Malware

Generic.Keylogger.2.FC654BAF (file analysis)

Malware Removal

The Generic.Keylogger.2.FC654BAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.2.FC654BAF virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Generic.Keylogger.2.FC654BAF?


File Info:

crc32: 7C9B3E45
md5: 57217eb6e20111a0c920ad0da2d77818
name: af1c1f3ee9ca22a077d1685b1df3f202.exe
sha1: 2af513372e7bae653c2942effdc068a73fa72717
sha256: 8246f2b18a1592cc2a37c001e2415412f5e63d14220324ae8356981e25a4ba76
sha512: 92d7119dd19b366ead9e5c56fe4e4e0a70dd0a2e8a3c49925d6001be5ab509c5ab5d880e31d2d3460880f9ffb06a79a1fda5c5275dc63e0bf16ddef501020051
ssdeep: 6144:SxLA03gEC9ffl6IOnxo60hDadHnfw4drnBro1MhiaXRiV3zOjH2TXD6ohHRr4yE:SxLAYC9l6hxobgwanBrtVAttD2ob
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Keylogger.2.FC654BAF also known as:

DrWebTrojan.DownLoader33.21655
MicroWorld-eScanGeneric.Keylogger.2.FC654BAF
McAfeeGenericRXAA-AA!57217EB6E201
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1250206
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGeneric.Keylogger.2.FC654BAF
K7GWSpyware ( 00549a701 )
K7AntiVirusSpyware ( 00549a701 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34104.wmGfama9EGmi
CyrenW32/Application.PNXH-0307
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PQM
TrendMicro-HouseCallTROJ_GEN.R04AC0DD120
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:Win32/Keylogger.37c3327f
RisingTrojan.Injector!1.AE3D (CLOUD)
Endgamemalicious (moderate confidence)
EmsisoftGeneric.Keylogger.2.FC654BAF (B)
F-SecureHeuristic.HEUR/AGEN.1043063
VIPRETrojan-Spy.Win32.KeyLogger
TrendMicroTROJ_GEN.R04AC0DD120
McAfee-GW-EditionBehavesLike.Win32.Virut.fc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.57217eb6e20111a0
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
JiangminTrojan.Generic.eksff
AviraHEUR/AGEN.1043063
FortinetW32/Spy.AGENT.PQM!tr
Antiy-AVLTrojan[Spy]/Win32.KeyLogger
ArcabitGeneric.Keylogger.2.FC654BAF
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Malware/Win32.RL_Generic.R283639
Acronissuspicious
VBA32BScope.Backdoor.Agent
ALYacGeneric.Keylogger.2.FC654BAF
MAXmalware (ai score=87)
Ad-AwareGeneric.Keylogger.2.FC654BAF
MalwarebytesBackdoor.Revcode
PandaTrj/GdSda.A
APEXMalicious
TencentWin32.Trojan.Generic.Sudt
YandexTrojan.Revcode!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataGeneric.Keylogger.2.FC654BAF
MaxSecureTrojan.Malware.74776117.susgen
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.6e2011
AvastWin32:RATX-gen [Trj]
Qihoo-360HEUR/QVM11.1.4DE1.Malware.Gen

How to remove Generic.Keylogger.2.FC654BAF?

Generic.Keylogger.2.FC654BAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment