Malware

Generic.Keylogger.2.12FAA1D2 removal tips

Malware Removal

The Generic.Keylogger.2.12FAA1D2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.12FAA1D2 virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz
m.gmcc.live
users.qzone.qq.com

How to determine Generic.Keylogger.2.12FAA1D2?


File Info:

crc32: CA97974D
md5: 3259351e074e0b036efec11043f02614
name: 3259351E074E0B036EFEC11043F02614.mlw
sha1: 9dfb613f26f638037eb197288fdb375ce17e29b7
sha256: a7da78124f82c045c8482886cb4716ceb14407b8ad6581e36fb2e60f99d6f29b
sha512: 707625de4c34c1fe759db715ab71e809d613b0d25041d081ae59c2d49089b871eee88ad283b61b7e545d9ec3be95ab6d0de4a52253850b7a6f85a03cf02883fc
ssdeep: 1536:C2Gsfd8S8Z64ctqTHFPY3B5/JgAITu3S4cbTygN3k4wNlXsw0+X9AkVcsg8b1:VL8SdxEHC3+ugbTykk4wHswLX9Vb1
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Microsoft Corp. All rights reserved.
InternalName: SQLPS
FileVersion: 10.50.1600.1 ((KJ_RTM).100402-1540 )
CompanyName: Microsoft Corporation
GoldenBits: True
LegalTrademarks: Microsoft SQL Server is a registered trademark of Microsoft Corporation.
Comments: SQL
ProductName: Microsoft SQL Server
Platform: NT INTEL X86
ProductVersion: 10.50.1600.1
FileDescription: SQL Server PowerShell
OriginalFilename: SQLPS.EXE
Translation: 0x0409 0x04b0

Generic.Keylogger.2.12FAA1D2 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0049c30b1 )
Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.744
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Keylogger.2.12FAA1D2
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.32685
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Farfli.64bb2753
K7GWTrojan ( 0049c30b1 )
Cybereasonmalicious.e074e0
CyrenW32/Sality.AJ.gen!Eldorado
SymantecInfostealer.Gampass
ESET-NOD32Win32/Farfli.AYO
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyTrojan-GameThief.Win32.Magania.uhuk
BitDefenderDeepScan:Generic.Keylogger.2.12FAA1D2
NANO-AntivirusTrojan.Win32.Magania.fqcuez
MicroWorld-eScanDeepScan:Generic.Keylogger.2.12FAA1D2
TencentMalware.Win32.Gencirc.10b84eb9
Ad-AwareDeepScan:Generic.Keylogger.2.12FAA1D2
SophosML/PE-A
ComodoTrojWare.Win32.Magania.F@7jjkv4
BitDefenderThetaGen:NN.ZexaF.34236.hmuaaa@CIqfj
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_ZEGOST.SM34
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.3259351e074e0b03
EmsisoftDeepScan:Generic.Keylogger.2.12FAA1D2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Magania.zr
WebrootW32.Trojan.Miner
AviraTR/Patched.Gen
eGambitUnsafe.AI_Score_81%
Antiy-AVLTrojan/Generic.ASMalwS.2B697E1
MicrosoftTrojan:Win32/Farfli.DSK!MTB
GDataDeepScan:Generic.Keylogger.2.12FAA1D2
AhnLab-V3Trojan/Win32.RL_Magania.R269602
Acronissuspicious
McAfeeArtemis!3259351E074E
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Zegost
MalwarebytesTrojan.AVKill
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingTrojan.Win32.Lebag.b (CLASSIC)
YandexTrojan.GenAsa!0xcWrMir5so
IkarusTrojan.Patched
MaxSecureTrojan.Malware.11280276.susgen
FortinetW32/Farfli.AYO!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Generic.Keylogger.2.12FAA1D2?

Generic.Keylogger.2.12FAA1D2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment