Malware

Should I remove “Troj/Quasar-AF”?

Malware Removal

The Troj/Quasar-AF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Quasar-AF virus can do?

  • Authenticode signature is invalid
  • CAPE detected the QuasarStealer malware family

How to determine Troj/Quasar-AF?


File Info:

name: BADF43E45F178CF6F1E6.mlw
path: /opt/CAPEv2/storage/binaries/a429e2302cb4c16326d6cc77a9a55860f5e4fd99311519c52386c9d64d39e1d3
crc32: 65D89BBA
md5: badf43e45f178cf6f1e6cb07c7e2ecfd
sha1: d76b5ee5507cd60185ff3247b400ea2f495bc1c2
sha256: a429e2302cb4c16326d6cc77a9a55860f5e4fd99311519c52386c9d64d39e1d3
sha512: 756c067b146a797dc9724ded179ffd28c0c02f21b2f506462256f51ae52aefefcdcecb95006f6b6285d9515c1f1060ab282dadd71177fc39678fae681cf8c989
ssdeep: 49152:dbzzN/+4zYvcWTfw4yfIN6qcZaQzHHcxUuxG:dbzJ/+vcWTfw4aIN6Jt8x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEE57C027BEA9E37D55FAAB3E021150A13F0E50AA787FB43BA91B7745C933648D119C3
sha3_384: 72f77b9271b96e0e92449dd568bca1dd81d5c542fc06ef576ed7798323974d1ab2b876ce19816dac0bfe3282fc58541a
ep_bytes: 00000000000000000000000000000000
timestamp: 2024-02-06 02:58:25

Version Info:

0: [No Data]

Troj/Quasar-AF also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
DrWebBackDoor.QuasarNET.3
ClamAVWin.Malware.Generic-9883083-0
FireEyeGeneric.mg.badf43e45f178cf6
SkyhighBehavesLike.Win32.Generic.wm
McAfeeArtemis!BADF43E45F17
MalwarebytesGeneric.Trojan.MSIL.DDS
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MSIL_Heur.B
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Agent.gen
AvastMSIL:Quasar-A [Rat]
TrendMicroTROJ_GEN.R011C0DB724
SophosTroj/Quasar-AF
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.4J06FK
GoogleDetected
Antiy-AVLTrojan[Spy]/Win32.Agent.foqx
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agent.gen
MicrosoftBackdoor:MSIL/Quasar!atmn
AhnLab-V3Backdoor/Win32.QuasarRAT.R341693
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R011C0DB724
RisingBackdoor.Quasar!1.E5F1 (CLASSIC)
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGMSIL:Quasar-A [Rat]
Cybereasonmalicious.5507cd
DeepInstinctMALICIOUS

How to remove Troj/Quasar-AF?

Troj/Quasar-AF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment