Trojan

Trojan.MSIL.Keylogger.u information

Malware Removal

The Trojan.MSIL.Keylogger.u is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Keylogger.u virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Trojan.MSIL.Keylogger.u?


File Info:

name: 62E759993AF7BCCC7CBD.mlw
path: /opt/CAPEv2/storage/binaries/564a16d7f84b5b48654850a9c0c99f072f7876b7009ae7354774376423b36740
crc32: 0A5FB826
md5: 62e759993af7bccc7cbde48b793d41d5
sha1: 2101b0f51a3a1129ce936321c4c69e5d796c99f4
sha256: 564a16d7f84b5b48654850a9c0c99f072f7876b7009ae7354774376423b36740
sha512: 4fe3cc863c0776d4f0fdae5da7cdf5bf0d20966fe76e103b3cdaf91c29b0fae8d82fe79be3e950c5f2b61447cd1ca99d60c489e92f42d9ff441b9a2a2c47f29e
ssdeep: 12288:1h1Lk70Tnvjc0nvamPommsDLikQ2ifGC6XkRZ0hVUHt772cNj:hk70Trc03DI2ifJ60R7972cNj
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D8A4F12075C1C1B2C87B643485D5CA75AA36707207BAD6D7BAED1B7A6F103E0A3362CD
sha3_384: 24c59866d5cef749f7f6a67f207e828570ca95d0ada81d0b8d0155d5c5c85935abdea52bdd0437dd14ec62f76d739c7f
ep_bytes: e8e15c0000e9a4feffff8bff558bec83
timestamp: 2012-07-13 22:47:16

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Runtime Broker.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: Runtime Broker.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.MSIL.Keylogger.u also known as:

LionicTrojan.MSIL.Agent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.49211113
FireEyeGeneric.mg.62e759993af7bccc
ALYacTrojan.GenericKD.49211113
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/Keylogger.b4c3b179
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Generic.D2EEE6E9
tehtrisGeneric.Malware
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.MSIL.Keylogger.u
BitDefenderTrojan.GenericKD.49211113
Ad-AwareTrojan.GenericKD.49211113
EmsisoftTrojan.GenericKD.49211113 (B)
TrendMicroTROJ_GEN.R03BC0PFN22
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
Paloaltogeneric.ml
AviraTR/Keylogger.wkfya
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.49211113
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5177330
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R03BC0PFN22
RisingTrojan.Generic@AI.100 (RDML:4qoLbT2xXUsBdXpwEkuMIw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34742.Dq0@a0WlW!m
AVGWin32:Malware-gen
Cybereasonmalicious.93af7b

How to remove Trojan.MSIL.Keylogger.u?

Trojan.MSIL.Keylogger.u removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment