Spy

Should I remove “Win32/Spy.KeyLogger.QWV”?

Malware Removal

The Win32/Spy.KeyLogger.QWV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.KeyLogger.QWV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Win32/Spy.KeyLogger.QWV?


File Info:

name: E6344546FC64041230F7.mlw
path: /opt/CAPEv2/storage/binaries/6f7c63ba5bb0264988ae424c13b8e4e46d31a05ffbd1a689a9ae7baeff92ddc0
crc32: 560DEBAE
md5: e6344546fc64041230f7f43e3bb4a6a8
sha1: 3d4cf48043070b5c7c54802ff5d3097a6a23ae23
sha256: 6f7c63ba5bb0264988ae424c13b8e4e46d31a05ffbd1a689a9ae7baeff92ddc0
sha512: d6e7421011b4eadedc454f0ce6bc1dff07a7770ad1848e690788cb9f2962413c964c3b7d3c6dfef47e91d1d5efe03ae1aac82ebe613d7ea1447ea4cacc712077
ssdeep: 6144:uz703IHpTFkZYBuYpq8t6QQ7REJ/xKwv+knGL4lb63VFA/+ppT2S3:M0epRkdpv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6F40C516C2081C1F4CB22749816A5B8491DACD7FFE1B71AE7D47E0B76B2AF90422E37
sha3_384: 015df7b8b8f62016737dbb49c431e0eb37ee9458f6d4135a092e6e206170de5ff4c9ccf3068aabb3b140b4347ae572b7
ep_bytes: 68dc224600e8eeffffff000000000000
timestamp: 2019-11-24 11:37:41

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Cyber Indonesia
ProductName: Project1k
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Project KLOG
OriginalFilename: Project KLOG.exe

Win32/Spy.KeyLogger.QWV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Graftor.2894
FireEyeGen:Variant.Graftor.2894
SkyhighBehavesLike.Win32.Infected.bz
ALYacGen:Variant.Graftor.2894
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.KeyLogger.sgcns
K7AntiVirusSpyware ( 005146d81 )
AlibabaTrojanSpy:Win32/Xegumumune.d694ccc4
K7GWSpyware ( 005146d81 )
ArcabitTrojan.Graftor.DB4E
BitDefenderThetaGen:NN.ZevbaCO.36792.Wm0@aKDN93ii
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.KeyLogger.QWV
APEXMalicious
KasperskyTrojan-Spy.Win32.Xegumumune.csy
BitDefenderGen:Variant.Graftor.2894
NANO-AntivirusTrojan.Win32.Xegumumune.hjepvu
AvastWin32:Trojan-gen
TencentWin32.Trojan-Spy.Xegumumune.Gkjl
EmsisoftGen:Variant.Graftor.2894 (B)
VIPREGen:Variant.Graftor.2894
SophosMal/Generic-S
GoogleDetected
MAXmalware (ai score=85)
Antiy-AVLTrojan[Spy]/Win32.Xegumumune
Kingsoftmalware.kb.a.970
XcitiumMalware@#1e0nwu1pkgwo0
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Spy.Win32.Xegumumune.csy
GDataGen:Variant.Graftor.2894
AhnLab-V3Trojan/Win32.Graftor.C3723726
McAfeeArtemis!E6344546FC64
Cylanceunsafe
PandaTrj/GdSda.A
RisingSpyware.KeyLogger!8.12F (CLOUD)
IkarusTrojan.Win32.VB
FortinetW32/KeyLogger.OHL!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Spy.KeyLogger.QWV?

Win32/Spy.KeyLogger.QWV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment