Spy

About “Spyware.KeyLogger.UPX.Generic” infection

Malware Removal

The Spyware.KeyLogger.UPX.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.KeyLogger.UPX.Generic virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

www.wpopphRGiB.com
zipansion.com
aporasal.net

How to determine Spyware.KeyLogger.UPX.Generic?


File Info:

crc32: 566F4714
md5: b456e4719a05953acda6bf671c753d6c
name: B456E4719A05953ACDA6BF671C753D6C.mlw
sha1: 7b1e58737a953ee722cbe4cd0016f72635d04990
sha256: 296477b0ecb0df9250e122a477f4821391a730860feeb2887ec70b6c39d8cecc
sha512: 61dbaae425837672a845d4922a103794c4722780240a0d8996e32d71b84aa1d2bc505831f7c91e7edecd1b89ade0c26226be2874d03ac4d18b49694acf0098d3
ssdeep: 6144:zsq/jiZBfQiFq0pnys50qWGqBU9NmIJWz4aE3Vjc7ujBkTQHX6:zP/uZBVFq0Ryy0qRWA4Si4aEFjc7QHH
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Spyware.KeyLogger.UPX.Generic also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.TP.pmW@bK74DYm
FireEyeGeneric.mg.b456e4719a05953a
McAfeeGenericRXAA-AA!B456E4719A05
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Trojan.Heur.TP.pmW@bK74DYm
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.19a059
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqw4qbiQsViuDk/4svUdChv)
Ad-AwareGen:Trojan.Heur.TP.pmW@bK74DYm
EmsisoftGen:Trojan.Heur.TP.pmW@bK74DYm (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.ULPM.Gen
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Mal/TibsPak
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Heur.TP.E6FD59
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.TP.pmW@bK74DYm
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R363534
BitDefenderThetaAI:Packer.2BC3B6C31E
ALYacGen:Trojan.Heur.TP.pmW@bK74DYm
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.KeyLogger.UPX.Generic
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallPAK_Xed-10
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FFP!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360HEUR/QVM19.1.0B1B.Malware.Gen

How to remove Spyware.KeyLogger.UPX.Generic?

Spyware.KeyLogger.UPX.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment