Malware

Application.Keylogger.QQJ information

Malware Removal

The Application.Keylogger.QQJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Keylogger.QQJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Uses IOCTL_SCSI_PASS_THROUGH control codes to manipulate drive/MBR which may be indicative of a bootkit
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempted to write directly to a physical drive

How to determine Application.Keylogger.QQJ?


File Info:

name: C027CE33C293F925324B.mlw
path: /opt/CAPEv2/storage/binaries/a4ffe3da00780acc018da4527fc5277338bb4a33516f27683dd2bed9f04fb488
crc32: 168C8110
md5: c027ce33c293f925324ba5477031e937
sha1: ec72fa870f36ab95b3a0f8c82544c6d4cdd500e3
sha256: a4ffe3da00780acc018da4527fc5277338bb4a33516f27683dd2bed9f04fb488
sha512: 45236458b9dac4dbc4d371a7900bc4c8a51579cee5f912e685594f34c1746b333fe4477178a89ba9428431469c33d5663c379d5e66a43c4c3c3146acd4a1b23b
ssdeep: 49152:n98AdahIsbjHs6xdl4QmUT/rKpJVE6E8EL+0oHmM8pYIycLdnxsqq:98Adqs6xqUfKhEttL+07JpGsbsqq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3A533596B836679F0819634AFD4C43496323C954A7AA0373BDD0BBC9F7A3D5E40A383
sha3_384: 24e0b4d0ab204d5b60edd53668ee6a32578ace2a6d6cc2d0591fbeacaee1db160b0e376033ff9221f848c16a64fbaa42
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Actual Keylogger Setup
FileVersion: 3.2
LegalCopyright: Copyright © 2005-2016 Actual Keylogger. All rights reserved.
ProductName: Actual Keylogger
ProductVersion: 3.2
Translation: 0x0000 0x04b0

Application.Keylogger.QQJ also known as:

LionicRiskware.Win32.Generic.1!c
DrWebProgram.ActualSpy.4
MicroWorld-eScanApplication.Keylogger.QQJ
FireEyeApplication.Keylogger.QQJ
McAfeeArtemis!C027CE33C293
CylanceUnsafe
SangforTrojan.Win32.Bitrep.A
K7AntiVirusPassword-Stealer ( 0055dec41 )
AlibabaRiskWare:Win32/ActualSpy.004a3bca
K7GWPassword-Stealer ( 0055dec41 )
CrowdStrikewin/grayware_confidence_60% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
TrendMicro-HouseCallSPYW_KEYLOG
Paloaltogeneric.ml
Kasperskynot-a-virus:UDS:Monitor.Win32.Generic
BitDefenderApplication.Keylogger.QQJ
AvastWin32:ActualSpy-Q [PUP]
TencentWin32.Trojan.Generic.Sudj
SophosActual Keylogger (PUA)
ComodoMalware@#1uj4pojiwtpvw
VIPRETrojan.Win32.Generic!BT
TrendMicroSPYW_KEYLOG
EmsisoftApplication.Keylogger.QQJ (B)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataApplication.Keylogger.QQJ
ALYacApplication.Keylogger.QQJ
MAXmalware (ai score=82)
VBA32BScope.Adware.Presenoker
MalwarebytesRiskWare.ActualKeyLogger
APEXMalicious
RisingMalware.Undefined!8.C (CLOUD)
MaxSecureTrojan.Malware.74282127.susgen
FortinetRiskware/Generic
AVGWin32:ActualSpy-Q [PUP]
Cybereasonmalicious.3c293f
PandaTrj/CI.A

How to remove Application.Keylogger.QQJ?

Application.Keylogger.QQJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment