Spy Trojan

How to remove “Trojan-Spy.Win32.KeyLogger.bkvs”?

Malware Removal

The Trojan-Spy.Win32.KeyLogger.bkvs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.KeyLogger.bkvs virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Spy.Win32.KeyLogger.bkvs?


File Info:

name: D19B688F73F5BA6BAD78.mlw
path: /opt/CAPEv2/storage/binaries/0d01466d01e26b5310f1ae6132ef8c1ea031d3262bde3d3e3721863ad5e62209
crc32: 59EDF0C2
md5: d19b688f73f5ba6bad78cf4444f26840
sha1: dacf6de4d5b2fcc7f49f4df08bdc0064a4d61d8d
sha256: 0d01466d01e26b5310f1ae6132ef8c1ea031d3262bde3d3e3721863ad5e62209
sha512: 51d7cde007d9e9c748953845cce35fe864b21d2274c586930444176b4cd3b5ac9c6100106630040f6ebca3f8784d52c61360a99555f29ea84caf6f6af43236c2
ssdeep: 12288:G3BGaAogwvah1D5JlO0AWbQXsHmu8sf1rCZIpnlkJ4XTHAyxO9N/L4FJPY5wwi4z:GG/AM5lBuIpi5cOrcFPwBV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B252335A530F634E1564D79EA63A39092DF4D6018C8EEA31FFC7F8F74752808AE9642
sha3_384: 12feb6180ead19bd6b3409e42b45f445693bf326c192f7ceee7c17b4e74bfe8f818ea68c6c7bd0397e3e1fcc74a577af
ep_bytes: 60be00b07c008dbe0060c3ff5783cdff
timestamp: 2014-03-17 10:26:18

Version Info:

FileVersion: 1.0.1.0
FileDescription: VPN金牌代理 Setup
ProductName: 西西VPN金牌代理 Setup
ProductVersion: 1.0.1.0
CompanyName: 西西工作室
LegalCopyright: 西西工作室 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan-Spy.Win32.KeyLogger.bkvs also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
FireEyeGeneric.mg.d19b688f73f5ba6b
CAT-QuickHealRisktool.Flystudio.16886
MalwarebytesMalware.Heuristic.1003
SangforVirus.Win32.Save.a
AlibabaTrojanSpy:Win32/KeyLogger.06e25567
CyrenW32/S-6b93e35e!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Zusy-6717397-0
KasperskyTrojan-Spy.Win32.KeyLogger.bkvs
AvastWin32:Malware-gen
F-SecureTrojan.TR/Spy.KeyLogger.kuque
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan-Dropper.Agent
GDataWin32.Trojan.PSE.10S0A6W
GoogleDetected
AviraTR/Spy.KeyLogger.kuque
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ZoneAlarmTrojan-Spy.Win32.KeyLogger.bkvs
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
McAfeeArtemis!D19B688F73F5
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.ELang!1.64ED (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4d5b2f
DeepInstinctMALICIOUS

How to remove Trojan-Spy.Win32.KeyLogger.bkvs?

Trojan-Spy.Win32.KeyLogger.bkvs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment