Malware

Generic.Keylogger.2.AE72E8C3 (file analysis)

Malware Removal

The Generic.Keylogger.2.AE72E8C3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.AE72E8C3 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Generic.Keylogger.2.AE72E8C3?


File Info:

name: 7735CCD928BEE0CBF037.mlw
path: /opt/CAPEv2/storage/binaries/c16c9c5800345ff7affc87206a4998d5dd639dd10de8f59072c1ccc109088ddf
crc32: 00789B7A
md5: 7735ccd928bee0cbf0373ef695a57b81
sha1: 0d1d7633d78764637b018e477f0a6f90be09b604
sha256: c16c9c5800345ff7affc87206a4998d5dd639dd10de8f59072c1ccc109088ddf
sha512: f21a70d875465fb7e5a458519cb49a4e1ec949164d35c51151cab4d6b1d161d76c8c98f754568bfa55ea8bcba2a332c9d268cc72de025e0dd783735ac4c84d01
ssdeep: 12288:w/cUoABfJFsQCvVj/CHNmZzCXK6g8eB0jOiaTNLIbNL+6f2SQ4OdNd4Zhuf:YcUNsQsj/aNUC6MeB0jOi2IbN6otlaSA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FD4235B61183690D9C21E78DA6FA2B44830AD472C503CB34C56FC9AF97B5DAFA0CE07
sha3_384: e29bc13526bdfe8b8c31e20829d11bed9d1c020aa8d6cbbc228a1164821442b7c938948729a8c12f61f5711ace9fd294
ep_bytes: 60be002043008dbe00f0fcff5783cdff
timestamp: 2010-07-01 05:39:56

Version Info:

CompanyName: Labeter 2005-2017
FileDescription: Proteug 10 AppLication
FileVersion: 7, 10, 33, 380
InternalName: Server.exe
LegalCopyright: Proteug (C) 保留所有权利。
OriginalFilename: Server.exe
ProductName: TODO:
ProductVersion: 7, 10, 33, 380
Translation: 0x0804 0x03a8

Generic.Keylogger.2.AE72E8C3 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Keylogger.2.AE72E8C3
FireEyeGeneric.mg.7735ccd928bee0cb
McAfeeArtemis!7735CCD928BE
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005677151 )
K7GWTrojan ( 0050ed721 )
Cybereasonmalicious.928bee
CyrenW32/QQhelper.C.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/Farfli.BGG
APEXMalicious
ClamAVWin.Malware.Deepscan-6972384-0
KasperskyTrojan-Banker.Win32.Banbra.wxcc
BitDefenderDeepScan:Generic.Keylogger.2.AE72E8C3
NANO-AntivirusTrojan.Win32.GenKryptik.fslxzc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b9aa87
Ad-AwareDeepScan:Generic.Keylogger.2.AE72E8C3
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.GenKryptik.Win32.31798
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.hc
Trapminesuspicious.low.ml.score
EmsisoftDeepScan:Generic.Keylogger.2.AE72E8C3 (B)
JiangminTrojan.Generic.bacrz
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDeepScan:Generic.Keylogger.2.AE72E8C3
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.FL.C5166974
BitDefenderThetaAI:Packer.7399527C1F
ALYacDeepScan:Generic.Keylogger.2.AE72E8C3
MAXmalware (ai score=81)
VBA32BScope.Trojan-GameThief.Magania
MalwarebytesTrojan.Injector
YandexTrojan.GenAsa!Bo60Z8VoEiY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.AIGT!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Generic.Keylogger.2.AE72E8C3?

Generic.Keylogger.2.AE72E8C3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment