Spy

Should I remove “Win32/Spy.KeyLogger.NLS”?

Malware Removal

The Win32/Spy.KeyLogger.NLS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.NLS virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Spy.KeyLogger.NLS?


File Info:

crc32: 0C86893A
md5: a134226882fd5349b513b3876c0e3bbd
name: A134226882FD5349B513B3876C0E3BBD.mlw
sha1: ed54769351a6e8bce5166e75d36e3ca21425e718
sha256: 09bcf8adcab26db1544e9881cf0f0858fe216c1c80d8f98fc3de25478c36775a
sha512: 5bdda31069afe747566304f5dac6153059e691b7695364802501170e1ace770784602fc1b5815205870f843d0b8dc2e788060e9b754c726d5f21eaba9eeb6774
ssdeep: 384:BVOX6H1jxakVWbiggB7GbhyLrUE5OPifOX6H1LhV:2X69xRVI+GMLJ5OlX6DV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
LegalCopyright: Copyright@ 2009-2010
InternalName: stub
FileVersion: 6.02.0008
CompanyName: Ati Tecknologie's
ProductName: AtiCnf
ProductVersion: 6.02.0008
FileDescription: Screen Utility
OriginalFilename: stub.dll

Win32/Spy.KeyLogger.NLS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00159cef1 )
LionicTrojan.Win32.Foreign.j!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.24757
CynetMalicious (score: 100)
CAT-QuickHealTrojan.ForeiMF.S10974049
ALYacGen:Variant.Razy.56598
CylanceUnsafe
SangforRansom.Win32.Foreign.8
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Foreign.d87e4d37
K7GWSpyware ( 00159cef1 )
Cybereasonmalicious.882fd5
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.KeyLogger.NLS
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-1848753
KasperskyTrojan-Ransom.Win32.Foreign.nbjp
BitDefenderGen:Variant.Razy.56598
NANO-AntivirusTrojan.Win32.Drop.ecbwch
MicroWorld-eScanGen:Variant.Razy.56598
TencentMalware.Win32.Gencirc.114bfd0f
Ad-AwareGen:Variant.Razy.56598
SophosML/PE-A + Mal/VB-NU
ComodoMalware@#3mfajwr2mwy8c
BitDefenderThetaAI:Packer.AD3559841F
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionGenericR-HKB!A134226882FD
FireEyeGeneric.mg.a134226882fd5349
EmsisoftGen:Variant.Razy.56598 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/VB.cqab
WebrootTrojan.Gen
AviraHEUR/AGEN.1125775
Antiy-AVLTrojan/Generic.ASMalwS.1860DE7
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
ArcabitTrojan.Razy.DDD16
GDataGen:Variant.Razy.56598
AhnLab-V3Trojan/Win32.VB.R8627
McAfeeGenericR-HKB!A134226882FD
MAXmalware (ai score=99)
VBA32Malware-Cryptor.VB.gen.1
PandaTrj/CI.A
YandexTrojan.Foreign!Qs8vRPUc9Zg
IkarusTrojan-Spy.Agent
FortinetW32/Generic.AC.817!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HgIASOcA

How to remove Win32/Spy.KeyLogger.NLS?

Win32/Spy.KeyLogger.NLS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment