Spy

Win32/Spy.KeyLogger.RHP removal guide

Malware Removal

The Win32/Spy.KeyLogger.RHP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.RHP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

wpad.local-net

How to determine Win32/Spy.KeyLogger.RHP?


File Info:

name: 4033EBD9255133EBF885.mlw
path: /opt/CAPEv2/storage/binaries/164d7e79cb9c455d9c7ca9e313cd5b9b553fc88f49a5c3f0b3871dd99783c183
crc32: FF5C9513
md5: 4033ebd9255133ebf885bc9b5967c58e
sha1: 2b53ec2fdd05df0717743dca47aad5d32c916698
sha256: 164d7e79cb9c455d9c7ca9e313cd5b9b553fc88f49a5c3f0b3871dd99783c183
sha512: 4c998760d7cf5cf36b8d081c6bc061a9a8e44b2d59aa0c9ee412495e8b1926d475fa904e2d2700c62bd349d9020dda4f2464548b73365ab5ea92725ac1f5b67d
ssdeep: 6144:BrWVjLH+hSyBL106ckp3Y5Z4t46Vcb16fl+37AyFjXNTD3Ll:BrWVuhSy/7cRfQVSZMyh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164347C313606C436D5A101F568E8EBFA9158AD358BB605C3B3D85FBDD9201E32932F6B
sha3_384: cae186f89060ff4ad990ea0e03479252e3415793ce205179f92093dd7b7b90096ceaccc18c89443eba164e4ae9c11e68
ep_bytes: e8ea050000e97afeffff558bec6a00ff
timestamp: 2021-11-18 07:29:47

Version Info:

0: [No Data]

Win32/Spy.KeyLogger.RHP also known as:

LionicTrojan.Win32.KeyLogger.4!c
MicroWorld-eScanTrojan.GenericKD.38093363
FireEyeTrojan.GenericKD.38093363
ALYacTrojan.GenericKD.38093363
AlibabaTrojanSpy:Win32/KeyLogger.ba334d3a
SymantecBackdoor.Trojan
ESET-NOD32a variant of Win32/Spy.KeyLogger.RHP
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.KeyLogger.gen
BitDefenderTrojan.GenericKD.38093363
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.38093363
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.dcnqe
DrWebTrojan.MulDrop19.3950
McAfee-GW-EditionBehavesLike.Win32.BadFile.dh
EmsisoftTrojan.GenericKD.38093363 (B)
GDataWin32.Trojan.Agent.LEDPHL
AviraTR/Redcap.dcnqe
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2454233
ViRobotTrojan.Win32.Z.Keylogger.232448
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!4033EBD92551
MAXmalware (ai score=87)
VBA32BScope.Trojan.Malex
TrendMicro-HouseCallTROJ_GEN.R002H0CKM21
YandexTrojan.KeyLogger!rsNSzlmvi0Y
IkarusTrojan-Spy.Agent
FortinetMalicious_Behavior.SB
WebrootW32.Trojan.Dropper
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A

How to remove Win32/Spy.KeyLogger.RHP?

Win32/Spy.KeyLogger.RHP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment