Trojan

BScope.TrojanDownloader.Cridex removal guide

Malware Removal

The BScope.TrojanDownloader.Cridex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanDownloader.Cridex virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine BScope.TrojanDownloader.Cridex?


File Info:

crc32: E475F6A6
md5: da4659843ed3c663d3b7b033619ba275
name: wusa.exe
sha1: d11f3fba8c924627ef9bd31cf40f3975e6d948bd
sha256: 450553dc27a8361fea14df58598a7bab9bba7f92be759850efef53423bea4450
sha512: bdc383c496766c057720e3b4bde2320f1af762aacd45dec889dc23f8abc4da7d06939d7ac9f38fa98c648acd091ff8618eb713c7684805057b82f0abdb13adcb
ssdeep: 12288:nJCOHjjkfMlBwUGqYXiv3TtnZ0SUh/FTs5SLiNOwC1NpAc7XMf2/ynU7n:8y3PqivxZm/FcSLwT7cFqn6n
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1991-2005 by Gougelet Pierre-e
InternalName: XnView
FileVersion: 2.13
CompanyName: XnView, http://www.xnview.com
LegalTrademarks: (
iew: .x05x01ProductVersion
3: D
FileDescription: XnView SlideShow
iginalFilename: .x07x01ProductName
Translation: 0x0409 0x04b0

BScope.TrojanDownloader.Cridex also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Razy.720542
FireEyeGeneric.mg.da4659843ed3c663
McAfeeArtemis!DA4659843ED3
SangforMalware
Cybereasonmalicious.a8c924
ArcabitTrojan.Razy.DAFE9E
Invinceaheuristic
SymantecTrojan!im
APEXMalicious
BitDefenderGen:Variant.Razy.720542
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.720542 (B)
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-APV
SentinelOneDFI – Malicious PE
FortinetW32/Cridex.VHO!tr
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
VBA32BScope.TrojanDownloader.Cridex
ALYacGen:Variant.Razy.720542
MAXmalware (ai score=85)
Ad-AwareGen:Variant.Razy.720542
CylanceUnsafe
RisingMalware.Heuristic!ET#82% (RDMK:cmRtazrqag9TNF5PyF4GAVi5+u4M)
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Razy.720542
BitDefenderThetaGen:NN.ZexaF.34138.in1@aeS2ndce
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM20.1.BDC7.Malware.Gen

How to remove BScope.TrojanDownloader.Cridex?

BScope.TrojanDownloader.Cridex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment