Spy Trojan

About “Trojan-Spy.MSIL.Quasar.jbe” infection

Malware Removal

The Trojan-Spy.MSIL.Quasar.jbe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.MSIL.Quasar.jbe virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan-Spy.MSIL.Quasar.jbe?


File Info:

crc32: 90F2A4A3
md5: f4bd9325c00e4636be017c841cb6c847
name: rub2703_bb_11cr5.exe
sha1: 4c268a1b96519bb2d7fb08bb7d4281a52d0db90d
sha256: 315e75c0008052bbd294e509d4b6e7b7166c35fa6eb61ba897d13574c61e96c3
sha512: 9bae0a32ee831858ae3be86dd9380215807723c6e86eddd2978b4f63e2003350f30ccc8b20d5e980c24589f7554cdfc168ad724934defaa524aff6c278e96f49
ssdeep: 24576:ofbu2O6XEFZDGUhg6GUIoZh1oxQl6xU/gfdzfcoedRlQ0s9Hk/CjlZ:0uVBFZCwfvIoLs5DcoedjQB9E/Cj7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2015
InternalName: Individuals'
FileVersion: 4.5.6.5
CompanyName: Realsil Microelectronics Inc.
FileDescription: Onclick Pendingset England
LegalTrademarks: Copyright 2015
Comments: Onclick Pendingset England
ProductName: Individuals'
Languages: English
ProductVersion: 4.5.6.5
PrivateBuild: 4.5.6.5
OriginalFilename: Individuals'.exe
Translation: 0x0409 0x04b0

Trojan-Spy.MSIL.Quasar.jbe also known as:

MicroWorld-eScanTrojan.GenericKD.42900053
Qihoo-360HEUR/QVM10.1.3BB5.Malware.Gen
McAfeeArtemis!F4BD9325C00E
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42900053
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaE.34104.xr0@aKBEsKmi
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42900053
KasperskyTrojan-Spy.MSIL.Quasar.jbe
AlibabaTrojanSpy:MSIL/Quasar.5beb05e7
AegisLabTrojan.Multi.Generic.4!c
TencentMsil.Trojan-spy.Quasar.Edxl
Ad-AwareTrojan.GenericKD.42900053
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.kykri
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42900053 (B)
IkarusTrojan-Ransom.GandCrab
AviraTR/Spy.Agent.kykri
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28E9A55
ZoneAlarmTrojan-Spy.MSIL.Quasar.jbe
MicrosoftTrojan:Win32/Dynamer!rfn
VBA32BScope.Trojan.Khalesi
CylanceUnsafe
ESET-NOD32MSIL/Spy.Agent.BYF
TrendMicro-HouseCallTROJ_GEN.R057H0CCT20
eGambitUnsafe.AI_Score_94%
FortinetW32/Agent.BYF!tr.spy
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Spy.MSIL.Quasar.jbe?

Trojan-Spy.MSIL.Quasar.jbe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment