Spy Trojan

Trojan-Spy.Win32.KeyLogger.bqec (file analysis)

Malware Removal

The Trojan-Spy.Win32.KeyLogger.bqec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.KeyLogger.bqec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Spy.Win32.KeyLogger.bqec?


File Info:

name: B117AD89AE0FE64DA5A5.mlw
path: /opt/CAPEv2/storage/binaries/b2e2623b5ba411586f0e1a36eb69d4ff9a85a082b90a5a278245062c962e1b02
crc32: 4550D128
md5: b117ad89ae0fe64da5a5b2f7345f3ea8
sha1: 36edf0c26d697fce0ec59f2da2df084afbf9a393
sha256: b2e2623b5ba411586f0e1a36eb69d4ff9a85a082b90a5a278245062c962e1b02
sha512: 632196be9a9622c7828cb879583ef3c0417ac31c4e36940eabf13b45f4669d9930ae172a45c8d874d8cbc1f6b4c3aa943fdfe494c21d4e803a263054471f1de3
ssdeep: 12288:ZRr85t/VFS4RwstHUaevv092fH7x7cE7zWZcszOJxxsNaejb4yIxDdv:Xr85t/hWv892fH7xgE/yZzOB/ejbU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DE4129BC5A44228D37D0A307BDEE58328F2786564E63B495DC4E12BA73324DAF47E13
sha3_384: aed6cc823f9d337a9a8c4d1bba8069ce95848a1cb8e9e5f97124e6aa30a8a129ca248a43de6512f1f262943e9c96ab2c
ep_bytes: 60be006055008dbe00b0eaff57eb0b90
timestamp: 2019-11-10 18:13:41

Version Info:

0: [No Data]

Trojan-Spy.Win32.KeyLogger.bqec also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lpKS
Elasticmalicious (moderate confidence)
ClamAVWin.Malware.Generic-9820446-0
FireEyeGeneric.mg.b117ad89ae0fe64d
MalwarebytesMalware.Heuristic.1003
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojanSpy:Win32/KeyLogger.fdf51c87
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.9ae0fe
BitDefenderThetaGen:NN.ZexaF.36196.PmGfaaCh8knb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.KeyLogger.bqec
NANO-AntivirusTrojan.Win32.KeyLogger.hdraft
AvastWin32:Malware-gen
F-SecureHeuristic.HEUR/AGEN.1335467
ZillyaTrojan.Keylogger.Win32.65969
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10248TU
AviraHEUR/AGEN.1335467
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
ZoneAlarmTrojan-Spy.Win32.KeyLogger.bqec
MicrosoftTrojan:Win32/Occamy.CB2
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2115913
McAfeeArtemis!B117AD89AE0F
VBA32BScope.Trojan.Tiggre
Cylanceunsafe
PandaTrj/GdSda.A
RisingSpyware.KeyLogger!8.12F (CLOUD)
IkarusPUA.FlyStudio
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Trojan-Spy.Win32.KeyLogger.bqec?

Trojan-Spy.Win32.KeyLogger.bqec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment