Trojan

Trojan-Banker.Win32.Cridex.kwa removal guide

Malware Removal

The Trojan-Banker.Win32.Cridex.kwa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.kwa virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
resolver1.opendns.com
myip.opendns.com
curlmyip.net
ali-express1.at
taslks.at

How to determine Trojan-Banker.Win32.Cridex.kwa?


File Info:

crc32: 6371ABCA
md5: 8e748f9c23ee08308148f1bcd05d7f63
name: lns.exe
sha1: 19959e69eef8f2b2965bd0050edec50ca3a51c3e
sha256: 2a80deaa083bb554ccc57c0ffd467b4fd1a6e2f1ae6ab1a3de140aab849b19bf
sha512: 6fc6921b65b56d5417ff83476b6796fefc6e40c84d89b30caa9305e837794df3ad818270225befd7dde3524dbf65804be9036d7e56cf97d2c52364a3445c0ae5
ssdeep: 24576:6FZmMf48UZ+rT118fhGiv7DFD8JqogqL8bH94MqEvZjlrVgVgJAXzNSdqINDnEQx:6FZD48Ukvn8fYiHJ8JqogqL8bH94MqER
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Gavetwenty Svitla Systems, Inc.* Father Back bettersea Co
InternalName: Pose much
FileVersion: 6.0.88.83
CompanyName: Gavetwenty Svitla Systems, Inc.* Father
BuildID: 43055570
LegalTrademarks: Pose much Red Ar Gavetwenty Svitla Systems, Inc.* Father
ProductName: Pose much
ProductVersion: 6.0.88.83
FileDescription: Pose much
OriginalFilename: driv.exe
Translation: 0x0000 0x04b0

Trojan-Banker.Win32.Cridex.kwa also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ulise.103428
McAfeeArtemis!8E748F9C23EE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Ursnif.4!c
K7AntiVirusSpyware ( 0054b3121 )
BitDefenderGen:Variant.Ulise.103428
K7GWSpyware ( 0054b3121 )
TrendMicroTROJ_GEN.R049C0DCR20
BitDefenderThetaGen:NN.ZexaE.34104.mr0@a0lARgli
F-ProtW32/Ursnif.CQ.gen!Eldorado
ESET-NOD32Win32/Spy.Ursnif.CH
TrendMicro-HouseCallTROJ_GEN.R049C0DCR20
AvastWin32:CrypterX-gen [Trj]
GDataGen:Variant.Ulise.103428
KasperskyTrojan-Banker.Win32.Cridex.kwa
AlibabaTrojanBanker:Win32/Cridex.d0e216f0
ViRobotTrojan.Win32.S.Agent.1253888.Y
RisingSpyware.Ursnif!8.1DEF (CLOUD)
Ad-AwareGen:Variant.Ulise.103428
EmsisoftTrojan.Agent (A)
ComodoMalware@#28ees8d5pocx3
F-SecureTrojan.TR/AD.Ursnif.heseo
DrWebTrojan.PWS.Siggen2.45605
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.GQGN-2715
AviraTR/AD.Ursnif.heseo
MAXmalware (ai score=100)
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D19404
ZoneAlarmTrojan-Banker.Win32.Cridex.kwa
MicrosoftTrojan:Win32/Bluteal!rfn
VBA32BScope.Trojan.Wacatac
ALYacSpyware.Ursnif
MalwarebytesTrojan.Ursnif
PandaTrj/GdSda.A
TencentWin32.Trojan.Inject.Auto
IkarusTrojan-Banker.UrSnif
FortinetW32/Ursnif.CH!tr.spy
WebrootW32.Malware.gen
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.95d

How to remove Trojan-Banker.Win32.Cridex.kwa?

Trojan-Banker.Win32.Cridex.kwa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment