Malware

Generic.Keylogger.2.5167C2E4 information

Malware Removal

The Generic.Keylogger.2.5167C2E4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.5167C2E4 virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
d.nxxxn.ga

How to determine Generic.Keylogger.2.5167C2E4?


File Info:

crc32: 87E0C6B9
md5: 0a79285ad0e13531a730e7c824c36e16
name: 0A79285AD0E13531A730E7C824C36E16.mlw
sha1: fac07ce363d0a9cf6a766a5426d8abc4fb673f50
sha256: f54ab9736e0b804a3ca5bc39821b6d6d24f1c55c5e61f773611009a0fbadac55
sha512: 90de77b41d28c9210a559c387bfec067ff68bfaeae21813e08a6d2ba43f99ce497664a0b81fa9d0132599c09853a5be3e0b5c1a2eba549a09544895ab3711c4f
ssdeep: 6144:3v5zQJVb5p72cHF1ybDFwekh212KhvwIb759QOaBjpaVRPu23E2rJmWjFc94:34VOiF1WD7kE1dTYOi8V5u23zmWFy4
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: (C) 360.cn All Rights Reserved.
InternalName: LSPFix
FileVersion: 7, 1, 3, 1057
CompanyName: 360.cn
ProductName: 360x5b89x5168x536bx58eb
ProductVersion: 7, 1, 3, 1057
FileDescription: 360x5b89x5168x536bx58eb LSPx4feex590dx6a21x5757
OriginalFilename: LSPFix.EXE
Translation: 0x0804 0x04b0

Generic.Keylogger.2.5167C2E4 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Farfli.96
MicroWorld-eScanDeepScan:Generic.Keylogger.2.5167C2E4
FireEyeGeneric.mg.0a79285ad0e13531
CAT-QuickHealTrojan.Magania.18692
McAfeeArtemis!0A79285AD0E1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004c81771 )
BitDefenderDeepScan:Generic.Keylogger.2.5167C2E4
K7GWTrojan ( 004c81771 )
Cybereasonmalicious.ad0e13
BitDefenderThetaGen:NN.ZexaF.34780.xm1@amtk6uij
CyrenW32/S-6cc11623!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:Malware-gen
ClamAVWin.Malware.Deepscan-9770175-0
KasperskyTrojan-Banker.Win32.Banbra.wvay
RisingBackdoor.Farfli!8.B4 (TFE:5:bL8vVvLdNzM)
Ad-AwareDeepScan:Generic.Keylogger.2.5167C2E4
SophosML/PE-A + Troj/AutoG-KB
ComodoTrojWare.Win32.Fusing.CF@5afr59
F-SecureTrojan.TR/Agent.fjrz
McAfee-GW-EditionGenericRXDW-XG!5027FF28BBE4
EmsisoftDeepScan:Generic.Keylogger.2.5167C2E4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fjkle
eGambitUnsafe.AI_Score_59%
AviraTR/Agent.fjrz
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftBackdoor:Win32/PcClient
GridinsoftTrojan.Win32.PcClient.vb!s1
ArcabitDeepScan:Generic.Keylogger.2.5167C2E4
SUPERAntiSpywareBackdoor.PcClient/Variant
ZoneAlarmTrojan-Banker.Win32.Banbra.wvay
GDataDeepScan:Generic.Keylogger.2.5167C2E4
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2832100
Acronissuspicious
VBA32BScope.Trojan-GameThief.Magania
MalwarebytesBackdoor.Farfli
APEXMalicious
ESET-NOD32Win32/Farfli.BGG
TencentMalware.Win32.Gencirc.10b40de8
YandexTrojan.GenAsa!TUiWhMkZPf8
IkarusTrojan.Win32.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Midie.26C0!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM18.1.F1C9.Malware.Gen

How to remove Generic.Keylogger.2.5167C2E4?

Generic.Keylogger.2.5167C2E4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment