Malware

Generic.StealerA.60FAB621 (file analysis)

Malware Removal

The Generic.StealerA.60FAB621 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.StealerA.60FAB621 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Generic.StealerA.60FAB621?


File Info:

name: 446EF0D420462B0BAA60.mlw
path: /opt/CAPEv2/storage/binaries/90235bb44a09d2982efc9ad004afe356688406a257010cf44c8548dcb2645af8
crc32: 082FEBE4
md5: 446ef0d420462b0baa60c2cd95842b79
sha1: d89c1a046931f75cc44c3432dff48c8cc3c80f1d
sha256: 90235bb44a09d2982efc9ad004afe356688406a257010cf44c8548dcb2645af8
sha512: a30ca1eb28431a887097c6991765f9090308eab8315fc73d6f9bc2f59563c08543022c5dd4f7cd382a201cd6d748a71d4cfa942ca8a343007ba2fef715560638
ssdeep: 1536:h+uYx6qTrpFCSFjJdSmjmr3YpE/PIYGtkr9dLkOcwGTv8EOgkzm3y:4pY2JSUpE/PnkOXLEOc3y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AA30803F480F0F1C1A12BB17BC11761EBF99E697C3A8D4AEF4C49856DB268B7B16412
sha3_384: b8d8f3f64320ba14a35ed2ee2f883928b8ec1c28678d72d76caec716c36ae89ab6e99997615d70868ff3f98507600dc5
ep_bytes: 558bec5d6836004100f87201c3ffe855
timestamp: 2014-03-15 15:53:26

Version Info:

0: [No Data]

Generic.StealerA.60FAB621 also known as:

BkavW32.AIDetect.malware1
ElasticWindows.Trojan.Pony
DrWebTrojan.PWS.Stealer.1932
MicroWorld-eScanGeneric.StealerA.60FAB621
FireEyeGeneric.mg.446ef0d420462b0b
CAT-QuickHealPWS.Fareit.E3
ALYacGeneric.StealerA.60FAB621
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0040f4f51 )
K7GWPassword-Stealer ( 0040f4f51 )
Cybereasonmalicious.420462
BitDefenderThetaGen:NN.ZexaF.34712.gmW@ayCc9cp
VirITTrojan.Win32.Generic.BHAO
CyrenW32/A-f0951580!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.Fareit.D
TrendMicro-HouseCallBKDR_PONY.SM
Paloaltogeneric.ml
ClamAVWin.Trojan.PonyStealer-9831667-0
KasperskyTrojan-PSW.Win32.Tepfer.gen
BitDefenderGeneric.StealerA.60FAB621
NANO-AntivirusTrojan.Win32.Siggen.evgeyh
AvastSf:Crypt-AS [Trj]
TencentTrojan.Win32.Tepfer.a
Ad-AwareGeneric.StealerA.60FAB621
EmsisoftGeneric.StealerA.60FAB621 (B)
ComodoTrojWare.Win32.PWS.Fareit.GS@5t8zib
BaiduWin32.Trojan-PSW.Fareit.a
ZillyaTrojan.Fareit.Win32.22103
TrendMicroBKDR_PONY.SM
McAfee-GW-EditionBehavesLike.Win32.ZBot.cm
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Mal/Pony-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.Fareit.F81UOL
JiangminTrojan/PSW.Tepfer.bzwv
WebrootW32.Trojan.Gen
AviraTR/PSW.Fareit.iloen
MAXmalware (ai score=83)
ArcabitGeneric.StealerA.60FAB621
ViRobotBackdoor.Win32.Pony.Gen.A
MicrosoftPWS:Win32/Fareit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R54812
McAfeePWS-Zbot.gen.ate
VBA32BScope.Malware-Cryptor.Ponik
MalwarebytesSpyware.Pony
APEXMalicious
RisingStealer.Fareit!1.B777 (CLASSIC)
YandexTrojan.GenAsa!y66aUFdfsrQ
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.14B!tr
AVGSf:Crypt-AS [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.StealerA.60FAB621?

Generic.StealerA.60FAB621 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment