Trojan

Trojan-Banker.Win32.Cridex.qls removal tips

Malware Removal

The Trojan-Banker.Win32.Cridex.qls is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.qls virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

support.oracle.com
support.apple.com
www.intel.com
soldkorean.top
help.twitter.com

How to determine Trojan-Banker.Win32.Cridex.qls?


File Info:

crc32: 15B5032D
md5: eaee3f4ddd608ce362f8dcdfca40aad6
name: upload_file
sha1: 8700616ac6d73f84e615e7a33d42ac96a7a3b535
sha256: 0aa2727753d68654ada04a86531c216b15754fe0fabb38bf5db9c9bd4d8933a8
sha512: 777c0d2fc5cd9e18183e2a92247a41210a330d82c3359316b30673bb4e33ac5de954413ce4c6d3c795957544431ff89995ab864ab0c683aca6473fd0c1a68bdc
ssdeep: 1536:hF+KOaaJzE/2b3RDdJQ5ZU5m/Yzs/8OXmlWunuZtH2WY8+pt6PytN8bUMWf:hF6JAkhR2Ssfm0tH/+poPANjTf
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Cridex.qls also known as:

DrWebTrojan.IcedID.30
ALYacTrojan.GenericKD.34355468
SangforMalware
K7AntiVirusTrojan ( 0056c7781 )
BitDefenderTrojan.GenericKD.34355468
K7GWTrojan ( 0056c7781 )
TrendMicroTrojan.Win32.WACATAC.THHAEBO
CyrenW32/S-05c8e478!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.Win32.WACATAC.THHAEBO
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyTrojan-Banker.Win32.Cridex.qls
AlibabaTrojanBanker:Win32/Cridex.57848815
MicroWorld-eScanTrojan.GenericKD.34355468
RisingTrojan.Kryptik!1.CA98 (CLASSIC)
Ad-AwareTrojan.GenericKD.34355468
ComodoTrojWare.Win32.UMal.qaswf@0
F-SecureTrojan.TR/AD.PhotoDlder.BN
VIPRETrojan.Win32.Generic!BT
FireEyeTrojan.GenericKD.34355468
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
F-ProtW32/S-05c8e478!Eldorado
JiangminTrojan.Banker.Cridex.agb
AviraTR/AD.PhotoDlder.BN
FortinetW32/GenKryptik.EQIK!tr
Antiy-AVLTrojan[Banker]/Win32.Cridex
ArcabitTrojan.Generic.D20C390C
ZoneAlarmTrojan-Banker.Win32.Cridex.qls
MicrosoftTrojan:Win32/IcedID.DL!MTB
TACHYONBanker/W32.Cridex.172032
AhnLab-V3Malware/Win32.RL_Generic.R348270
McAfeeGenericRXLR-FJ!EAEE3F4DDD60
MAXmalware (ai score=81)
VBA32TrojanBanker.Cridex
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFOC
TencentMalware.Win32.Gencirc.10cde870
GDataTrojan.GenericKD.34355468
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Trojan.Generic

How to remove Trojan-Banker.Win32.Cridex.qls?

Trojan-Banker.Win32.Cridex.qls removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment