Malware

Generic.PyKeylogger.1.205B04F6 removal instruction

Malware Removal

The Generic.PyKeylogger.1.205B04F6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PyKeylogger.1.205B04F6 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Generic.PyKeylogger.1.205B04F6?


File Info:

name: 25B994E1C8DC81BCF4DF.mlw
path: /opt/CAPEv2/storage/binaries/6236d6ae4014637f3e137d68ba25d02f6e7321469571ac24cfc29586043ccc31
crc32: 2133C21D
md5: 25b994e1c8dc81bcf4dfd3513c6a5727
sha1: 1932d1d5e01dd1f807ae5f0805dba0f3da741981
sha256: 6236d6ae4014637f3e137d68ba25d02f6e7321469571ac24cfc29586043ccc31
sha512: eef233a09f15623e518ba3979dcf636bd975e7149967ac3db948c49e202c79ea6c527a164ede3f9ccf356e7a35bc66843df8e80ff00211ef2a2e7976705afe00
ssdeep: 98304:4RMMMNqSAALKTDbdRGQSxUTZeNEiIK176Fz1p/kpkG51JfhRAKVaFvdjIL4om:hqP7TDp4QeUpg176F1p/k/XtPA0AdMp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC56339988121470F66285B6C363FD46A50EB7D5CF33982BC7113B66A873ACD1A53C2B
sha3_384: ea54c38f6ad563b761ef96a352469b20bbbc93fe421bf13ef2643dbe69f5fcb06b456857fbc83ddca070f83cde63fa3b
ep_bytes: 60be004043008dbe00d0fcff57eb0b90
timestamp: 2021-08-01 04:40:34

Version Info:

0: [No Data]

Generic.PyKeylogger.1.205B04F6 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.593226
ALYacGeneric.PyKeylogger.1.205B04F6
CylanceUnsafe
ZillyaTrojan.Reconyc.Win32.32015
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/Spy.KeyLogger.NG
APEXMalicious
BitDefenderGen:Variant.Bulz.593226
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Variant.Bulz.593226
FireEyeGeneric.mg.25b994e1c8dc81bc
EmsisoftGen:Variant.Bulz.593226 (B)
GDataWin32.Trojan.PSE.T3TB1E
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.34559CE
ArcabitTrojan.Bulz.D90D4A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R447910
TencentMalware.Win32.Gencirc.11d9fa12
BitDefenderThetaGen:NN.ZexaF.34062.@pJfaOU@J
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.5e01dd
PandaTrj/Genetic.gen

How to remove Generic.PyKeylogger.1.205B04F6?

Generic.PyKeylogger.1.205B04F6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment