PUA Spy

PUA:Win32/SpyrixKeylogger removal instruction

Malware Removal

The PUA:Win32/SpyrixKeylogger is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/SpyrixKeylogger virus can do?

  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Anomalous binary characteristics

How to determine PUA:Win32/SpyrixKeylogger?


File Info:

name: 64BC4E987662E1E86B46.mlw
path: /opt/CAPEv2/storage/binaries/ff921088060b3214db532f59e9bbcfceebfb95f310bff4c37098e233dd3bd77c
crc32: 14232DDE
md5: 64bc4e987662e1e86b464a58d0544df0
sha1: f86283459c6657aa98254c7d660fada89bd4370e
sha256: ff921088060b3214db532f59e9bbcfceebfb95f310bff4c37098e233dd3bd77c
sha512: 296240639917369aa13d27985f3412baa886983c3111cd9a312cdfe6ee9583f94d808569dab09c09692ac73a54f361dfdb9a769880209cd120b1f34ef8eca472
ssdeep: 24576:4pN0RrFnXIRr8UihtBWS5d1RWupI/W5QCaNi4g6PrenDdoJAjmPo1qRScJzs3fzy:NtYSfjWvCnDdHffzy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191954B6262C5B03BE0761BBA4C7BD6545C3B7B603E25C82B2FB45A4C0E35B41AC39B57
sha3_384: c3a4c253fa9cf276375d0511759152ba594597f462cf9a6278e36cb37e719253b98adb83ef16b0bd429474448e861715
ep_bytes: 558becb9070000006a006a004975f951
timestamp: 2020-04-10 06:31:18

Version Info:

0: [No Data]

PUA:Win32/SpyrixKeylogger also known as:

LionicRiskware.Win32.Sprx.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Keylogger.Spyrix.28
FireEyeGen:Variant.Application.Keylogger.Spyrix.28
CAT-QuickHealPUA.GenericPMF.S20733813
McAfeeGenericRXAA-AA!64BC4E987662
CylanceUnsafe
ZillyaTool.Sprx.Win32.35
SangforTrojan.Win32.Sprx.gen
BitDefenderGen:Variant.Application.Keylogger.Spyrix.28
K7GWPassword-Stealer ( 005607e41 )
K7AntiVirusPassword-Stealer ( 005607e41 )
ArcabitTrojan.Application.Keylogger.Spyrix.28
CyrenW32/Keylogger.AV.gen!Eldorado
ESET-NOD32a variant of Win32/KeyLogger.Spyrix.N
TrendMicro-HouseCallTROJ_GEN.R002H0CJC21
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:Monitor.Win32.Sprx.gen
AlibabaRiskWare:Win32/Spyrix.7634c015
NANO-AntivirusRiskware.Win32.Sprx.hjetby
ViRobotAdware.Sprx.1908896.BB
Ad-AwareGen:Variant.Application.Keylogger.Spyrix.28
EmsisoftGen:Variant.Application.Keylogger.Spyrix.28 (B)
DrWebProgram.Spyrix.10
VIPRETrojan.Win32.Generic!BT
SentinelOneStatic AI – Suspicious PE
SophosActual Keylogger (PUA)
APEXMalicious
JiangminMonitor.Sprx.w
AviraHEUR/AGEN.1145700
MAXmalware (ai score=79)
Antiy-AVLTrojan/Generic.ASMalwS.30447D8
MicrosoftPUA:Win32/SpyrixKeylogger
SUPERAntiSpywarePUP.SpyrixKeylogger/Variant
GDataGen:Variant.Application.Keylogger.Spyrix.28
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R429158
ALYacGen:Variant.Application.Keylogger.Spyrix.28
MalwarebytesMalware.AI.449758187
TencentTrojan.Win32.BitCoinMiner.la
YandexRiskware.Spyrix!StHzM+w39WY
IkarusPUA.Keylogger.Spyrix
FortinetW32/Keylogger.N!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]

How to remove PUA:Win32/SpyrixKeylogger?

PUA:Win32/SpyrixKeylogger removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment