Trojan

Trojan.Agent.CRIO removal

Malware Removal

The Trojan.Agent.CRIO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CRIO virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key

Related domains:

zaltzburgopportunity.top
corruptionobedienceorderskiing.tk

How to determine Trojan.Agent.CRIO?


File Info:

crc32: F0C043A6
md5: 62ae37d640f67fcbecd6b66ef1aa78e1
name: 62AE37D640F67FCBECD6B66EF1AA78E1.mlw
sha1: 9a1a72d3325599eb396bd312ee15614ed4030e82
sha256: f91cf1905b041ea927f29ff6e9c306c33693d66dbd6fb0b9bf8e03d5f745fae0
sha512: b3a25c0edb09fb742ddca895d9fdb2d4bef1ba3f21b534bf67d9c5b37982732c59c13874d62ddb95a6f5b989f5ffae0ee0a97e572e9301a0c1e1aeda4e835b02
ssdeep: 3072:2mnRIDTFrMh3ETyaqRScNe19BxBP+zHebMGXFzQEB2J4CQP7IKjLedGYw:bRIDBrMO/qRZNe19ZPF227IKjadGR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: stub.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: stub.exe
Translation: 0x0419 0x04b0

Trojan.Agent.CRIO also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CRIO
CAT-QuickHealTrojan.Generic
McAfeeGenericR-LBD!62AE37D640F6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0051c78c1 )
BitDefenderTrojan.Agent.CRIO
K7GWTrojan-Downloader ( 0051c78c1 )
Cybereasonmalicious.640f67
BitDefenderThetaGen:NN.ZexaF.34804.tu2@amHNkvgk
CyrenW32/S-dfd211d5!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Inject.evqomk
AegisLabTrojan.Win32.Inject.4!c
TencentMalware.Win32.Gencirc.10b23b26
Ad-AwareTrojan.Agent.CRIO
TACHYONTrojan/W32.Inject.324608.G
EmsisoftTrojan.Agent.CRIO (B)
ComodoApplication.Win32.DLBoost.H@7fexu7
F-SecureHeuristic.HEUR/AGEN.1115396
ZillyaDownloader.Tovkater.Win32.667
TrendMicroHT_TOVKATER_GL0400BB.UVPM
McAfee-GW-EditionGenericR-LBD!62AE37D640F6
FireEyeGeneric.mg.62ae37d640f67fcb
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
JiangminTrojan.Generic.fwmfe
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1115396
Antiy-AVLTrojan/Win32.Inject
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Agent.CRIO
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Agent.CRIO
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Inject.C2289986
Acronissuspicious
VBA32BScope.Trojan.Tiggre
ALYacTrojan.Agent.CRIO
MAXmalware (ai score=99)
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.HQ
TrendMicro-HouseCallHT_TOVKATER_GL0400BB.UVPM
RisingTrojan.Generic@ML.87 (RDMK:Pp7eqyTesYkgry6KnZ+Gew)
YandexTrojan.Inject!feCDzq4av48
SentinelOneStatic AI – Malicious PE
FortinetW32/Tovkater.HQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.41f

How to remove Trojan.Agent.CRIO?

Trojan.Agent.CRIO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment