Malware

Generic.MSIL.PasswordStealerA.BFB7AE27 removal guide

Malware Removal

The Generic.MSIL.PasswordStealerA.BFB7AE27 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.BFB7AE27 virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine Generic.MSIL.PasswordStealerA.BFB7AE27?


File Info:

crc32: B2DC0ACF
md5: 252ecd2827723011e3d37edeaccd2599
name: 252ECD2827723011E3D37EDEACCD2599.mlw
sha1: 9525bec4453a777d852838a62f82ece0233b9487
sha256: 7e53df2cb418ad47d225c64efe2cd9a111b4a010ed363a1f9bcd6e23a807c244
sha512: 0f837027aee2193dc9b050e0cbc6af4248b4bc91f1dee181afe6ea284ca73017e760e1c00e467256e6c767e97e8f0a9bf66ee6818cc472ded367f3736a7b7ab3
ssdeep: 6144:8TEgdc0Y5Xc2rao+RGmZOxclf7PQHydcEHab8F9hvuhYV6cTR314:8TEgdfYdrafXdXdzmhYEcd14
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xae Microsoft Corporation. All rights reserved.
Assembly Version: 10.0.19041.546
InternalName: svchost.exe
FileVersion: 10.0.19041.546
CompanyName: Microsoftxae
LegalTrademarks: Microsoftxae Windows 10xae
Comments:
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.19041.546
FileDescription: Host Process for Windows Services
OriginalFilename: svchost.exe

Generic.MSIL.PasswordStealerA.BFB7AE27 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop13.10660
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S15413537
ALYacGeneric.MSIL.PasswordStealerA.BFB7AE27
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Quasar.3b7
K7GWTrojan ( 0054cc751 )
Cybereasonmalicious.827723
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.BPH
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Packed.Downeks-6898097-0
KasperskyHEUR:Trojan.MSIL.Quasar.gen
BitDefenderGeneric.MSIL.PasswordStealerA.BFB7AE27
MicroWorld-eScanGeneric.MSIL.PasswordStealerA.BFB7AE27
TencentMsil.Trojan.Quasar.Hoos
Ad-AwareGeneric.MSIL.PasswordStealerA.BFB7AE27
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34738.Fm2@aKeiqV
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_TINCLEX.SM1
McAfee-GW-EditionGenericRXKX-GN!252ECD282772
FireEyeGeneric.mg.252ecd2827723011
EmsisoftGeneric.MSIL.PasswordStealerA.BFB7AE27 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.oyqd
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1135947
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3095FB3
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Quasar.GG!MTB
AegisLabTrojan.MSIL.Quasar.4!c
GDataMSIL.Backdoor.Quasar.B
AhnLab-V3Backdoor/Win32.QuasarRAT.R341693
Acronissuspicious
McAfeeGenericRXKX-GN!252ECD282772
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Quasar
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_TINCLEX.SM1
IkarusBackdoor.Win32.Xiclog
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BPH!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.MSIL.PasswordStealerA.BFB7AE27?

Generic.MSIL.PasswordStealerA.BFB7AE27 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment