Spy

What is “Spyware.Keydoor”?

Malware Removal

The Spyware.Keydoor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Keydoor virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Spyware.Keydoor?


File Info:

name: CC63F27CADD6DF9FA666.mlw
path: /opt/CAPEv2/storage/binaries/ec3f9ab49cfb788101f7c16e09115ad732169338f9e278743cc26174f4326541
crc32: A36F2C2D
md5: cc63f27cadd6df9fa6666b5c700023d2
sha1: ed27906dc370178eb18402b634ce5140a8dfe545
sha256: ec3f9ab49cfb788101f7c16e09115ad732169338f9e278743cc26174f4326541
sha512: dbb6341b69e372f70a62d8e589c978427d9a0f003bb49c82b91a075186a46b30e01b475ee27649832d26fcfa6fdcbcc2381fc8d071f8a73a51fc7898db5c0eef
ssdeep: 1536:IE3qz4ayX9ioT5Xl8lQWj1vTo5G6kvBzodfjZw4jk5tGwts1d:179l86WqGzIfjZwik5tE1d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1A38D11B881C573C04A95711499E7B2AB3DF9316A79A583F38D0FBA5FB02D0663E387
sha3_384: 2bcfa9477c3abfb857e6220d1a3f0e6a99b2e9b3bba55fca970ab1686177d9e7085f4657dc04471ad0dcf5a9502dcb7c
ep_bytes: e8ea650000e978feffff8bff558bec51
timestamp: 2012-07-26 18:49:30

Version Info:

0: [No Data]

Spyware.Keydoor also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.37920560
FireEyeGeneric.mg.cc63f27cadd6df9f
CAT-QuickHealTrojan.Dynamer.8881
McAfeeGenericRXEO-DF!CC63F27CADD6
CylanceUnsafe
ZillyaTrojan.Katusha.Win32.38343
SangforWorm.Win32.Save.a
K7AntiVirusTrojan ( 004c47121 )
K7GWTrojan ( 004c47121 )
Cybereasonmalicious.cadd6d
ArcabitTrojan.Generic.D2429F30
BitDefenderThetaAI:Packer.DD3671A21F
CyrenW32/S-0ee6d6bf!Eldorado
SymantecBackdoor.Waketagat
ESET-NOD32Win32/Spy.Keydoor.AD
BaiduWin32.Trojan.Agent.avd
TrendMicro-HouseCallTSPY_HPURSNIF.SM1
ClamAVWin.Malware.Scar-9776391-0
KasperskyTrojan.Win32.Scar.ojnn
BitDefenderTrojan.GenericKD.37920560
NANO-AntivirusTrojan.Win32.TrjGen.drufdw
AvastWin32:BackDoor-AFV [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKD.37920560
EmsisoftTrojan.GenericKD.37920560 (B)
ComodoTrojWare.Win32.Agent.XYZ@6l9auh
F-SecureTrojan.TR/Agent.106509
DrWebTrojan.Siggen6.34441
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosML/PE-A + Troj/Scar-CV
APEXMalicious
JiangminTrojan/Generic.beovz
MaxSecureTrojan.Scar.OETR
AviraTR/Agent.106509
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.1039187
MicrosoftBackdoor:Win32/Rifdoor.B!bit
ViRobotBackdoor.Win32.Agent.106526
GDataWin32.Trojan-Spy.Ursnif.K
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bmbot.C792257
Acronissuspicious
VBA32Trojan.Scar
ALYacTrojan.Agent.Spear16F1
MalwarebytesSpyware.Keydoor
IkarusTrojan.Win32.Agent
RisingSpyware.Keydoor!1.B6A0 (CLASSIC)
YandexTrojan.Agent!v5BuXtqGM7w
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.XFS!tr
AVGWin32:BackDoor-AFV [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Spyware.Keydoor?

Spyware.Keydoor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment