Trojan

About “Trojan-Banker.Win32.Cridex.quv” infection

Malware Removal

The Trojan-Banker.Win32.Cridex.quv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.quv virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

support.apple.com
loadofficer.casa
help.twitter.com
www.intel.com
support.oracle.com

How to determine Trojan-Banker.Win32.Cridex.quv?


File Info:

crc32: 9F355A0F
md5: a3b793072c34b41b46b69d0ba74fcec3
name: upload_file
sha1: fdd15342dab8c71a4b0580bcbac4d5423874e51e
sha256: a45f209badc9cd8d0c7164a3a3593771f14fb52eadfd62a1a0b31a92c31af526
sha512: 634edb21436e3d4c8792801ecdbed6b28a63706b24ab8a76d81b525b8ce132dcc56cef8fed3e201af90318b753203e0eaec8415f05eebd014d1dbdd30afe40f7
ssdeep: 3072:0jQM9Q+UlKtdHj+/B+B+LkLJc6HjtyNpY:QS+Ua1fHjCY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2012 Jama Software Ran Corporation. All rights reserved.
InternalName: office.dll
FileVersion: 1.6.5.205
CompanyName: Jama Software Ran
ProductName: Jama Software Ran Againstsuffix
ProductVersion: 1.6.5.205
Way: Question
FileDescription: Againstsuffix
OriginalFilename: office.dll
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Cridex.quv also known as:

MicroWorld-eScanTrojan.GenericKD.43684755
FireEyeTrojan.GenericKD.43684755
CAT-QuickHealTrojan.Cridex
ALYacTrojan.IcedID.gen
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Cridex.7!c
K7AntiVirusTrojan ( 0056cbfb1 )
BitDefenderTrojan.GenericKD.43684755
K7GWTrojan ( 0056cbfb1 )
CyrenW32/Kryptik.BUK.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Cridex.quv
AlibabaTrojanBanker:Win32/Cridex.ddb23bf7
ViRobotTrojan.Win32.Z.Icedid.134144.AO
TencentWin32.Trojan-banker.Cridex.Lmuh
Ad-AwareTrojan.GenericKD.43684755
ComodoTrojWare.Win32.Genome.bkbah@0
F-SecureTrojan.TR/Kryptik.vpmpx
DrWebTrojan.IcedID.30
TrendMicroTROJ_GEN.R032C0DHI20
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Valak
AviraTR/Kryptik.vpmpx
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.GenKryptik
MicrosoftTrojan:Win32/IcedId.DA!MTB
ArcabitTrojan.Generic.D29A9393
ZoneAlarmTrojan-Banker.Win32.Cridex.quv
GDataTrojan.GenericKD.43684755
McAfeeArtemis!A3B793072C34
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EQOO
TrendMicro-HouseCallTROJ_GEN.R032C0DHI20
RisingTrojan.Kryptik!1.CAD4 (CLOUD)
FortinetW32/GenKryptik.EQOO!tr
BitDefenderThetaGen:NN.ZedlaF.34186.iu8@aC1je8ki
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.c15

How to remove Trojan-Banker.Win32.Cridex.quv?

Trojan-Banker.Win32.Cridex.quv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment