)
CylanceUnsafe
TrendMicro-HouseCallTSPY_KEYLOG.SMIC
RisingTrojan.Generic@AI.99 (RDMK:rm2U+k5VKNUXA3UVpFK+1A)
YandexBackdoor.Ubot!8Vszq0MWmTc
MaxSecureTrojan.Malware.2903509.susgen
FortinetMSIL/SpyPSW.AVQ!tr
BitDefenderThetaGen:NN.ZemsilF.34606.fm0@aeFmvZb
AVGMSIL:Agent-BJ [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.MSIL.PasswordStealerA.A08B9A47?

Generic.MSIL.PasswordStealerA.A08B9A47 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment