Malware

About “Mal/Generic-S + Mal/Quasar-B” infection

Malware Removal

The Mal/Generic-S + Mal/Quasar-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/Quasar-B virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • CAPE detected the QuasarStealer malware family

How to determine Mal/Generic-S + Mal/Quasar-B?


File Info:

name: 014CCACBD3735F3494D1.mlw
path: /opt/CAPEv2/storage/binaries/67cb4da8b9147f5a6e518d56b099ab69ed615fe62e6c45c6676e9c2e20e0676f
crc32: D639B95B
md5: 014ccacbd3735f3494d1269c39dddae8
sha1: e5d2d42633d668823335d6190a461a88ef7300e8
sha256: 67cb4da8b9147f5a6e518d56b099ab69ed615fe62e6c45c6676e9c2e20e0676f
sha512: 9da8bbc4d0bd4519df5cddbe6be74de80bdb81db82bbecf88ce642e58170c553be3b60d8db54ad9fceefdc9f0ef5ed32bfd3b4742a5a82b723d6a6c83b377d67
ssdeep: 6144:pTEgdc0Y7ebGbXOsA6j1RdhrQw2wT7awVyvEhcEYGb8F97azseHcTR3HmD:pTEgdfYzA6r5loBZws2cdHW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ECC45B4023EC8A17E26E47BAE871D4305BF4EC16B657E78F4588B9EE3C667029D40763
sha3_384: 3f317d37b08dfd23bfb9c2af61c60112d6081490ac49d189722cd277aa793840850ebcb4c14d8514e40be5e3caf57640
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-06-05 15:59:49

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Microsoft
FileDescription: Windows Command Processor
FileVersion: 1.0.0.0
InternalName:
LegalCopyright: Microsoft 2019
LegalTrademarks: Windows 10
OriginalFilename:
ProductName: Microsoft Corporation
ProductVersion: 6.2.100.100
Assembly Version: 6.2.100.100

Mal/Generic-S + Mal/Quasar-B also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Quasar.4!c
MicroWorld-eScanIL:Trojan.MSILZilla.2050
CAT-QuickHealTrojan.MsilFC.S15413537
ALYacIL:Trojan.MSILZilla.2050
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056b6611 )
AlibabaBackdoor:Win32/Quasar.3b7
K7GWTrojan ( 0056b6611 )
Cybereasonmalicious.bd3735
VirITTrojan.Win32.MulDrop13.PUA
CyrenW32/MSIL_Troj.BTX.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.BPH
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Passwordstealera-9792228-0
KasperskyHEUR:Trojan.MSIL.Quasar.gen
BitDefenderIL:Trojan.MSILZilla.2050
AvastMSIL:Quasar-A [Rat]
TencentTrojan.Msil.Quasar.wa
Ad-AwareIL:Trojan.MSILZilla.2050
EmsisoftIL:Trojan.MSILZilla.2050 (B)
F-SecureHeuristic.HEUR/AGEN.1235885
DrWebTrojan.MulDrop13.10660
TrendMicroTSPY_TINCLEX.SM1
McAfee-GW-EditionPWS-FDEK!014CCACBD373
FireEyeGeneric.mg.014ccacbd3735f34
SophosMal/Generic-S + Mal/Quasar-B
IkarusBackdoor.Win32.Xiclog
GDataMSIL.Backdoor.Quasar.B
JiangminTrojan.MSIL.oyqd
AviraHEUR/AGEN.1235885
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.30A0B40
MicrosoftBackdoor:MSIL/Quasar.GG!MTB
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.QuasarRAT.R341693
Acronissuspicious
McAfeePWS-FDEK!014CCACBD373
VBA32TScope.Trojan.MSIL
MalwarebytesBladabindi.Backdoor.Njrat.DDS
TrendMicro-HouseCallTSPY_TINCLEX.SM1
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:ulmCRQkXPW7szj4Zf2Vb1A)
YandexTrojan.Quasar!TmRozJ0FA5s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BPH!tr
BitDefenderThetaGen:NN.ZemsilF.34606.Hm0@a8F6Ij
AVGMSIL:Quasar-A [Rat]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-S + Mal/Quasar-B?

Mal/Generic-S + Mal/Quasar-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment