Malware

Generic.MSIL.PasswordStealerA.D27893BC (file analysis)

Malware Removal

The Generic.MSIL.PasswordStealerA.D27893BC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.D27893BC virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Generic.MSIL.PasswordStealerA.D27893BC?


File Info:

crc32: E9F63241
md5: f9c2fda57b0b306aefc0fe738748eade
name: setup.exe
sha1: 4a2467a7584f8e786111010daec3e1ff617d95d0
sha256: 84fb3a26f12bd746a7f6fba2a857186a5c575faf2ed31cf3d4f49e131b062262
sha512: 352f274d83f1acadc6a5b4e7af5c6f1023c6ffded234f4d059a5ad420588ba065e357c618a516aaef69627a9a2ad3af65b7875dc1be9adc9948fef5fddb14049
ssdeep: 6144:2VnbLQmhTECuWZm4G+7PJQ4Hwqxy0OPzZhXnAO:2VnLO7ZhXnl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2017 Discord Inc. All rights reserved.
InternalName: Setup.exe
FileVersion: 0.0.301
CompanyName: Discord Inc.
SquirrelAwareVersion: 1
ProductName: Discord - https://discordapp.com/
ProductVersion: 0.0.301
FileDescription: Discord - https://discordapp.com/
OriginalFilename: Setup.exe
Translation: 0x0409 0x04b0

Generic.MSIL.PasswordStealerA.D27893BC also known as:

MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.D27893BC
FireEyeGeneric.mg.f9c2fda57b0b306a
McAfeeArtemis!F9C2FDA57B0B
CylanceUnsafe
VIPRETrojan-Spy.Win32.Usteal.da (v)
K7AntiVirusTrojan ( 00012a951 )
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.D27893BC
K7GWTrojan ( 00012a951 )
Cybereasonmalicious.57b0b3
TrendMicroTrojanSpy.Win32.USTEAL.SMTH
BitDefenderThetaAI:Packer.7C5A8FE91E
CyrenW32/Usteal.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Usteal.C
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Usteal.4659a425
NANO-AntivirusTrojan.Win32.Usteal.eriozk
RisingSpyware.Usteal!8.307 (CLOUD)
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerA.D27893BC
EmsisoftDeepScan:Generic.MSIL.PasswordStealerA.D27893BC (B)
ComodoMalware@#1n1y4t7urcg8u
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.PWS.UFR.3111
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.ft
Trapminemalicious.high.ml.score
SophosMal/Generic-S
GDataDeepScan:Generic.MSIL.PasswordStealerA.D27893BC
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
MicrosoftTrojanSpy:Win32/Usteal.D
Endgamemalicious (high confidence)
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.DD6CF5BC
AhnLab-V3Trojan/Win32.Ruftar.R22332
ZoneAlarmHEUR:Trojan.Win32.Generic
VBA32BScope.Trojan.Anomaly
ALYacDeepScan:Generic.MSIL.PasswordStealerA.D27893BC
TrendMicro-HouseCallTrojanSpy.Win32.USTEAL.SMTH
TencentWin32.Trojan.Generic.Egec
YandexTrojan.FruStealer.Gen.LG
IkarusTrojan.Win32.Ransom
FortinetW32/ZBOT.CDL!tr
WebrootW32.Trojan.Gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM11.1.3809.Malware.Gen

How to remove Generic.MSIL.PasswordStealerA.D27893BC?

Generic.MSIL.PasswordStealerA.D27893BC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment