Malware

What is “Generic.Keylogger.2.01E2270A”?

Malware Removal

The Generic.Keylogger.2.01E2270A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.01E2270A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Generic.Keylogger.2.01E2270A?


File Info:

name: 00C90964EFD958B1DA93.mlw
path: /opt/CAPEv2/storage/binaries/0a059577a452f44873df803adaf035b8dbd77911547d6da2c8ad129442fc5da5
crc32: 739DFF74
md5: 00c90964efd958b1da93c2d336e93ce2
sha1: 0bf36f6bec4d7cc7e73da9006ebfee9ae7f947f0
sha256: 0a059577a452f44873df803adaf035b8dbd77911547d6da2c8ad129442fc5da5
sha512: 7bdce0168c261be69b083fd551daa057ef9a2c8393844ac3ca8e76f1873ae169dc2a101e8395a9eeae32eec75eadcde57cd8e261ee2249bf3719f35087663a05
ssdeep: 49152:xNUz+uq0qFruSPhzCtAAp/Hzc7C0cz7bzOg33V:xw+uqk+hyQW0cz3T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109A5B003F2824072E4D301FA92B35FFA6E36A7310316A8E393C46CE55B615E1BA35797
sha3_384: 8e7cb8d39385dde8b206fd571287f903bae63bc059eaa5a2950855cd73ad92d46ad712209d99d6da8dde046a63f22c07
ep_bytes: e8e3cc0000e9000000006a146808f655
timestamp: 2017-11-26 15:18:47

Version Info:

0: [No Data]

Generic.Keylogger.2.01E2270A also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGeneric.Keylogger.2.01E2270A
FireEyeGeneric.mg.00c90964efd958b1
ALYacGeneric.Keylogger.2.01E2270A
CylanceUnsafe
ZillyaTrojan.Generic.Win32.188869
SangforTrojan.Win32.Save.a
Cybereasonmalicious.4efd95
BitDefenderThetaGen:NN.ZexaF.34698.@vX@ayR0obi
CyrenW32/Injector.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R067C0WJ322
KasperskyUDS:Trojan.Win32.Inject.sb
BitDefenderGeneric.Keylogger.2.01E2270A
AvastWin32:Dh-A [Heur]
TencentMalware.Win32.Gencirc.10b27b49
Ad-AwareGeneric.Keylogger.2.01E2270A
EmsisoftGeneric.Keylogger.2.01E2270A (B)
VIPREGeneric.Keylogger.2.01E2270A
TrendMicroTROJ_GEN.R067C0WJ322
McAfee-GW-EditionArtemis
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataGeneric.Keylogger.2.01E2270A
JiangminTrojan.Generic.gyeqn
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.3303
ArcabitGeneric.Keylogger.2.01E2270A
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
McAfeeArtemis!00C90964EFD9
MAXmalware (ai score=85)
VBA32Trojan.Occamy
MalwarebytesMalware.Heuristic.1001
RisingTrojan.Invader!8.450 (RDMK:cmRtazqnyqwBKgs8qwa4fPrp/fm1)
YandexTrojan.GenAsa!xI9xVZQ8rlg
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic!tr
AVGWin32:Dh-A [Heur]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generic.Keylogger.2.01E2270A?

Generic.Keylogger.2.01E2270A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment