Backdoor

Backdoor:Win32/Keylogger.PA!MTB removal

Malware Removal

The Backdoor:Win32/Keylogger.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Keylogger.PA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Backdoor:Win32/Keylogger.PA!MTB?


File Info:

crc32: FEC20143
md5: 303a76ec54eaf0642487b4d5e639ed47
name: 303A76EC54EAF0642487B4D5E639ED47.mlw
sha1: c9c371e750fb7257228b96c449682413f553e676
sha256: a84f11e95b767a018ebd535c055ce9dd39d0ab23bf563312092662cd8cedf00b
sha512: 797fd54c9dd41211d1629ac2f811c29030458735a1944f79d1994de00628899535d7028fa209f0ab8315ef53c22bb7fbb6ba2aa06ceb5af64da9b0ac1bc82a8e
ssdeep: 12288:VpqsmUta2bc2vqJFBJQ6iH2jjtSW3Yv4wm0EMoL2W9xkDq56HD4iNcIUxU:Kuta2IzJQ6iWj8JTm0zK2WID4zC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 1.0.0.0
InternalName: UCOMIEnumConnectionPoints.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: SEC Football
ProductVersion: 1.0.0.0
FileDescription: SEC Football
OriginalFilename: UCOMIEnumConnectionPoints.exe

Backdoor:Win32/Keylogger.PA!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.254728
FireEyeGen:Variant.Bulz.254728
Qihoo-360Generic/Trojan.PSW.374
McAfeePWS-FCTY!303A76EC54EA
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005746a71 )
BitDefenderGen:Variant.Bulz.254728
K7GWTrojan ( 005746a71 )
Cybereasonmalicious.750fb7
BitDefenderThetaGen:NN.ZemsilF.34670.7m0@aG4uCke
CyrenW32/Trojan.SW.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/runner.ali1000123
ViRobotTrojan.Win32.Z.Kryptik.973312.K
AegisLabTrojan.MSIL.Agensla.i!c
Ad-AwareGen:Variant.Bulz.254728
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/Kryptik.uwwpb
DrWebTrojan.Packed2.42726
TrendMicroTrojanSpy.MSIL.NEGASTEAL.THLOIBO
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Kryptik.uwwpb
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Keylogger.PA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Bulz.D3E308
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataGen:Variant.Bulz.254728
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSILKrypt.R357493
ALYacGen:Variant.Bulz.254728
MAXmalware (ai score=85)
MalwarebytesSpyware.AgentTesla
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YYW
TrendMicro-HouseCallTrojanSpy.MSIL.NEGASTEAL.THLOIBO
IkarusTrojan.MSIL.Inject
FortinetMSIL/GenKryptik.EYEL!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor:Win32/Keylogger.PA!MTB?

Backdoor:Win32/Keylogger.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment