Malware

Generic.Keylogger.6.D2EB69C8 (file analysis)

Malware Removal

The Generic.Keylogger.6.D2EB69C8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Keylogger.6.D2EB69C8 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
smtp.yandex.com
repository.certum.pl

How to determine Generic.Keylogger.6.D2EB69C8?


File Info:

crc32: C3B7FD4E
md5: 09a03ba6e66fda9442f7382e9076e30d
name: sabriiiii.exe
sha1: 98137d88fea27d450d99e9bcfff75e7bb6e03a00
sha256: 8b8d5e64739617028749c6e0bdcf0b6770b691f95a35e301173392e57ef0f9d6
sha512: e79621ca9df70013524bf1533807504ca401ebc491d56de2078faa8728b510ef990872cc314415d3b20ddfc1ff304881b3b47707d8a0d6c11f19ed876cf3be77
ssdeep: 1536:n9kJ/pqzeXcn4SgAlXQdbEh9Pw3j8d4w3t89aYbfmYgEHxRoIVigTB:e/seXcn4zlaOJ9amhHxRoI/9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 15.00
InternalName: Service
FileVersion: 15.00
OriginalFilename: Service.exe
ProductName: Service
Translation: 0x0409 0x04b0

Generic.Keylogger.6.D2EB69C8 also known as:

BkavW32.CiscesaBCAAA.Trojan
DrWebTrojan.MulDrop6.62867
MicroWorld-eScanGeneric.Keylogger.6.D2EB69C8
McAfeePUP-XAL-VT
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 00442b511 )
BitDefenderGeneric.Keylogger.6.D2EB69C8
K7GWSpyware ( 00442b511 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R002C0ODS20
BitDefenderThetaGen:NN.ZevbaF.34108.hm0@aCi!QYoO
CyrenW32/Diztakun.YYNS-7375
SymantecSMG.Heur!gen
ZonerTrojan.Win32.85509
TrendMicro-HouseCallTROJ_GEN.R002C0ODS20
AvastWin32:Malware-gen
ClamAVWin.Dropper.TrickBot-7354129-0
GDataWin32.Trojan-Stealer.Hakops.A
KasperskyTrojan.Win32.Diztakun.asae
AlibabaTrojanSpy:Win32/Diztakun.b50cc852
NANO-AntivirusTrojan.Win32.VB.ehlhxv
AegisLabTrojan.Win32.Diztakun.tnyY
TencentMalware.Win32.Gencirc.10b0b220
Endgamemalicious (high confidence)
SophosKeylogger (PUA)
ComodoTrojWare.Win32.KeyLogger.Diztakun.A@72rokn
F-SecureTrojan.TR/VB.Downloader.Gen
BaiduWin32.Trojan-Spy.VB.e
ZillyaTrojan.Diztakun.Win32.2758
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.09a03ba6e66fda94
EmsisoftGeneric.Keylogger.6.D2EB69C8 (B)
IkarusTrojan-Spy.Agent
F-ProtW32/Diztakun.M
JiangminTrojan.Diztakun.bqm
MaxSecureTrojan.Malware.10044411.susgen
AviraTR/VB.Downloader.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitGeneric.Keylogger.6.D2EB69C8
SUPERAntiSpywarePUP.Keylogger/Variant
ZoneAlarmTrojan.Win32.Diztakun.asae
MicrosoftMonitoringTool:Win32/AnyKeylogger
AhnLab-V3Trojan/Win32.Agent.R192285
Acronissuspicious
VBA32Trojan.Diztakun
ALYacGeneric.Keylogger.6.D2EB69C8
Ad-AwareGeneric.Keylogger.6.D2EB69C8
MalwarebytesTrojan.KeyLogger
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32Win32/Spy.KeyLogger.OSB
RisingTrojan.Sysn!1.A23F (CLOUD)
YandexTrojanSpy.KeyLogger!3QQn1YheGrE
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Diztakun.ASAE!tr
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.46b

How to remove Generic.Keylogger.6.D2EB69C8?

Generic.Keylogger.6.D2EB69C8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment