HDQuali2y-v2

HDQuali2y-v2

Known Malware

by Evangelion Group

What is HDQuali2y-v2?

HDQuali2y-v2 is software application developed by Evangelion Group. It is most commonly found on computers running Windows 7 with nearly 69.23% of installations running this operating system. HDQuali2y-v2's installer is typically 9.00 MB in size and installs around 119 files. The most common release is 1.34.7.29 with 88.46% of all installations currently using this version.

HDQuali2y-v2 is most popular in the United States with 97.83% of installations residing in this country.

About HDQuali2y-v2?

HDQuali2y is a web browser advertisement extension designed to deliver ads to the user's web browser. The ads may come in the form of traditional banners or context-hyperlinks. It is important to note that the ads are injected on various web pages chosen by the software, not limited to those affiliated with the software or its affiliates. These ads are not endorsed by the underlying websites on which they appear. The software also periodically connects to remote servers to download new ad feeds and may track the domains and URLs visited by the user, as well as the links and advertisements they interact with while browsing the web.

Multiple virus scanners have detected malware in HDQuali2y-v2.

utils.exe (MD5: c5ed7c251f02392f8c1342b892ff9795) has been flagged by 43 scanners:
Scanner Software Result
Bkav FE HW32.CDB
IKARUS anti.virus PUA.PlusHD
Malwarebytes PUP.Optional.CrossRider.A
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AI [PUP]
AVG Generic.727
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.GoogUpdate.AlLB
CAT-QuickHeal Trojan.NSIS.r5
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27798
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.R
K7 AntiVirus Unwanted-Program ( 004a9d081 )
K7GW Unwanted-Program ( 004a9d081 )
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
McAfee Artemis!B2DBE34C634A
McAfee-GW-Edition BehavesLike.Win32.BadFile.fh
NANO AntiVirus Trojan.Win32.Crossrider.deaixn
Qihoo-360 Win32/Trojan.921
Sophos AppRider
Tencent Nsis.Trojan.Googupdate.Pgcx
Trend Micro TROJ_GEN.R001C0EK214
TrendMicro-HouseCall TROJ_GEN.R001C0EK214
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.943
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL Trojan/Win32.TSGeneric
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Panda Antivirus Trj/Genetic.gen
Agnitum Outpost PUA.Toolbar.CrossRider!
nProtect Trojan/W32.Agent.546160.D
d2f9d2f1-9dc6-4579-8ec5-b82208b3d9d0-11.exe (MD5: 5bf9a18b2c547c521fe192594f8693a9) has been flagged by 35 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
avast! Win32:Adware-gen [Adw]
AVG Generic.727
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Kazy.374062
Dr.Web Trojan.Crossrider.27302
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
McAfee Artemis!5BF9A18B2C54
McAfee-GW-Edition Artemis!5BF9A18B2C54
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Qihoo-360 HEUR/Malware.QVM10.Gen
VIPRE Antivirus Crossrider (fs)
Kaspersky Trojan.NSIS.GoogUpdate.ck
Panda Antivirus Trj/Chgt.C
Sophos Generic PUA IH
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Baidu-International PUA.Win32.CrossRider.bAJ
Fortinet FortiGate Riskware/CrossRider
NANO AntiVirus Trojan.Win32.Crossrider.ddrrpp
Rising Antivirus PE:Malware.Obscure!1.9C59
TrendMicro-HouseCall Suspicious_GEN.F47V0803
Avira AntiVir ADWARE/CrossRider.Gen2
Comodo Security ApplicUnwnt
Tencent Nsis.Trojan.Googupdate.Sxyk
nProtect Trojan/W32.Agent.350064.B
Symantec Trojan.ADH
Vba32 AntiVirus Trojan.GoogUpdate
Zillya Trojan.GoogUpdate.Win32.201
AhnLab-V3 PUP/Win32.Toolbar
F-Prot W32/A-7d811582!Eldorado
b81a2ae5-07bf-4b28-b16b-d08080aa8a54-7.exe (MD5: 5a96f28d78f046038d9ee2f777d071de) has been flagged by 35 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.727
AVware Crossrider (fs)
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27505
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
Fortinet FortiGate Riskware/CrossRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Kaspersky Trojan.NSIS.GoogUpdate.ck
McAfee Artemis!5A96F28D78F0
McAfee-GW-Edition Artemis!5A96F28D78F0
NANO AntiVirus Trojan.Win32.Crossrider.ddrpek
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA BP
Tencent Nsis.Trojan.Googupdate.Sxyk
TrendMicro-HouseCall Suspicious_GEN.F47V0803
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-M [PUP]
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
nProtect Trojan/W32.Agent.350064.B
Symantec Trojan.ADH
Vba32 AntiVirus Trojan.GoogUpdate
Zillya Trojan.GoogUpdate.Win32.201
AhnLab-V3 PUP/Win32.Toolbar
F-Prot W32/A-7d811582!Eldorado
Qihoo-360 Win32/Trojan.e1c
Baidu-International PUA.Win32.CrossRider.bAG
G Data Win32.Trojan.Agent.NDHGJE
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Rising Antivirus PE:Malware.Obscure!1.9C59
b81a2ae5-07bf-4b28-b16b-d08080aa8a54-6.exe (MD5: cb7b11b49a086d47b24be12e90a9858b) has been flagged by 30 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.Toolbar
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.727
AVware Crossrider (fs)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AE
Fortinet FortiGate Riskware/CrossRider
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
McAfee Artemis!CB7B11B49A08
McAfee-GW-Edition Artemis!CB7B11B49A08
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA FJ
TrendMicro-HouseCall Suspicious_GEN.F47V0803
VIPRE Antivirus Crossrider (fs)
avast! Win32:Adware-gen [Adw]
Dr.Web Trojan.Crossrider.27284
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
NANO AntiVirus Trojan.Win32.Crossrider.ddiuus
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation.1
Antiy-AVL Trojan/NSIS.GoogUpdate
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Qihoo-360 Win32/Trojan.921
Tencent Nsis.Trojan.Googupdate.Ljtk
b81a2ae5-07bf-4b28-b16b-d08080aa8a54-5.exe (MD5: 5da7317d227708117e11d3ce616f14f8) has been flagged by 26 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
avast! Win32:Adware-gen [Adw]
AVG Generic.727
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus AdWare.Adload
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
Antiy-AVL Trojan/NSIS.GoogUpdate
Dr.Web Trojan.Crossrider.27652
Kaspersky Trojan.NSIS.GoogUpdate.ck
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
Panda Antivirus Trj/Chgt.C
Qihoo-360 Win32/Trojan.921
Symantec Trojan.ADH
Fortinet FortiGate Riskware/CrossRider
McAfee Artemis!A2443C40DFFF
Tencent Nsis.Trojan.Googupdate.Ljtk
TrendMicro-HouseCall Suspicious_GEN.F47V0803
Sophos Generic PUA GK
Avira AntiVir ADWARE/CrossRider.Gen2

Startup Entries

Startup tasks:
  • f6fc667b-2894-459a-b9d6-381725717547-5.exe is automatically launched at startup through a scheduled task named f6fc667b-2894-459a-b9d6-381725717547-5_user.
  • b81a2ae5-07bf-4b28-b16b-d08080aa8a54-7.exe is automatically launched at startup through a scheduled task named b81a2ae5-07bf-4b28-b16b-d08080aa8a54-1.
  • b81a2ae5-07bf-4b28-b16b-d08080aa8a54-6.exe is automatically launched at startup through a scheduled task named b81a2ae5-07bf-4b28-b16b-d08080aa8a54-6.
  • b81a2ae5-07bf-4b28-b16b-d08080aa8a54-5.exe is automatically launched at startup through a scheduled task named b81a2ae5-07bf-4b28-b16b-d08080aa8a54-5_user.
  • b81a2ae5-07bf-4b28-b16b-d08080aa8a54-4.exe is automatically launched at startup through a scheduled task named e267594c-af4f-40de-95cf-e0051fb92c09.
  • b81a2ae5-07bf-4b28-b16b-d08080aa8a54-11.exe is automatically launched at startup through a scheduled task named b81a2ae5-07bf-4b28-b16b-d08080aa8a54-3.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\hdquali2y-v2
Uninstaller:
C:\Program Files\HDQuali2y-v2\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

HDQuali2y-v2 Executable Details

Primary executable:
utils.exe
Name:
HDQuali2y-v2
Path:
C:\Program Files\hdquali2y-v2\utils.exe
MD5:
c5ed7c251f02392f8c1342b892ff9795
SHA-1:
–
SHA-256:
–
Files installed by HDQuali2y-v2
File Type Filename MD5
EXE
ab3b6afd3fc4d3de4a07ea982e1c3974
EXE
22cfedc0fe9cb69eabd892da22f06629
EXE
35b6b4a601652d9c2a54fdb72ec6976b
EXE
2b2581fcc22fda93ac4a48465ecc1a53
EXE
af4fa1e9db217d08e00492c5ddc12726
EXE
39a31f996d2a3ef78cca6d2c8978a8ee
EXE
5a96f28d78f046038d9ee2f777d071de
EXE
eddd0d36b06a5fa882e12864bc542dd4
EXE
cb7b11b49a086d47b24be12e90a9858b
EXE
5da7317d227708117e11d3ce616f14f8