Threat Database Adware Adware.Generic6.QDX

Adware.Generic6.QDX

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 117
First Seen: February 27, 2015
Last Seen: July 27, 2026
OS(es) Affected: Windows

Computer users notified of the Adware.Generic6.QDX infection might want to know that it is a general name used by security solutions to specify adware. Security experts note that adware often arrives on PCs by bundling with free software installers that many users don't bother to handle via the 'Advanced' or 'Custom' option. The Adware.Generic6.QDX cyber threat may appear as a Browser Helper Object, an add-on and a browser extension depending on what web applications you have installed on your system. The Adware.Generic6.QDX can collect information about your favorite websites and preferred online resources in order to personalize the marketing materials presented to you. The Adware.Generic6.QDX might show pop-ups loaded with ads and banners that may cover your browser surface. If you want to secure your online activities and purge Adware.Generic6.QDX from your PC, you might want to consider using a trustworthy anti-spyware utility.

Analysis Report

General information

Family Name: Adware.AddLyrics.E
Signature status: No Signature

Known Samples

MD5: 77ed84254a5299a294b1cd3b8afeb299
SHA1: efb725c31096e514c8ed179b6e540a2a8e32a6a1
SHA256: 31E0AEB6E7B1D19ACC2EF6AF27CC65AEC6142ADCCC0BE477BFFD48539C84C82A
File Size: 133.12 KB, 133120 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 502
Potentially Malicious Blocks: 97
Whitelisted Blocks: 405
Unknown Blocks: 0

Visual Map

0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x 0 x x x 0 x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x 0 x x x x x x 0 x 0 x x x x x 0 x x 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x 0 x x 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 1 0 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 1 0 0 0 0 0 0 0 1 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\efb725c31096e514c8ed179b6e540a2a8e32a6a1_0000133120.,LiQMAxHB