Spy

About “MSIL/Spy.Keylogger.CUK” infection

Malware Removal

The MSIL/Spy.Keylogger.CUK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Keylogger.CUK virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Spy.Keylogger.CUK?


File Info:

crc32: 75EDA792
md5: 974bd8aa9d668d6318ca34d9ae4aaf79
name: ql.exe
sha1: 9a6cda6d3424f996e4c322a6a55dc13191e418cc
sha256: 9a4c350c16a2c82aca1a47680efb1120f24cea54cd7d1472d8ea01c08169c7d5
sha512: c3d72f77a25bccd47951cd314296608f0058fc9fb6d809bf31e94475fde18caf8838b066152269ab5db9cab300a14c1ecc22e18a234a4287d03dd6833e7f7a2b
ssdeep: 24576:i20gPgFKA1FGERjUG3y1pg67SlAJxO6pkNRGJxOQQ:TKCWja1pg61JU6pkNEJUF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL/Spy.Keylogger.CUK also known as:

MicroWorld-eScanTrojan.GenericKD.42082594
FireEyeGeneric.mg.974bd8aa9d668d63
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.42082594
SangforMalware
K7AntiVirusSpyware ( 00539c921 )
BitDefenderTrojan.GenericKD.42082594
K7GWSpyware ( 00539c921 )
Cybereasonmalicious.a9d668
Invinceaheuristic
CyrenW32/Application.VDWR-3710
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.42082594
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:MSIL/KeyLogger.b8e62f47
ViRobotTrojan.Win32.Z.Spy.819082
AegisLabTrojan.Win32.Generic.4!c
RisingSpyware.KeyLogger!8.12F (CLOUD)
Ad-AwareTrojan.GenericKD.42082594
SophosMal/Generic-S
ComodoMalware@#1zx5taxm537mh
F-SecureTrojan.TR/SPY.KeyLogger.lckrs
TrendMicroTROJ_GEN.R023C0PLD19
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42082594 (B)
AviraTR/SPY.KeyLogger.lckrs
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2822122
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C3638343
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=88)
PandaTrj/CI.A
ESET-NOD32MSIL/Spy.Keylogger.CUK
TrendMicro-HouseCallTROJ_GEN.R023C0PLD19
TencentWin32.Trojan.Spy.Hssh
IkarusTrojan.MSIL.Spy
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Keylogger.CUK!tr.spy
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove MSIL/Spy.Keylogger.CUK?

MSIL/Spy.Keylogger.CUK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment