Spy

What is “Spyware.Pony.UPX”?

Malware Removal

The Spyware.Pony.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Pony.UPX virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

Related domains:

ekitty.net

How to determine Spyware.Pony.UPX?


File Info:

crc32: 64051425
md5: ec833eb164e86c797df3dab47f6e0774
name: EC833EB164E86C797DF3DAB47F6E0774.mlw
sha1: ba94798452ccd67cc2cd5f41bfa945b614205ab7
sha256: c0150543944bc0dd08e602f453da6a03fc44c535bf5863a1b75b956ec1da3e3a
sha512: b1c9b09a8c8381145b309ca7a74540c0ca42e5ee6275b431ca2f1b45a1b5ed9005bda2c12b5a01830cbd96c25b1e2565d67357c1519538a75bc4051506907a41
ssdeep: 1536:Fkww+SPqTnHmHn5zNqBELNMHk6fTz6nWjqN3OqrgTvVEw/kzmCa3tn:KwwHfqBELqEiP0OxEw/N3tn
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Spyware.Pony.UPX also known as:

BkavW32.AIDetect.malware1
K7AntiVirusPassword-Stealer ( 0040f4f51 )
LionicTrojan.Win32.Generic.mtwx
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.16780
CynetMalicious (score: 100)
CAT-QuickHealTrojanpws.Tepfer
ALYacGeneric.StealerA.6BBEDD7A
CylanceUnsafe
SangforWin.Trojan.Fareit-403
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Tepfer.e55dbfe1
K7GWPassword-Stealer ( 0040f4f51 )
Cybereasonmalicious.164e86
BaiduWin32.Trojan-PSW.Fareit.a
CyrenW32/Tepfer.R.gen!Eldorado
SymantecInfostealer!im
ESET-NOD32a variant of Win32/PSW.Fareit.D
APEXMalicious
AvastSf:Crypt-AS [Trj]
ClamAVWin.Trojan.PonyStealer-9831667-0
KasperskyTrojan-PSW.Win32.Tepfer.gen
BitDefenderGeneric.StealerA.6BBEDD7A
NANO-AntivirusTrojan.Win32.Tepfer.dzgdrw
MicroWorld-eScanGeneric.StealerA.6BBEDD7A
TencentWin32.Trojan-qqpass.Qqrob.Amvr
Ad-AwareGeneric.StealerA.6BBEDD7A
SophosMal/Generic-R + Mal/Behav-116
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34050.gqW@aSyTwsp
VIPRETrojan.Win32.Fareit.gi (v)
TrendMicroTROJ_GEN.R03BC0DGJ21
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.ec833eb164e86c79
EmsisoftGeneric.StealerA.6BBEDD7A (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Tepfer.alp
AviraTR/PSW.Fareit.iloen
eGambitUnsafe.AI_Score_100%
MicrosoftPWS:Win32/Fareit
ZoneAlarmTrojan-PSW.Win32.Tepfer.gen
GDataGeneric.StealerA.6BBEDD7A
TACHYONTrojan-PWS/W32.Fareit.107520.D
AhnLab-V3Trojan/Win32.RL_Tepfer.R362025
Acronissuspicious
McAfeeBackDoor-FJW!EC833EB164E8
MAXmalware (ai score=84)
VBA32BScope.TrojanPSW.Tepfer
MalwarebytesSpyware.Pony.UPX
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DGJ21
RisingStealer.Fareit!1.B777 (CLASSIC)
YandexTrojan.GenAsa!JZ4Z7+DmmVA
IkarusTrojan-Spy.Fareit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NTM!tr
AVGSf:Crypt-AS [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Tepfer.HxMBtjsA

How to remove Spyware.Pony.UPX?

Spyware.Pony.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment