Spy

Spyware:PowerShell/Keylogger.G!MTB removal guide

Malware Removal

The Spyware:PowerShell/Keylogger.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware:PowerShell/Keylogger.G!MTB virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipapi.co
ocsp.digicert.com

How to determine Spyware:PowerShell/Keylogger.G!MTB?


File Info:

crc32: B550EC4F
md5: 0e38a6bb062873822593284b615f8142
name: 0E38A6BB062873822593284B615F8142.mlw
sha1: 33f8df4dc055bda16fe17574a4105645f13eb6ab
sha256: f5ed9dec87b0878010a0378f4295d233fc12fa23bd196c495904b8402dad9944
sha512: 7476f9623ad3d2ef034932a99f9f307e1653b4c9b3549c47d3927a9e76643fbc05f2acfa91d71f1f78bac454c5e526b609d216a9b3dbed2b5c77bef828a8cbdf
ssdeep: 24576:ZRmJkcoQricOIQxiZY1iax18JWQhDnG9sNCqf+Sxp/14:2JZoQrbTFZY1iaxigQ5n4Mf+Kd4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Spyware:PowerShell/Keylogger.G!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Malware.PVoPk!3g.CF6B5940
FireEyeGeneric.mg.0e38a6bb06287382
CAT-QuickHealTrojan.Script
ALYacDeepScan:Generic.Malware.PVoPk!3g.CF6B5940
CylanceUnsafe
AegisLabTrojan.Script.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056e5201 )
BitDefenderDeepScan:Generic.Malware.PVoPk!3g.CF6B5940
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.b06287
BitDefenderThetaAI:Packer.7492DFF116
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Script.Generic
AlibabaTrojan:Win32/Injector.c64e13c1
ViRobotTrojan.Win32.Z.Autoit.1201484
TencentWin32.Trojan.Generic.Gls
Ad-AwareDeepScan:Generic.Malware.PVoPk!3g.CF6B5940
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1105622
DrWebTrojan.AutoIt.577
TrendMicroTROJ_GEN.R002C0DAV21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftDeepScan:Generic.Malware.PVoPk!3g.CF6B5940 (B)
IkarusTrojan.Autoit
AviraHEUR/AGEN.1110309
MicrosoftSpyware:PowerShell/Keylogger.G!MTB
ArcabitDeepScan:Generic.Malware.PVoPk!3g.CF6B5940
SUPERAntiSpywareTrojan.Agent/Gen-Undef
ZoneAlarmHEUR:Trojan.Script.Generic
GDataDeepScan:Generic.Malware.PVoPk!3g.CF6B5940
CynetMalicious (score: 100)
McAfeeArtemis!0E38A6BB0628
MAXmalware (ai score=83)
VBA32Trojan-Downloader.Autoit.gen
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0DAV21
RisingBackdoor.888Rat/Autoit!1.C8E3 (CLASSIC)
eGambitUnsafe.AI_Score_90%
FortinetW32/Autoit.CW!tr
AVGAutoIt:Injector-IM [Trj]
AvastAutoIt:Injector-IM [Trj]
Qihoo-360Win32/Worm.AutoIt.HwoCAm8A

How to remove Spyware:PowerShell/Keylogger.G!MTB?

Spyware:PowerShell/Keylogger.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment