Gridinsoft Logo

Client-built_protected.exe Stealer Keylogger Analysis

Stealer Keylogger
Updated on 2024-06-06 (4 months ago)
Checked by Online Virus Scanner
Online Virus Checker v.1.0.178.174
DB Version: 2024-06-06 11:00:43

Spy.Win32.Keylogger.dd!n

Keylogger is designed to secretly record keystrokes on a computer or mobile device, capturing everything a user types, including sensitive information like passwords and credit card numbers. It can be used by cybercriminals to steal personal and confidential data without the user's knowledge or consent.

File Client-built_protected.exe
Checked 2024-06-06 08:30:54
MD5 3698cbad0b7519be7e082a22dc5f2b49
SHA1 2b24597d6e7ad9c233d158c990611eedb0917a76
SHA256 bd0ac7deb5974dc367e9f651eac20557ada9d3da266518a097595ab079f63907
SHA512 f770f4bedb8a6a8b9a84ba0c13e0f81a2694f57c1aeb15c15b7d2e7384849a2a561b0a06ae7f1f156721b15fcebdd51140eb951f1b67765c7b08f44f3bf51ec5
Imphash 2e5467cba76f44a088d39f78c5e807b6
File Size 2580480 bytes

Spy.Win32.Keylogger.dd!n Removal

Spy.Win32.Keylogger.dd!n Removal

Gridinsoft has the capability to identify and eliminate Spy.Win32.Keylogger.dd!n without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation 0x0000 0x04b0
Comments
CompanyName
FileDescription Quasar Client
FileVersion 1.4.1
InternalName Client.exe
LegalCopyright Copyright © MaxXor 2023
LegalTrademarks
OriginalFilename Client.exe
ProductName Quasar
ProductVersion 1.4.1
Assembly Version 1.4.1.0

Portable Executable Info

cbb20a5708405155b587a60e15b1c8e2
964526c29875eddef1c6c3a557a78f4c
554932926d6d5545
Image Base: 0x00400000
Entry Point: 0x0042dd34
Compilation: 2023-03-12 16:16:39
Checksum: 0x00000000 (Actual: 0x0027f3ce)
OS Version: 4.0
PEiD: PE32 executable (GUI) Intel 80386, for MS Windows
Sign: The PE file does not contain a certificate table.
Sections: 6
Imports: kernel32, user32, advapi32, oleaut32, gdi32, shell32, version, mscoree,
Exports: 0
Resources: 4

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
0x00002000 0x0031e000 0x0012a400 f5550cd8fbc31b9167bb89384cec21ef 8.00
0x00320000 0x0003e000 0x00000200 c3aa48df900c2f715902743b535b7220 0.67
0x0035e000 0x00002000 0x00000200 df9b02d12a7937ba0ca301a4b29e0e71 0.30
.rsrc 0x00360000 0x0003e000 0x0003ce00 20968fa609ad33138d59a5536aeafb3d 2.82
0x0039e000 0x00280000 0x0002ba00 82ec1d2bda6e2a480cb1c93825dec53a 8.00
.data 0x0061e000 0x000e4000 0x000e2c00 308984a82eb93bb1f6c23b94c44b3018 7.98

Leave a comment *

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware