Spy Trojan

Should I remove “UDS:Trojan-Spy.MSIL.KeyLogger.sb”?

Malware Removal

The UDS:Trojan-Spy.MSIL.KeyLogger.sb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.MSIL.KeyLogger.sb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Checks for the presence of known windows from debuggers and forensic tools
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
tankionline.com
a.tomx.xyz
relax.no-ip.info

How to determine UDS:Trojan-Spy.MSIL.KeyLogger.sb?


File Info:

crc32: 027C78F4
md5: d0a3e022238da36781ff1d59180bb62d
name: D0A3E022238DA36781FF1D59180BB62D.mlw
sha1: 0796cf4dd0c305d991184c7b456b9219fe6fca99
sha256: be11b8a494a0d8f07ec0889113401abf1921ea089f3049015a06d9be6de4434e
sha512: 4e26eed51f4a84d48f901536c466224fe6d8e2bcb84be6123231d7c7fcef4a556b94f13b7771b4499076d726d59d23517b0e97dd1eb06bf3858b3f73e83de47f
ssdeep: 24576:dJIP5U9TOVmY+mK2B2MFZ0NZNMWm2i/v3xZAVg5/NuLWUs00Pa1kNqMcjs:/IBgqI2BXFZiZNRm2i/I0Nou0aqM5
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

UDS:Trojan-Spy.MSIL.KeyLogger.sb also known as:

LionicTrojan.Win32.Generic.4!c
ALYacTrojan.GenericKD.2141410
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 004bd6f41 )
K7AntiVirusTrojan ( 004bd6f41 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.Q
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyUDS:Trojan-Spy.MSIL.KeyLogger.sb
BitDefenderTrojan.GenericKD.2141410
NANO-AntivirusTrojan.Win32.Bladabindi.dnmuui
MicroWorld-eScanTrojan.GenericKD.2141410
TencentWin32.Trojan.Spy.Wqcp
Ad-AwareTrojan.GenericKD.2141410
F-SecureHeuristic.HEUR/AGEN.1112157
BitDefenderThetaGen:NN.ZexaF.34170.WqW@aqkg0rk
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.d0a3e022238da367
EmsisoftTrojan.GenericKD.2141410 (B)
AviraHEUR/AGEN.1112157
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D20ACE2
GDataTrojan.GenericKD.2141410
McAfeeArtemis!D0A3E022238D
MAXmalware (ai score=100)
PandaTrj/CI.A
RisingTrojan.Generic@ML.93 (RDML:Wru1tHq2qwUitg/is1rZuQ)
YandexTrojan.Agent!OFML8TzbfZ4
IkarusBackdoor.MSIL.Bladabindi
FortinetW32/Generic.Q!tr
AVGWin32:Malware-gen

How to remove UDS:Trojan-Spy.MSIL.KeyLogger.sb?

UDS:Trojan-Spy.MSIL.KeyLogger.sb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment