Spy

How to remove “MonitoringTool:Win32/TotalSpy”?

Malware Removal

The MonitoringTool:Win32/TotalSpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MonitoringTool:Win32/TotalSpy virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine MonitoringTool:Win32/TotalSpy?


File Info:

name: 5D944ACB881AE9397E88.mlw
path: /opt/CAPEv2/storage/binaries/a2e8947e058922e11b23b389ee9e44893731dc5d3e1e0a7a75063a452b82c3cd
crc32: 33A96087
md5: 5d944acb881ae9397e88a288c6b6137a
sha1: f3e9a40e483eaf7dd74d45d8f3a5272cfd909c55
sha256: a2e8947e058922e11b23b389ee9e44893731dc5d3e1e0a7a75063a452b82c3cd
sha512: 34b0a9fe57de79fb7c852f02b8306eda3e23e566a9756068a8586aa94da08393fca0d564fbaee67d7a25cea3114f7a324ac0422ba73f11444e7b880abffbd6d9
ssdeep: 12288:Cc+MevXdrHieGPeUUd7YW/ebxOgDsdLsI8sMHpyv7xMDRGCU5gwYft0qDHadGhUi:l+MevllLs1sMHpyHCXft0qD6dMURVQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168254A12BAE0486BD53339FB9CC752947865FE702A145E436BE83D48FF79BD23821252
sha3_384: dbabfc28ea8dec65f276ec6ba1102a6b42339da11c77144ca5e570aaf3b906f721df6ef42b2c7eec28094ce255c4c7ca
ep_bytes: 558bec83c4f033c08945f0b8f0b84c00
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

MonitoringTool:Win32/TotalSpy also known as:

BkavW32.Common.A98FAAA7
LionicTrojan.Win32.Keylogger.l!c
FireEyeGeneric.mg.5d944acb881ae939
CAT-QuickHealTrojanSpy.KeyLogger
SkyhighBehavesLike.Win32.PUP.dh
McAfeeArtemis!5D944ACB881A
Cylanceunsafe
SangforSpyware.Win32.KeyLogger.V5qp
K7AntiVirusPassword-Stealer ( 004973991 )
AlibabaTrojanSpy:Win32/FreeKeylogger.09036739
K7GWPassword-Stealer ( 004973991 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36744.9GW@a8h87xok
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/KeyLogger.FreeKeylogger.B
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.KeyLogger.gen
NANO-AntivirusRiskware.Win32.FreeKeylogger.ebonbg
AvastWin32:PUP-gen [PUP]
TencentWin32.Trojan-Spy.Keylogger.Eflw
ZillyaTrojan.Keylogger.Win32.71816
SophosMal/Generic-S
IkarusPUA.KeyLogger.Freekeylogger
WebrootW32.Malware.Gen
GoogleDetected
Antiy-AVLRiskWare[Monitor]/Win32.FreeKeylogger
XcitiumMalware@#3j1gllskquq3e
ViRobotAdware.Freekeylogger.999424
ZoneAlarmHEUR:Trojan-Spy.Win32.KeyLogger.gen
MicrosoftMonitoringTool:Win32/TotalSpy
AhnLab-V3PUP/Win32.Helper.C1441507
VBA32TrojanSpy.Keylogger
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CAO24
RisingTrojan.Generic@AI.88 (RDML:MvL/BLSWx6Gr/Dhg7w/caQ)
YandexTrojan.GenAsa!c/bE+sVNEj8
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FreeKeylogger
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.e483ea
DeepInstinctMALICIOUS

How to remove MonitoringTool:Win32/TotalSpy?

MonitoringTool:Win32/TotalSpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment