Malware

Generic.StealerA.C6ABCB4C removal instruction

Malware Removal

The Generic.StealerA.C6ABCB4C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.StealerA.C6ABCB4C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Generic.StealerA.C6ABCB4C?


File Info:

name: B16D9CBF5937DF166C11.mlw
path: /opt/CAPEv2/storage/binaries/5efefe682d0e8f13361b50d4d0440fe24ea30a2ef79c320f7deab62d72e3c6cf
crc32: 531CFFCD
md5: b16d9cbf5937df166c1138fbb75b5f28
sha1: f6f83e38c353311d160298bcf0e2b454d4368b42
sha256: 5efefe682d0e8f13361b50d4d0440fe24ea30a2ef79c320f7deab62d72e3c6cf
sha512: 026d05f17e91ad8f9fdbf9f7a7ff50c6bf38e48f6d6c3152d224a98ea756524446ba14a1a881c80f035dcdb4da8c337ae2bb6af60dee143e2601c53b648b09a4
ssdeep: 3072:J/AKzsKDsTdvONjEk0xcsmO0xb8PGZqBG0jHuuuugW:J/ldsZvOImVquZqdHuuuur
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T114446C03F580F4F5C0912BB177C21A60D3F9AD36B8798D6BBF9C795639B62472B21086
sha3_384: c4a321ad88d54b5236ad8142198a32e46aefcdd572c862060e722be6c491b19bb3acd678e2193bfb7849e3a6ba1169f7
ep_bytes: 558bec5d68c7fe4000f87201c3ffe854
timestamp: 2017-05-18 22:13:26

Version Info:

0: [No Data]

Generic.StealerA.C6ABCB4C also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.mtwx
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.b16d9cbf5937df16
CAT-QuickHealPWS.Fareit.E3
McAfeePWS-Zbot.gen.ate
CylanceUnsafe
VIPRETrojan.Win32.Fareit.gi (v)
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0040f4f51 )
AlibabaTrojanPSW:Win32/Tepfer.01011c5c
K7GWPassword-Stealer ( 0040f4f51 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.BFOG
CyrenW32/A-f0951580!Eldorado
SymantecInfostealer!im
ESET-NOD32a variant of Win32/PSW.Fareit.D
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.PonyStealer-9831667-0
KasperskyTrojan-PSW.Win32.Tepfer.gen
BitDefenderGeneric.StealerA.C6ABCB4C
NANO-AntivirusTrojan.Win32.Siggen.evgeyh
MicroWorld-eScanGeneric.StealerA.C6ABCB4C
AvastSf:Crypt-AS [Trj]
TencentTrojan.Win32.Tepfer.a
Ad-AwareGeneric.StealerA.C6ABCB4C
EmsisoftGeneric.StealerA.C6ABCB4C (B)
ComodoTrojWare.Win32.PWS.Fareit.GS@5t8zib
F-SecureTrojan.TR/PSW.Fareit.iloen
DrWebTrojan.PWS.Stealer.1932
TrendMicroBKDR_PONY.SM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dm
SophosMal/Generic-S + Mal/Pony-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.Zbot.AB
JiangminTrojan/PSW.Tepfer.cbui
AviraTR/PSW.Fareit.iloen
Antiy-AVLTrojan[PSW]/Win32.Tepfer
KingsoftWin32.PSWTroj.Tepfer.g.(kcloud)
GridinsoftRansom.Win32.Zbot.sa
ArcabitGeneric.StealerA.C6ABCB4C
ViRobotBackdoor.Win32.Pony.Gen.A
MicrosoftPWS:Win32/Fareit
AhnLab-V3Trojan/Win32.Tepfer.R54812
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34084.qmZ@aSIRVnb
ALYacGeneric.StealerA.C6ABCB4C
MAXmalware (ai score=84)
VBA32BScope.Malware-Cryptor.Ponik
MalwarebytesSpyware.Pony
TrendMicro-HouseCallBKDR_PONY.SM
RisingStealer.Fareit!1.B777 (CLASSIC)
YandexTrojan.GenAsa!y66aUFdfsrQ
IkarusTrojan-Spy.Fareit
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.14B!tr
AVGSf:Crypt-AS [Trj]
Cybereasonmalicious.f5937d
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.StealerA.C6ABCB4C?

Generic.StealerA.C6ABCB4C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment