Malware

Generic.Keylogger.2.C74647FB information

Malware Removal

The Generic.Keylogger.2.C74647FB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.C74647FB virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself

Related domains:

d.nxxxn.ga
r.pengyou.com

How to determine Generic.Keylogger.2.C74647FB?


File Info:

crc32: 4498C77A
md5: c2d4244ab9677f2af2d333b6244d9f3f
name: SQLSernsf.exe
sha1: b920103f84d3d6888d08304096fbb15190a83d50
sha256: 4aed65276d2b559f90fe15473e870c255869c1d93b3489188cd6e4136c23bd65
sha512: 6ebcab00872f012fa1293c7943300c60324d2fe5ca94cdb058bc4ae82c8979bf8c56166bf896f54e4db967567104fdf23161063b7fcbe4a8edf48ab53323c2c4
ssdeep: 6144:dv5zQJVb5p72cHF1ybDFwekh212KhvwIb759QOaBjpaVRPu23E2rJmWjFc94:d4VOiF1WD7kE1dTYOi8V5u23zmWFy4
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: (C) 360.cn All Rights Reserved.
InternalName: LSPFix
FileVersion: 7, 1, 3, 1057
CompanyName: 360.cn
ProductName: 360x5b89x5168x536bx58eb
ProductVersion: 7, 1, 3, 1057
FileDescription: 360x5b89x5168x536bx58eb LSPx4feex590dx6a21x5757
OriginalFilename: LSPFix.EXE
Translation: 0x0804 0x04b0

Generic.Keylogger.2.C74647FB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanDeepScan:Generic.Keylogger.2.C74647FB
FireEyeGeneric.mg.c2d4244ab9677f2a
CAT-QuickHealTrojan.Magania.18692
ALYacDeepScan:Generic.Keylogger.2.C74647FB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004c81771 )
BitDefenderDeepScan:Generic.Keylogger.2.C74647FB
K7GWTrojan ( 004c81771 )
Cybereasonmalicious.ab9677
BitDefenderThetaGen:NN.ZexaF.34100.xm1@aCydqRfj
CyrenW32/S-6cc11623!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.BGG
APEXMalicious
GDataDeepScan:Generic.Keylogger.2.C74647FB
KasperskyTrojan.Win32.Agent.xabxmr
RisingBackdoor.Farfli!8.B4 (CLOUD)
Ad-AwareDeepScan:Generic.Keylogger.2.C74647FB
ComodoTrojWare.Win32.Fusing.CF@5afr59
F-SecureHeuristic.HEUR/AGEN.1042577
DrWebBackDoor.Farfli.96
ZillyaTrojan.Banbra.Win32.29854
Invinceaheuristic
McAfee-GW-EditionGenericRXDW-XG!B9C76DEF243A
Trapminemalicious.high.ml.score
CMCVirus.Win32.Sality!O
EmsisoftDeepScan:Generic.Keylogger.2.C74647FB (B)
IkarusTrojan.Win32.Farfli
F-ProtW32/S-6cc11623!Eldorado
JiangminBackdoor.Farfli.cmb
eGambitUnsafe.AI_Score_52%
AviraHEUR/AGEN.1042577
MAXmalware (ai score=87)
Endgamemalicious (high confidence)
ArcabitDeepScan:Generic.Keylogger.2.C74647FB
SUPERAntiSpywareBackdoor.PcClient/Variant
AhnLab-V3Malware/Win32.Generic.C2832100
ZoneAlarmTrojan.Win32.Agent.xabxmr
MicrosoftBackdoor:Win32/PcClient.ZR
Acronissuspicious
McAfeeGenericRXDW-XG!B9C76DEF243A
VBA32BScope.Trojan-GameThief.Magania
MalwarebytesBackdoor.Farfli
ZonerTrojan.Win32.80229
TencentMalware.Win32.Gencirc.10b40de8
YandexTrojan.PWS.Banbra!fVil7drZyCo
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Midie.26C0!tr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Backdoor.Agent.ACI

How to remove Generic.Keylogger.2.C74647FB?

Generic.Keylogger.2.C74647FB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment