Malware

Generic.MSIL.PasswordStealerA.ABA2EFE6 removal guide

Malware Removal

The Generic.MSIL.PasswordStealerA.ABA2EFE6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.ABA2EFE6 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Generic.MSIL.PasswordStealerA.ABA2EFE6?


File Info:

name: A7EDB834286C34CF44A2.mlw
path: /opt/CAPEv2/storage/binaries/324736f6a1d531393c3798bb9a801b6376dab1813282b0f2a1711f0e8e122655
crc32: DEA44739
md5: a7edb834286c34cf44a2d0dca6f8e983
sha1: 3e58a92406c69042defcc830579348a79778be9f
sha256: 324736f6a1d531393c3798bb9a801b6376dab1813282b0f2a1711f0e8e122655
sha512: 44602c665df4c200aed550e3adff1094e000631fbcc9bda5ffb194faf8ddb26b8fc6812d4604a90a5f54a4c0f1b8004949c1ebbb285b9f67f81ec38d02c8010a
ssdeep: 24576:wgZXoZUTVdt7K0hnk3+k5bSlgkNuLYRp9efj2MGkBjeBmcSxka930JgthaXPQcbK:rhmzbSBgOpMfj2mj2m9F9kmhaXPQb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5551313F6C089B1D97211322E2B6B52E57CBC700B754ED7D3951C6DEE321D0AA33AA6
sha3_384: 5d30f0901c1662b0ddc7b312dff0dda6fea07570137922e5bf7d962cd672779aa67ca6cbdafc913aac949e24971ab0fb
ep_bytes: e8c6040000e978feffffcccccccccccc
timestamp: 2023-02-16 12:31:25

Version Info:

0: [No Data]

Generic.MSIL.PasswordStealerA.ABA2EFE6 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win64.Reflo.tspz
AVGWin32:Malware-gen
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.ABA2EFE6
FireEyeGeneric.mg.a7edb834286c34cf
McAfeeArtemis!A7EDB834286C
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1693826
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Generic.08d3ef2e
Cybereasonmalicious.4286c3
CyrenW32/ABRisk.MSKQ-3049
SymantecTrojan.Gen.MBT
ESET-NOD32BAT/Runner.IA
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.njRAT-9986242-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.PasswordStealerA.ABA2EFE6
SophosMal/Generic-S
VIPREGeneric.MSIL.PasswordStealerA.ABA2EFE6
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftBackdoor.Orcus (A)
GDataGeneric.MSIL.PasswordStealerA.ABA2EFE6
Antiy-AVLGrayWare/JS.Encry.sfx
ArcabitGeneric.MSIL.PasswordStealerA.ABA2EFE6
ZoneAlarmUDS:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
ALYacGeneric.MSIL.PasswordStealerA.ABA2EFE6
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H09EP23
RisingTrojan.Agent/SFX!1.E69B (CLASSIC)
MaxSecureTrojan.Malware.7164915.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.MSIL.PasswordStealerA.ABA2EFE6?

Generic.MSIL.PasswordStealerA.ABA2EFE6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment