Trojan

Trojan-Banker.Win32.Cridex.qlu information

Malware Removal

The Trojan-Banker.Win32.Cridex.qlu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.qlu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

support.oracle.com
support.apple.com
www.intel.com
soldkorean.top
help.twitter.com

How to determine Trojan-Banker.Win32.Cridex.qlu?


File Info:

crc32: 6E1C703A
md5: 8a470086ff267dda0724c12ce9dd9f72
name: upload_file
sha1: 27b4b723114ae0db6ce2c3034f1843c9bbf9daa2
sha256: e5f1b3c69e967ec1531a0fb923599009fd86a9667110079be0b8cf50360f4e8c
sha512: 8de97612dbb4ca4aecf7de0ba13e3b693084ddf344a24efae8c9bfd863ecdb2a251afefc4f3f4cb2b93468dfd802adb96545e30e1594560d4195b650870fb2e0
ssdeep: 1536:hF+KOaaJzE/2b3RDdJQ5ZU5m/Yzs/8OXmlW9nuZtH2WY8+pt6PytN8bUMWfy:hF6JAkhR2SsfmvtH/+poPANjTfy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Cridex.qlu also known as:

McAfeeRDN/PWS-Banker
MalwarebytesTrojan.IcedID
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056c8921 )
BitDefenderTrojan.GenericKD.34355452
K7GWTrojan ( 0056c8921 )
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyTrojan-Banker.Win32.Cridex.qlu
AlibabaTrojanBanker:Win32/Cridex.54903b7c
MicroWorld-eScanTrojan.GenericKD.34355452
RisingTrojan.Kryptik!1.CA98 (CLASSIC)
Ad-AwareTrojan.GenericKD.34355452
EmsisoftTrojan.GenericKD.34355452 (B)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/AD.PhotoDlder.BN
DrWebTrojan.IcedID.30
TrendMicroTrojan.Win32.WACATAC.THHAEBO
FireEyeTrojan.GenericKD.34355452
SophosMal/Generic-S
CyrenW32/Kryptik.BTZ.gen!Eldorado
JiangminTrojan.Banker.Cridex.agb
AviraTR/AD.PhotoDlder.BN
MAXmalware (ai score=83)
Antiy-AVLTrojan[Banker]/Win32.Cridex
MicrosoftTrojan:Win32/IcedID.DL!MTB
ArcabitTrojan.Generic.D20C38FC
ZoneAlarmTrojan-Banker.Win32.Cridex.qlu
GDataTrojan.GenericKD.34355452
AhnLab-V3Malware/Win32.RL_Generic.R348270
ALYacTrojan.GenericKD.34355452
TACHYONBanker/W32.Cridex.172034
VBA32TrojanBanker.Cridex
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFOC
TrendMicro-HouseCallTrojan.Win32.WACATAC.THHAEBO
TencentWin32.Trojan-banker.Cridex.Eaxb
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.105298335.susgen
FortinetW32/GenKryptik.EQIK!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan-Banker.Win32.Cridex.qlu?

Trojan-Banker.Win32.Cridex.qlu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment