Spy

Win32/Spy.KeyLogger.QQI information

Malware Removal

The Win32/Spy.KeyLogger.QQI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.QQI virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Spy.KeyLogger.QQI?


File Info:

name: 459C89A2E2880B72BE37.mlw
path: /opt/CAPEv2/storage/binaries/fd283d9c2c12cba05949d5a8e3d898e03afd31d53ee660cff51958508a5486e2
crc32: FC4FDB72
md5: 459c89a2e2880b72be3789c4ebca0031
sha1: 57145303afe0c3891d2c9de7b137dca75f39407e
sha256: fd283d9c2c12cba05949d5a8e3d898e03afd31d53ee660cff51958508a5486e2
sha512: 569cf003db910673509c7d029cc994cb6be7228f490b5ce9954f796e7c310bdeeee635d0b971417e5682021c248e4da1eaa312fba906285b2a649265c2a47aea
ssdeep: 12288:izcmEnv2QHTZFajhAmgoS+swM5rWcFtZ7tfo55:izcmIFFrmi5rWc1dk5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C84238591260EA1E5C343716E7E146B31A4F2BCB4C897C78ED8EBC699E79049E4C70F
sha3_384: e4de5e03768fc0b54197b4fc8948beb1e09b57ca5d726aae4b8618269340dac1c1443f384da277a549741b017a62cf91
ep_bytes: 60be00f043008dbe0020fcff5789e58d
timestamp: 2008-03-09 15:12:03

Version Info:

CompanyName: Intel
FileDescription:
FileVersion: 0.0.0.0
InternalName:
LegalCopyright:
OriginalFilename:
ProductName:
ProductVersion: 0.0.0.0
Translation: 0x0809 0x04b0

Win32/Spy.KeyLogger.QQI also known as:

CynetMalicious (score: 100)
FireEyeTrojan.GenericKD.41275937
McAfeeArtemis!459C89A2E288
CylanceUnsafe
VIPRETrojan.GenericKD.41275937
AlibabaTrojanSpy:Win32/Skeeyah.dcd8304c
Cybereasonmalicious.2e2880
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Spy.KeyLogger.QQI
APEXMalicious
KasperskyTrojan-Spy.Win32.Agent.jtws
BitDefenderTrojan.GenericKD.41275937
NANO-AntivirusTrojan.Win32.KeyLogger.fqqega
MicroWorld-eScanTrojan.GenericKD.41275937
AvastOther:Malware-gen [Trj]
Ad-AwareTrojan.GenericKD.41275937
EmsisoftTrojan.GenericKD.41275937 (B)
F-SecureTrojan.TR/Spy.KeyLogger.gnjzq
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
GDataTrojan.GenericKD.41275937 (2x)
AviraTR/Spy.KeyLogger.gnjzq
ZoneAlarmTrojan-Spy.Win32.Agent.jtws
MicrosoftTrojan:Win32/Skeeyah.A!MTB
GoogleDetected
ALYacTrojan.GenericKD.41275937
VBA32TrojanSpy.Agent
MalwarebytesMalware.Heuristic.1003
TencentWin32.Trojan-spy.Agent.Pdcu
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KeyLogger.QQI!tr.spy
AVGOther:Malware-gen [Trj]
PandaTrj/GdSda.A

How to remove Win32/Spy.KeyLogger.QQI?

Win32/Spy.KeyLogger.QQI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment