Backdoor

Backdoor:Win32/Quicdy.A removal

Malware Removal

The Backdoor:Win32/Quicdy.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Quicdy.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Compression (or decompression)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Polish
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

barthrtada.com
sourpuss.net
ns1.opennameserver.org
freya.stelas.de
ns.dotbit.me
ns1.moderntld.com

How to determine Backdoor:Win32/Quicdy.A?


File Info:

crc32: 2122CA2F
md5: ae39c323218af31016f0ba9a2b58b984
name: n1.exe
sha1: 6a225eb1d9186aa1bf001509e40341521590a201
sha256: 61a2e05d5ec897847fe7309ffad64bc2c7960e9c94c3766df7720f7473e529d5
sha512: d03d90a6fc12032e686e686356664ca5ca01ac41e4df0e5209af8c75ad6a269984a4d92e271928eb38e5c8e48fdfd2eff7fdcde47d7e1077e08addd2436ba5a7
ssdeep: 6144:qEboKtaJsb1ua38O1EGyWGClvppe2vDnFJQq65y:qwlRug11EGVGC9f5nEFM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Quicdy.A also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Encoder.25965
MicroWorld-eScanTrojan.GenericKDZ.47017
FireEyeGeneric.mg.ae39c323218af310
Qihoo-360Generic/HEUR/QVM10.2.D935.Malware.Gen
McAfeeGenericRXGK-WE!AE39C323218A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Jimmy.4!c
SangforMalware
K7AntiVirusTrojan ( 0053b72b1 )
BitDefenderTrojan.GenericKDZ.47017
K7GWTrojan ( 0053b72b1 )
Cybereasonmalicious.3218af
TrendMicroTrojan.Win32.SODINOK.SM.hp
BitDefenderThetaGen:NN.ZexaF.34106.tyW@auNqF7lG
CyrenW32/Kryptik.IE.gen!Eldorado
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
GDataTrojan.GenericKDZ.47017
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.e179c802
NANO-AntivirusTrojan.Win32.Coins.fhocwq
TencentWin32.Trojan.Generic.Lnxx
Ad-AwareTrojan.GenericKDZ.47017
SophosMal/GandCrab-B
ComodoMalware@#1gke4knfskbbl
F-SecureHeuristic.HEUR/AGEN.1102756
ZillyaTrojan.GenericKD.Win32.179212
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.47017 (B)
SentinelOneDFI – Suspicious PE
F-ProtW32/Kryptik.IE.gen!Eldorado
JiangminTrojan.PSW.Coins.bbw
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1102756
Antiy-AVLTrojan[PSW]/Win32.Coins
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.DB7A9
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Quicdy.A
AhnLab-V3Win-Trojan/Gandcrab08.Exp
Acronissuspicious
VBA32BScope.Trojan.Vigorf
ALYacTrojan.GenericKDZ.47017
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ZonerTrojan.Win32.72207
ESET-NOD32a variant of Win32/Kryptik.GKIB
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Vigorf!8.EAEA (CLOUD)
YandexTrojan.Agent!O19UCy4do4U
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GKJF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73700185.susgen

How to remove Backdoor:Win32/Quicdy.A?

Backdoor:Win32/Quicdy.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment