Malware

Generic.StealerA.1987FFCD removal tips

Malware Removal

The Generic.StealerA.1987FFCD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.StealerA.1987FFCD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • CAPE detected the Fareit malware family
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Generic.StealerA.1987FFCD?


File Info:

name: F65DA40A19A06761B819.mlw
path: /opt/CAPEv2/storage/binaries/2b47754cf732ab3ab2ea368c664d5a9bc4940aeb10a2fd6ab317d75e55072bd0
crc32: 19F6F07A
md5: f65da40a19a06761b81919c560e6e0e5
sha1: 9fdd30bd02dd78d9b503d1f6ea33f977894c3eff
sha256: 2b47754cf732ab3ab2ea368c664d5a9bc4940aeb10a2fd6ab317d75e55072bd0
sha512: 142400e97cfc7726667b8e1cb557476308eba7125448219974559b20baa578032286d6a43b5fb59d0c92ba474176540a5f5b065060e4b0d7a986f3cd3722486d
ssdeep: 3072:oXl4Bx9TLVx6WywArOpyO/DKJF6cam1D6jd:oXlAx9TLj8weOpz/DKJ0cPQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9E34B02F885E0F5D1A112723BC16AB1F3F99E78BC794D4EFF9D294579A2187AB12403
sha3_384: 08e357f28fedf9e7fa9cf2a72cf71bc1859366e171e307cc7400d39cabddfe1911b4d7b9dbcad426afb62ebe5794c48c
ep_bytes: 33c233d033c268c509410090f8907202
timestamp: 2013-09-23 12:31:47

Version Info:

0: [No Data]

Generic.StealerA.1987FFCD also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.StealerA.1987FFCD
FireEyeGeneric.mg.f65da40a19a06761
CAT-QuickHealTrojanpws.Tepfer.20314
ALYacGeneric.StealerA.1987FFCD
CylanceUnsafe
VIPRETrojan.Win32.Zbot.smao (v)
K7AntiVirusPassword-Stealer ( 0040f4f51 )
BitDefenderGeneric.StealerA.1987FFCD
K7GWPassword-Stealer ( 0040f4f51 )
Cybereasonmalicious.a19a06
BitDefenderThetaGen:NN.ZexaF.34182.jmZ@a8XObRj
CyrenW32/S-c6861fad!Eldorado
SymantecDownloader.Ponik!gm
ESET-NOD32a variant of Win32/PSW.Fareit.D
BaiduWin32.Trojan-PSW.Fareit.a
TrendMicro-HouseCallTSPY_FAREIT.SMY
KasperskyTrojan-PSW.Win32.Tepfer.gen
NANO-AntivirusTrojan.Win32.Siggen.evgeyh
TencentTrojan.Win32.Tepfer.a
SophosMal/Generic-R + Mal/Behav-116
ComodoTrojWare.Win32.PWS.Fareit.GS@5t8zib
DrWebTrojan.PWS.Stealer.4118
ZillyaTrojan.Fareit.Win32.1074
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
SentinelOneStatic AI – Malicious PE
EmsisoftGeneric.StealerA.1987FFCD (B)
APEXMalicious
JiangminTrojan/Generic.avqfg
AviraTR/Kryptik.avp.8
MicrosoftPWS:Win32/Fareit
GDataWin32.Trojan-Stealer.Zbot.AB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fareit.R62236
McAfeePWS-Zbot-FAVV!F65DA40A19A0
MAXmalware (ai score=89)
VBA32SScope.Malware-Cryptor.Ponik
MalwarebytesMalware.AI.1289867402
PandaTrj/Genetic.gen
RisingStealer.Fareit!8.170 (TFE:dGZlOgJmjdeFOpWuOA)
IkarusTrojan-PWS.Win32.Tepfer
eGambitUnsafe.AI_Score_100%
FortinetW32/FakeAV.UUS!tr
AVGSf:Crypt-AS [Trj]
AvastSf:Crypt-AS [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.StealerA.1987FFCD?

Generic.StealerA.1987FFCD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment