Malware

How to remove “Generic.MSIL.PasswordStealerA.B535E408”?

Malware Removal

The Generic.MSIL.PasswordStealerA.B535E408 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.B535E408 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Generic.MSIL.PasswordStealerA.B535E408?


File Info:

crc32: B17DD2C6
md5: 038a542964abfc11b0934ad2b657fb8d
name: server.exe
sha1: 32925b1759a95d343170cf16b38559c3df1fe41e
sha256: 0269df02325fa81fbba3891f457ae86f806a7fe44ba0369b81ad54b5dcb716e6
sha512: e4e5aeeb88bba6aee957472ef670f9a902e8ea7fb3faf39ff421492967cec77055ce10da64a6a2c4eaafbf78aa77a7ee13e34feba0e6b4898f020a48843eb1c7
ssdeep: 6144:8ozV3ceuT/+rLkAUy+irw0qrU4jjwBBoTE7I9uYQSf185:N0TmrAAxEPryn7ef185
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.MSIL.PasswordStealerA.B535E408 also known as:

MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.B535E408
FireEyeGeneric.mg.038a542964abfc11
McAfeeGenericRXAY-TF!038A542964AB
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.B535E408
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.964abf
TrendMicroMal_Banker15
BaiduWin32.Trojan.Agent.co
F-ProtW32/Injector.HZL
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Spyrat.B
APEXMalicious
AvastWin32:BackDoor-ACX [Trj]
ClamAVWin.Packed.Spynet-6841468-0
GDataDeepScan:Generic.MSIL.PasswordStealerA.B535E408
KasperskyHEUR:Trojan.Win32.Generic
AlibabaWorm:Win32/Rebhip.bef476fe
NANO-AntivirusTrojan.Win32.Stealer.dzlmzr
ViRobotTrojan.Win32.A.Llac.291328.A
AegisLabWorm.Win32.Fearso.lDrx
RisingWorm.Rebhip!1.A338 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftDeepScan:Generic.MSIL.PasswordStealerA.B535E408 (B)
ComodoBackdoor.Win32.Delf.~DF@1mio94
F-SecureTrojan.TR/Hijacker.Gen
DrWebTrojan.PWS.Stealer.516
VIPRETrojan.Win32.Generic.pak!cobra
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
SophosMal/Behav-328
IkarusTrojan.Win32.Llac
CyrenW32/Injector.VOTX-5100
JiangminTrojan/Generic.hpon
WebrootW32.Trojan.Gen
AviraTR/Hijacker.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.B535E408
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Rebhip.A!upx
AhnLab-V3Trojan/Win32.Antisb.C77097
Acronissuspicious
VBA32BScope.Backdoor.Cybergate
ALYacDeepScan:Generic.MSIL.PasswordStealerA.B535E408
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerA.B535E408
MalwarebytesBackdoor.SpyNet
PandaTrj/CI.A
ESET-NOD32Win32/Spatet.T
TrendMicro-HouseCallMal_Banker15
TencentMalware.Win32.Gencirc.10b3cbf2
YandexWorm.DR.Rebhip.Gen
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Spatet.TRR!tr
BitDefenderThetaAI:Packer.575B14FC1B
AVGWin32:BackDoor-ACX [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM05.1.C5BF.Malware.Gen

How to remove Generic.MSIL.PasswordStealerA.B535E408?

Generic.MSIL.PasswordStealerA.B535E408 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment