Trojan

Trojan:MSIL/Keylogger.DA!MTB (file analysis)

Malware Removal

The Trojan:MSIL/Keylogger.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Keylogger.DA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Anomalous binary characteristics

How to determine Trojan:MSIL/Keylogger.DA!MTB?


File Info:

crc32: 43BE6A05
md5: af64d8a19657dbaff868618bd814003a
name: AF64D8A19657DBAFF868618BD814003A.mlw
sha1: dfa4b37e6591c736e5920fd265f246ce1b128d79
sha256: c8fcd5bd2114de2bb20a7ff82b93c566f90fe0c96267c1cc9d517273b33a687b
sha512: ea11d23d0ff75c575f992b2e84ddee242b4bbe9dd2f048f7e103159607f723fe7af740b2bd917187ee4998b80e491a9e72a1c0e7564b66df7dc60bca617bb796
ssdeep: 96:H0razdYo3snNgsirgdLynI3kLVe22Mzc1+6PIYm/tdmkb6V3xOiu7USZcPzNt:UfNgZrOwl022K8nQTdmZxKy
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 HP Inc. 2018
Assembly Version: 1.0.0.0
InternalName: C.PrivateStubWinForm.exe
FileVersion: 1.0.0.0
CompanyName: HP Inc.
LegalTrademarks:
Comments:
ProductName: C.PrivateStubWinForm
ProductVersion: 1.0.0.0
FileDescription: C.PrivateStubWinForm
OriginalFilename: C.PrivateStubWinForm.exe

Trojan:MSIL/Keylogger.DA!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.148
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.377374
SangforTrojan.Win32.Save.a
Cybereasonmalicious.19657d
CyrenW32/Ursu.FA.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.REN
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
ClamAVWin.Packed.Score-6905873-0
KasperskyHEUR:Trojan.MSIL.Disfa.gen
BitDefenderGen:Variant.Ursu.377374
MicroWorld-eScanGen:Variant.Ursu.377374
Ad-AwareGen:Variant.Ursu.377374
F-SecureTrojan.TR/Dropper.MSIL.Gen
BitDefenderThetaGen:NN.ZemsilF.34678.am0@aSHhocg
McAfee-GW-EditionGenericRXHG-EO!AF64D8A19657
FireEyeGeneric.mg.af64d8a19657dbaf
EmsisoftGen:Variant.Ursu.377374 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:MSIL/Keylogger.DA!MTB
ArcabitTrojan.Ursu.D5C21E
GDataGen:Variant.Ursu.377374
AhnLab-V3Trojan/Win32.Disfa.C3270649
McAfeeGenericRXHG-EO!AF64D8A19657
MAXmalware (ai score=80)
MalwarebytesBackdoor.Quasar
RisingBackdoor.Bladabindi!8.B1F (TFE:dGZlOgzLuhG2qJyy4Q)
FortinetMSIL/Kryptik.KTL!tr
AVGWin32:KeyloggerX-gen [Trj]

How to remove Trojan:MSIL/Keylogger.DA!MTB?

Trojan:MSIL/Keylogger.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment