Malware

About “Generic.Keylogger.6.8AE9F9A7” infection

Malware Removal

The Generic.Keylogger.6.8AE9F9A7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.6.8AE9F9A7 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

smtp.yandex.com
repository.certum.pl

How to determine Generic.Keylogger.6.8AE9F9A7?


File Info:

crc32: 5D156BB4
md5: 7c53d1f6f821fe0dacd5784f9172ba41
name: sonoyuncu..exe
sha1: db74237da459fca75588bba2ee3a85925c9b10cd
sha256: fb329fe647702d59655b69ae213b895bcb518e417a29e65bfd761bb311743e35
sha512: bd3eb0da5277b18db77b96308e977bce7b9992b8d73ebc6b23df10a8a1fc8b12b37f47d298615d48feee9eeb411a8487082893b55976ff64709de8f1d911b7ed
ssdeep: 1536:QTIiMeq7HxZzGBsiSgo0SBFkiR053U+cI+XfsYBS6jScaz1XnXgXijeXrVI8iUjc:ubMeq7RZ4sR0U+cl0DQBLJj2t
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Mscvin
FileVersion: 1.00
CompanyName: Mscvin
ProductName: Mscvin
ProductVersion: 1.00
OriginalFilename: Mscvin.exe
Translation: 0x0409 0x04b0

Generic.Keylogger.6.8AE9F9A7 also known as:

MicroWorld-eScanGeneric.Keylogger.6.8AE9F9A7
FireEyeGeneric.mg.7c53d1f6f821fe0d
CAT-QuickHealTrojanspy.Vlogger.A3
McAfeeGenericRXAF-HQ!7C53D1F6F821
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 004b7a371 )
BitDefenderGeneric.Keylogger.6.8AE9F9A7
K7GWSpyware ( 004b7a371 )
CrowdStrikewin/malicious_confidence_80% (D)
TrendMicroTSPY_SYSN_EJ19019F.UVPM
BaiduWin32.Trojan-Spy.VB.e
CyrenW32/VB.FNDD-7067
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Keylogger.Sysn-6809104-0
GDataWin32.Trojan-Stealer.Hakops.A
KasperskyTrojan-Dropper.Win32.Sysn.bfnw
NANO-AntivirusTrojan.Win32.TrjGen.dxlrun
RisingTrojan.Sysn!1.A23F (CLASSIC)
Ad-AwareGeneric.Keylogger.6.8AE9F9A7
SophosKeylogger (PUA)
ComodoTrojWare.Win32.TrojanSpy.Vlogger.GG@77echk
F-SecureTrojan.TR/VB.Downloader.Gen
DrWebTrojan.Siggen6.63796
ZillyaTrojan.VB.Win32.147756
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Shadebot.cm
EmsisoftGeneric.Keylogger.6.8AE9F9A7 (B)
IkarusTrojan-Spy.Agent
F-ProtW32/VB.DSP
JiangminTrojan.Generic.aarl
WebrootTrojan.Dropper.Gen
AviraTR/VB.Downloader.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Dropper]/Win32.Sysn
Endgamemalicious (high confidence)
ArcabitGeneric.Keylogger.6.8AE9F9A7
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan-Dropper.Win32.Sysn.bfnw
MicrosoftTrojanSpy:Win32/Vlogger.gen!A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R168618
VBA32Malware-Cryptor.VB.gen.1
ALYacGeneric.Keylogger.6.8AE9F9A7
MalwarebytesTrojan.HakopsKeyLogger
PandaTrj/Genetic.gen
ZonerTrojan.Win32.74798
ESET-NOD32Win32/Spy.VB.NZV
TrendMicro-HouseCallTSPY_SYSN_EJ19019F.UVPM
TencentMalware.Win32.Gencirc.10b09442
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/DropperSysn.BFNW!tr
BitDefenderThetaAI:Packer.A925848C20
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.6f821f
Qihoo-360HEUR/QVM03.0.D5FB.Malware.Gen

How to remove Generic.Keylogger.6.8AE9F9A7?

Generic.Keylogger.6.8AE9F9A7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment