Malware

KeyBase.1 removal guide

Malware Removal

The KeyBase.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What KeyBase.1 virus can do?

  • Network activity detected but not expressed in API logs

How to determine KeyBase.1?


File Info:

crc32: 19CA7FB2
md5: b86c000007846c924e1f4a82a842686f
name: B86C000007846C924E1F4A82A842686F.mlw
sha1: 8c0fa5188b3c54c0e1f976f93d2ddfbcbe6f22b6
sha256: 2e097fe074b8ea46ccb330e8a0302cac0f9a58736e1ebebd1a2c9e8a849dbeb8
sha512: c0173d60c3e3d8957d7c7a2260d326e1534d20a8dc9c946e6937946b47556c073d1219cc17722adce492342e5b04153e1ff81f91a08287636ef0b78159c93ae4
ssdeep: 6144:i9GCDkel6mpdl4TKjwzXTz4EvzSaKYriP+qAkoakCc8L0fB4L:/vewiKq/2+3iVS0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright 1984-2018 Adobe Systems Incorporated and its licensors. All rights reserved.
Assembly Version: 19.10.20069.49826
InternalName: YConsoleApp117all.exe
FileVersion: 19.10.20069.49826
CompanyName: Adobe Systems Incorporated
LegalTrademarks:
Comments: Adobe Acrobat DC
ProductName: Adobe Acrobat DC
ProductVersion: 19.10.20069.49826
FileDescription: Adobe Acrobat DC
OriginalFilename: YConsoleApp117all.exe

KeyBase.1 also known as:

K7AntiVirusTrojan ( 00588bcd1 )
LionicTrojan.Win32.KeyBase.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.18490
CynetMalicious (score: 100)
ALYacGen:Variant.KeyBase.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:MSIL/Blocker.0f6302f8
K7GWTrojan ( 00588bcd1 )
Cybereasonmalicious.007846
CyrenW32/MSIL_Kryptik.GAU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ADJY
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Dropper.Generic-7113183-0
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Variant.KeyBase.1
MicroWorld-eScanGen:Variant.KeyBase.1
TencentMalware.Win32.Gencirc.11d616f0
Ad-AwareGen:Variant.KeyBase.1
SophosMal/Generic-S
ComodoTrojWare.Win32.UMal.syxgv@0
BitDefenderThetaGen:NN.ZemsilF.34266.vm0@auz5qAk
TrendMicroRansom_Blocker.R002C0WK421
McAfee-GW-EditionRDN/BitRAT
FireEyeGen:Variant.KeyBase.1
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.akvhx
WebrootW32.Trojan.Gen
AviraTR/Dropper.MSIL.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
GDataGen:Variant.KeyBase.1
AhnLab-V3Trojan/Win.Generic.C4754007
McAfeeRDN/BitRAT
MAXmalware (ai score=81)
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Blocker.R002C0WK421
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FLUL!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove KeyBase.1?

KeyBase.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment