Trojan

How to remove “UDS:Trojan.MSIL.Quasar.ard”?

Malware Removal

The UDS:Trojan.MSIL.Quasar.ard is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.MSIL.Quasar.ard virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Terminates another process
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine UDS:Trojan.MSIL.Quasar.ard?


File Info:

name: 2051A13A0128BD4BCD48.mlw
path: /opt/CAPEv2/storage/binaries/44940d5902fadf3514ba87be7ee30ddccf1751307127a022fbd12edd447130eb
crc32: 7BFCF9BC
md5: 2051a13a0128bd4bcd48f73cbf856e39
sha1: 28f01fd1f5dbb15134516d75f6e181f83884159b
sha256: 44940d5902fadf3514ba87be7ee30ddccf1751307127a022fbd12edd447130eb
sha512: 52e53b8d92d0b4cd4e958112d32c202554d76ae176de41c0f0eaeaaa15b1bc0706ea2cabe73b979c060905828cda34e91a385b6a44dd2d8a773796ffa816a5e8
ssdeep: 24576:GoS2TQgzw/bMESt+cHqVaEahK4JXEuT8huJP2K01YlX2cUnb0XBI50v0E+J1alng:HS2Tt7t2f0tEcPQ+lXgoyov+PGwvPd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15A85338192E60576DBE10831066AB09EEB39A5390B208CEFDB543E53BD43DE8C97D3D5
sha3_384: d6c90c3f75005fac5484afba09c7c2a2e0bdd271360c4026e9b2f71f96af758e2f795e53642854fb0b234bc291722446
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

UDS:Trojan.MSIL.Quasar.ard also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Encoder.trrL
Elasticmalicious (high confidence)
FireEyeGeneric.mg.2051a13a0128bd4b
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058ef681 )
AlibabaTrojan:MSIL/Quasar.8de92083
K7GWTrojan ( 0058ef681 )
Cybereasonmalicious.1f5dbb
BitDefenderThetaGen:NN.ZexaF.34582.QvW@aSR45if
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.MSIL.Quasar.ard
TrendMicroTROJ_GEN.R002C0RH522
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASMalwS.5174
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!2051A13A0128
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0RH522
RisingTrojan.Generic@AI.90 (RDML:ppHog+3SfM+BtjQhKDy4JQ)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/NDAoF
PandaTrj/Chgt.AD

How to remove UDS:Trojan.MSIL.Quasar.ard?

UDS:Trojan.MSIL.Quasar.ard removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment