Malware

What is “Generic.MSIL.PasswordStealerA.AC60CD7D”?

Malware Removal

The Generic.MSIL.PasswordStealerA.AC60CD7D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.AC60CD7D virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Exhibits behavior characteristic of iSpy Keylogger
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

s1.putinso.site

How to determine Generic.MSIL.PasswordStealerA.AC60CD7D?


File Info:

crc32: CC000967
md5: 94e3e8259cf052aa7601e8034421ab5b
name: upload_file
sha1: 9451b85d82f81c0d05707f099a39982e44072633
sha256: ce1b595b85491977dee24248ddfb31424bb97691383b9fc5c911d42df58c6b6b
sha512: 11ce9671277636e46a3e522f53a89f1b6aed02aaadc531d8a0c1a2b6c308241e039cb6af307db8e2907f759b13760fdda6553ba5600d29b1f4f40597f62963e9
ssdeep: 24576:N6w4MROxnFj3H73MJJXRrZlI0AilFEvxHilM:N6TMi1bOhrZlI0AilFEvxHi
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Orcus.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: Orcus.exe

Generic.MSIL.PasswordStealerA.AC60CD7D also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.AC60CD7D
CAT-QuickHealTrojan.MsilFC.S6051223
McAfeeBackDoor-FDJE!94E3E8259CF0
MalwarebytesBackdoor.Orcus
SangforMalware
K7AntiVirusTrojan ( 005011a81 )
BitDefenderGeneric.MSIL.PasswordStealerA.AC60CD7D
K7GWTrojan ( 005011a81 )
Cybereasonmalicious.59cf05
TrendMicroBKDR_ORCUSRAT.SM
CyrenW32/MSIL_Injector.KK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Generic
SUPERAntiSpywareTrojan.Agent/Gen-Injector
RisingBackdoor.Orcus!1.BABC (CLASSIC)
Ad-AwareGeneric.MSIL.PasswordStealerA.AC60CD7D
EmsisoftBackdoor.Orcus (A)
ComodoTrojWare.MSIL.Orcusrat.D@8ftc87
F-SecureHeuristic.HEUR/AGEN.1128549
DrWebTrojan.DownLoader24.65022
InvinceaML/PE-A + Troj/Orcusrot-A
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.94e3e8259cf052aa
SophosTroj/Orcusrot-A
SentinelOneDFI – Malicious PE
JiangminTrojan.Generic.awmpo
AviraHEUR/AGEN.1128549
MAXmalware (ai score=89)
MicrosoftWorm:Win32/Ainslot
ArcabitGeneric.MSIL.PasswordStealerA.AC60CD7D
ZoneAlarmHEUR:Trojan-Spy.MSIL.Generic
GDataMSIL.Backdoor.Orcus.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/OrcusRAT.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34566.4m0@aWyEFMe
ALYacGeneric.MSIL.PasswordStealerA.AC60CD7D
VBA32Trojan.Downloader
CylanceUnsafe
ZonerTrojan.Win32.75536
ESET-NOD32a variant of MSIL/Orcusrat.D
TrendMicro-HouseCallBKDR_ORCUSRAT.SM
IkarusTrojan.MSIL.Agent
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Generic.AP.F529E!tr
WebrootW32.Trojan.Gen
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.9647.Malware.Gen

How to remove Generic.MSIL.PasswordStealerA.AC60CD7D?

Generic.MSIL.PasswordStealerA.AC60CD7D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment