Spy

How to remove “Win32/Spy.KeyLogger.QHL”?

Malware Removal

The Win32/Spy.KeyLogger.QHL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.QHL virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Win32/Spy.KeyLogger.QHL?


File Info:

name: 9632BFD736696189ED1D.mlw
path: /opt/CAPEv2/storage/binaries/22e7eedac0465a0120b2d009fb7632c614da77a0f2fc729db7f1b935015f984f
crc32: 05DCBE97
md5: 9632bfd736696189ed1da3e61657fa92
sha1: e1f6f6628cb8bebf1bcc5f84793ba5c3b0860982
sha256: 22e7eedac0465a0120b2d009fb7632c614da77a0f2fc729db7f1b935015f984f
sha512: bf7027780527520703064d711fafa5af533a9d899face937ece8b500fb56744d09631cee3d7e21557012aa86ef89a0b6201b95249ff5d6e5b131a8e3a869175d
ssdeep: 96:bdlTm+1/4fY+SjaBVqC52rI3u7cdsJjV866a2JeJ78jHzpgzGjwCihHx6H:R1QolrI+7osJj2JeJ78DlgzMwCi
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T173021A0794100417DBB191F981FB0A3F957DAA73336972D32AB739D2AB779C2A835183
sha3_384: 50555b44ee6c8fc88fc037af272672a8ed95506e371c6f8814d2d729790c70f9a1f00bafa2f479fecb70df71ce0430c5
ep_bytes: 558bece888090000e8c3070000ff157c
timestamp: 2018-08-05 03:41:05

Version Info:

0: [No Data]

Win32/Spy.KeyLogger.QHL also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.Katusha.x!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.SD!dld!g.5CC619FA
FireEyeGeneric.mg.9632bfd736696189
ALYacGeneric.Malware.SD!dld!g.5CC619FA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaPacked:Win32/Katusha.3eb40015
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.736696
CyrenW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.KeyLogger.QHL
APEXMalicious
Paloaltogeneric.ml
KasperskyPacked.Win32.Katusha.o
BitDefenderGeneric.Malware.SD!dld!g.5CC619FA
NANO-AntivirusTrojan.Win32.Katusha.fgggni
AvastWin32:Malware-gen
TencentWin32.Packed.Katusha.Hryg
Ad-AwareGeneric.Malware.SD!dld!g.5CC619FA
EmsisoftGeneric.Malware.SD!dld!g.5CC619FA (B)
ComodoMalware@#8jg850gmoax8
TrendMicroTROJ_GEN.R002C0GKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.xm
SophosGeneric PUA OB (PUA)
IkarusTrojan-Spy.Agent
GDataGeneric.Malware.SD!dld!g.5CC619FA
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.2737E03
MicrosoftTrojan:Win32/Occamy.C22
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!9632BFD73669
VBA32Trojan.Hide.Heur
MalwarebytesSpyware.KeyLogger
TrendMicro-HouseCallTROJ_GEN.R002C0GKN21
YandexTrojan.GenAsa!5XMrY8OHfHc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Katusha.O!tr.spy
BitDefenderThetaGen:NN.ZexaF.34084.auW@aONuaUni
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Spy.KeyLogger.QHL?

Win32/Spy.KeyLogger.QHL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment