Malware

Generic.StealerA.46C9FE2B (file analysis)

Malware Removal

The Generic.StealerA.46C9FE2B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.StealerA.46C9FE2B virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine Generic.StealerA.46C9FE2B?


File Info:

crc32: 446C3774
md5: ae0fba1cd6af06e2f518796fda6decc9
name: AE0FBA1CD6AF06E2F518796FDA6DECC9.mlw
sha1: 68eecad5c9072fb1a8e82336a4bcf25c843a52bb
sha256: 31e2c221f9f8be9acb89fcffe8b305dfeea554eefeb898ec8c6711e0398a6a1b
sha512: 10c0f51696b258e693b92ede7acd9c4fb204abb139aa63c27d70155600bd1af4024bab643201f4dc751ec25b54440fa26fa54f3295861e9c4b90bc99a09d8bd8
ssdeep: 768:yu4vtPBr4vKYrGCm8jaalTHpN5oxFNYwalnZ:ilevKZ0lTHbYYXZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.StealerA.46C9FE2B also known as:

BkavW32.AIDetect.malware1
K7AntiVirusPassword-Stealer ( 0040f4f51 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.1932
CynetMalicious (score: 100)
CAT-QuickHealPWS.Fareit.E3
ALYacGeneric.StealerA.46C9FE2B
CylanceUnsafe
ZillyaTrojan.Tepfer.Win32.91411
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWPassword-Stealer ( 0040f4f51 )
Cybereasonmalicious.cd6af0
BaiduWin32.Trojan-PSW.Fareit.a
CyrenW32/Tepfer.R.gen!Eldorado
SymantecTrojan.Fareit!gm
ESET-NOD32a variant of Win32/PSW.Fareit.D
APEXMalicious
AvastSf:Crypt-AS [Trj]
ClamAVWin.Trojan.PonyStealer-9831667-0
KasperskyTrojan-PSW.Win32.Tepfer.gen
BitDefenderGeneric.StealerA.46C9FE2B
NANO-AntivirusTrojan.Win32.Siggen.evgeyh
ViRobotBackdoor.Win32.Pony.Gen.A
MicroWorld-eScanGeneric.StealerA.46C9FE2B
TencentWin32.Trojan-qqpass.Qqrob.Lmup
Ad-AwareGeneric.StealerA.46C9FE2B
SophosML/PE-A + Mal/Pony-A
ComodoTrojWare.Win32.PWS.Fareit.GS@5t8zib
BitDefenderThetaGen:NN.ZexaF.34790.cmGfaWT5iep
VIPRETrojan-PWS.Win32.Fareit.i (v)
TrendMicroBKDR_PONY.SM
McAfee-GW-EditionBehavesLike.Win32.Backdoor.nc
FireEyeGeneric.mg.ae0fba1cd6af06e2
EmsisoftGeneric.StealerA.46C9FE2B (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.arfmq
WebrootTrojanspy:Win32/Fitmu.A
AviraTR/PSW.Fareit.iloen
Antiy-AVLTrojan/Generic.ASMalwS.192EB43
MicrosoftPWS:Win32/Fareit.C!bit
ArcabitGeneric.StealerA.46C9FE2B
ZoneAlarmTrojan-PSW.Win32.Tepfer.gen
GDataWin32.Trojan-Stealer.Zbot.AB
AhnLab-V3Trojan/Win32.Tepfer.R77902
Acronissuspicious
McAfeeArtemis!AE0FBA1CD6AF
MAXmalware (ai score=89)
VBA32BScope.Malware-Cryptor.Ponik
MalwarebytesSpyware.Pony
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_PONY.SM
RisingStealer.Fareit!1.B777 (CLASSIC)
IkarusTrojan-Spy.Fareit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.14B!tr
AVGSf:Crypt-AS [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Bulta.HwsBEpsA

How to remove Generic.StealerA.46C9FE2B?

Generic.StealerA.46C9FE2B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment