Backdoor

Should I remove “Backdoor.MSIL.Quasar”?

Malware Removal

The Backdoor.MSIL.Quasar is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.Quasar virus can do?

  • Network activity detected but not expressed in API logs

How to determine Backdoor.MSIL.Quasar?


File Info:

crc32: AF5B9E2C
md5: d6726a6d9741ba0f244e0d5282f8fcca
name: file.exe
sha1: 474137f8c0865333ed57e7b1eb6ec8a624944227
sha256: 4e7930058518f24a543687bc76bc7356f01b9d12b63afe3f7999f61b00d4bc3d
sha512: 6f3374abcc0172c6052cd98b534b95446108f6e4374194d42d186d533cf69cb165832cbb2b67d4ac723df3fa89aaabf2f35509d55232845a88c4ec810a8cfff6
ssdeep: 6144:2KOH3GKo9REmTeT88LLaXxa4wHiSRPXSftqywf7baM5LxgNoMmkttqFdzj:2Ke3Y9xoLLaXxvqvSfaCM5LWNykKn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.3.0.0
InternalName: Client.exe
FileVersion: 1.3.0.0
ProductVersion: 1.3.0.0
FileDescription:
OriginalFilename: Client.exe

Backdoor.MSIL.Quasar also known as:

MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.9DAC3A27
FireEyeGeneric.mg.d6726a6d9741ba0f
McAfeeGenericRXDB-RU!D6726A6D9741
ALYacBackdoor.MSIL.Quasar.gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 004bf53c1 )
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.9DAC3A27
K7GWSpyware ( 004bf53c1 )
Cybereasonmalicious.d9741b
Invinceaheuristic
F-ProtW32/MSIL_Mintluks.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-6623004-0
GDataMSIL.Trojan-Spy.Keylogger.J
KasperskyHEUR:Trojan.MSIL.Quasar.gen
AlibabaTrojan:Win32/Starter.ali2000005
RisingBackdoor.Quasar!1.B1DD (CLOUD)
Endgamemalicious (high confidence)
EmsisoftDeepScan:Generic.MSIL.PasswordStealerA.9DAC3A27 (B)
F-SecureHeuristic.HEUR/AGEN.1045085
DrWebBackDoor.Quasar.1
TrendMicroTSPY_TINCLEX.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminesuspicious.low.ml.score
SophosTroj/Subti-A
SentinelOneDFI – Malicious PE
CyrenW32/MSIL_Mintluks.A.gen!Eldorado
AviraHEUR/AGEN.1045085
MAXmalware (ai score=81)
Antiy-AVLTrojan/MSIL.Quasar
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.9DAC3A27
ZoneAlarmHEUR:Trojan.MSIL.Quasar.gen
MicrosoftBackdoor:Win32/QuasarRAT.A
AhnLab-V3Trojan/Win32.Inject.C1531898
Acronissuspicious
VBA32TScope.Trojan.MSIL
Ad-AwareDeepScan:Generic.MSIL.PasswordStealerA.9DAC3A27
MalwarebytesBackdoor.Quasar
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Spy.Agent.AES
TrendMicro-HouseCallTSPY_TINCLEX.SM1
TencentMsil.Trojan.Quasar.Wrgc
IkarusBackdoor.Win32.Xiclog
eGambitTrojan.Generic
FortinetMSIL/Agent.AES!tr
BitDefenderThetaGen:NN.ZemsilF.34104.Cm0@a0MpKJl
AVGMSIL:Rat-B [Trj]
AvastMSIL:Rat-B [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.b28

How to remove Backdoor.MSIL.Quasar?

Backdoor.MSIL.Quasar removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment