Spy

Win32/Spy.KeyLogger.RHS removal instruction

Malware Removal

The Win32/Spy.KeyLogger.RHS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.RHS virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Spy.KeyLogger.RHS?


File Info:

name: 84252999C2456146AC4C.mlw
path: /opt/CAPEv2/storage/binaries/6f02f5b8b276f94366f124db4ce345e98ae31fa850894fdce807f35d71d11c58
crc32: 4C6A89C2
md5: 84252999c2456146ac4cbfaea9e988c1
sha1: 0d26cb680f4d9ffafcee4974c254f07115a80c54
sha256: 6f02f5b8b276f94366f124db4ce345e98ae31fa850894fdce807f35d71d11c58
sha512: 4895cc9008e2a8982c7e6438e4c0be5767f08f582ab5fe4b2139503db770caea92ec39a1bd069adc2f47e3957d34b31fb6746a624928443f847eb643505629db
ssdeep: 384:rURiIm5VElUE6FstGYqsWUD7M1zKNPfgywn3lVu:IxyVEn6FCO71zKFIywVV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13492D072F749087BED3325F2152FA7197F751E044AB90B266924164F3DB40361F8BB48
sha3_384: 5d5557dc502a7f29a56fb4332f41ccdf6ce187af31f2d09b08035f351322942ea74d4a4a6f8e936d188cc2bd98a5d291
ep_bytes: 60be00d040008dbe0040ffff57eb0b90
timestamp: 2021-12-02 04:49:56

Version Info:

0: [No Data]

Win32/Spy.KeyLogger.RHS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47640161
FireEyeGeneric.mg.84252999c2456146
McAfeeRDN/Generic.dx
K7AntiVirusSpyware ( 0058bbba1 )
AlibabaTrojanSpy:Win32/KeyLogger.2d5a5c6a
K7GWSpyware ( 0058bbba1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.KeyLogger.RHS
TrendMicro-HouseCallTROJ_GEN.R002C0PLC21
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.47640161
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.47640161
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PLC21
McAfee-GW-EditionRDN/Generic.dx
EmsisoftTrojan.GenericKD.47640161 (B)
IkarusTrojan-Spy.Agent
AviraHEUR/AGEN.1202746
MAXmalware (ai score=87)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.47640161
CynetMalicious (score: 100)
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware

How to remove Win32/Spy.KeyLogger.RHS?

Win32/Spy.KeyLogger.RHS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment