Spy

What is “MSIL/Spy.Keylogger.EAI”?

Malware Removal

The MSIL/Spy.Keylogger.EAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Spy.Keylogger.EAI virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Spy.Keylogger.EAI?


File Info:

name: 8052BBF2FD7370EA03B2.mlw
path: /opt/CAPEv2/storage/binaries/8ccf4e11de4c44202bfc4f62c8a1f7602f79e98a5f4127097bae84165efe1717
crc32: 7422FBF4
md5: 8052bbf2fd7370ea03b2516f0a768d96
sha1: 1e36c50a369e4402e0e193b44bb2469e8b4fce48
sha256: 8ccf4e11de4c44202bfc4f62c8a1f7602f79e98a5f4127097bae84165efe1717
sha512: c56f7af4b156deb331bcfc7c46c4032ab47e5febd252edaff7b3895b29ce6e5f9473969076d34e05d89a343a3c20996ad5c306b95a7798a0ea03bca835020822
ssdeep: 96:eyPnqdeWJtyVHDpj9ZthXsgRjzkKv/LQR+rkiHgFpUfkFHNwzNtt:3qPyRDp5Zth8gBkajQInHgUfkFtSz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC12F71667C88A36DD7A0B3689B362441376E7069877DAAF64DC504F9FA33000792EB1
sha3_384: 2832d0d522c2e2b8a456308dfcdb7587f65cd8905448839870514287fcdf4becb12b63ba426f29ab7ec14cc6c2958dce
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-04-27 14:57:47

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: KeyLogger
FileVersion: 1.0.0.0
InternalName: KeyLogger.exe
LegalCopyright: Copyright © 2016
LegalTrademarks:
OriginalFilename: KeyLogger.exe
ProductName: KeyLogger
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Spy.Keylogger.EAI also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.38187097
FireEyeGeneric.mg.8052bbf2fd7370ea
ALYacTrojan.GenericKD.38187097
AlibabaTrojan:MSIL/SpywareX.4cec87c8
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Spy.Keylogger.EAI
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.38187097
AvastWin32:SpywareX-gen [Trj]
Ad-AwareTrojan.GenericKD.38187097
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.38187097 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38187097
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.Generic.D246B059
MicrosoftBackdoor:Win32/Bladabindi!ml
McAfeeArtemis!8052BBF2FD73
MAXmalware (ai score=83)
VBA32Trojan.MSIL.gen.4
MalwarebytesSpyware.KeyLogger
IkarusTrojan.MSIL.Spy
FortinetMSIL/Keylogger.EAI!tr.spy
BitDefenderThetaGen:NN.ZemsilF.34062.am0@aKi1T6b
AVGWin32:SpywareX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Spy.Keylogger.EAI?

MSIL/Spy.Keylogger.EAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment