Malware

What is “Generic.MSIL.PasswordStealerA.E4B402E2”?

Malware Removal

The Generic.MSIL.PasswordStealerA.E4B402E2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.PasswordStealerA.E4B402E2 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generic.MSIL.PasswordStealerA.E4B402E2?


File Info:

crc32: D061F9FF
md5: 8a26a73ab327d4293ca8aa566adb1a87
name: 8A26A73AB327D4293CA8AA566ADB1A87.mlw
sha1: 659071b156a4c76433f4b8420725a0e5b466732c
sha256: d495c16614ec1c253197597ee839215aa1f1237578de342e251a407fb59855f5
sha512: 950f2d90d9612926c174dbece637fe173c823606a70c89829f0b7fc9cca0f820c5f94aadbcb317205b02a17da7cc0a00e21dbc0649358b0cbff73ccef5553d6f
ssdeep: 6144:2PIibfJwmi/2NTCAUZtgfv1dEsG860jAnRwoOLRWu9:Xmf1iOHvEsG8VARwoOX9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: kogzmuahoke.exi
ProductVersion: 91.78.38.10
Copyright: Copyrighz (C) 2020, vodkaguts
Translation: 0x0483 0x011e

Generic.MSIL.PasswordStealerA.E4B402E2 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.QuasarNET.3
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacDeepScan:Generic.MSIL.PasswordStealerA.E4B402E2
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.553f2e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.AES
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
ClamAVWin.Packed.Uztuby-9853721-0
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.E4B402E2
MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.E4B402E2
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerA.E4B402E2
SophosMal/SpyNoon-A
BitDefenderThetaGen:NN.ZemsilF.34050.Im0@aKnfX8hi
McAfee-GW-EditionBehavesLike.Win32.Generic.hm
FireEyeGeneric.mg.560df81553f2ef8d
EmsisoftTrojan-Spy.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.bqes
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Spy.BYF!MTB
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.E4B402E2
GDataDeepScan:Generic.MSIL.PasswordStealerA.E4B402E2
AhnLab-V3Trojan/Win.Spy.C4559049
McAfeeGenericRXPF-LQ!560DF81553F2
MAXmalware (ai score=88)
MalwarebytesSpyware.PasswordStealer
IkarusTrojan.MSIL.Spy
FortinetMSIL/Agent.BYF!tr.spy
AVGWin32:KeyloggerX-gen [Trj]
Qihoo-360HEUR/QVM03.0.00C7.Malware.Gen

How to remove Generic.MSIL.PasswordStealerA.E4B402E2?

Generic.MSIL.PasswordStealerA.E4B402E2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment