Spy

About “MSIL/Spy.Keylogger.ATV” infection

Malware Removal

The MSIL/Spy.Keylogger.ATV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Keylogger.ATV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine MSIL/Spy.Keylogger.ATV?


File Info:

crc32: 1693BBE6
md5: 652f82fa36a6292ae1a5570293ebb768
name: 652F82FA36A6292AE1A5570293EBB768.mlw
sha1: 2d55c23cb80adb907113c49eae000c2f225d8663
sha256: c2dc297878a1d5409a600a16768fedcf3d7e39545b9c7284d90dc2824f8d2de7
sha512: b9fb990f00bb108661c6d0529a83d67f539a0f60d807f0bc7a0f809fb703bb428d2691d626a5a1c481f5f438f85ca0ac8f807935b4f6304c5c42bde364bd3aa8
ssdeep: 6144:KAoyoMGGGGGGGGGGbGGGGGGGGGG6GG/DGXxeXJE85PmWyVcjUkdHbIIA:fKHjl
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: stub.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: stub.exe

MSIL/Spy.Keylogger.ATV also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.31441
CynetMalicious (score: 99)
ALYacGen:Heur.MSIL.Krypt.2
CylanceUnsafe
SangforRansom.Win32.Blocker.goqt
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.a36a62
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Keylogger.ATV
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.goqt
BitDefenderGen:Heur.MSIL.Krypt.2
NANO-AntivirusTrojan.Win32.Blocker.dotbhp
MicroWorld-eScanGen:Heur.MSIL.Krypt.2
TencentWin32.Trojan.Blocker.Wmjf
Ad-AwareGen:Heur.MSIL.Krypt.2
ComodoMalware@#2lwwwe6gdj9m0
BitDefenderThetaGen:NN.ZemsilF.34058.tm0@ayQb0!b
VIPREMSIL.Spy.Keylogger
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.652f82fa36a6292a
EmsisoftGen:Heur.MSIL.Krypt.2 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.E8BF56
MicrosoftTrojan:Win32/Dynamer!ac
ZoneAlarmTrojan-Ransom.Win32.Blocker.goqt
GDataGen:Heur.MSIL.Krypt.2
AhnLab-V3Trojan/Win32.Delfiles.R2378
McAfeeArtemis!652F82FA36A6
MAXmalware (ai score=85)
MalwarebytesBackdoor.Agent.PGen
PandaTrj/CI.A
YandexTrojan.Blocker!5IGdkREv9A8
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Keylogger.ATV!tr.spy
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgAASSEA

How to remove MSIL/Spy.Keylogger.ATV?

MSIL/Spy.Keylogger.ATV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment