Trojan

How to remove “Trojan-Banker.Win32.Cridex.qux”?

Malware Removal

The Trojan-Banker.Win32.Cridex.qux is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.qux virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
support.apple.com
loadofficer.casa
help.twitter.com
www.intel.com
support.oracle.com

How to determine Trojan-Banker.Win32.Cridex.qux?


File Info:

crc32: 08879A00
md5: b0f74b47997f07b2d740c27d72f9e2a8
name: upload_file
sha1: 18a8e564c6284351721d1c6f1b89d4435c4875b1
sha256: 5251393cd54a8a1b7e73a61c60c861187fbbd6d708025bcb99bbe7103fd303d4
sha512: 453faf5efc2cd1e0f4a4c6a09be61f4b071a326a279f0a75bf648b21bf0295ebcba5d0d9810908303427c058a131ffc2e090d5401f0b2b5c2760fb9f261ae5bb
ssdeep: 3072:hjQM9Q+UlKtdHj+/B+B+LkLJc6HjtyNpYX:lS+Ua1fHjCYX
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2012 Jama Software Ran Corporation. All rights reserved.
InternalName: office.dll
FileVersion: 1.6.5.205
CompanyName: Jama Software Ran
ProductName: Jama Software Ran Againstsuffix
ProductVersion: 1.6.5.205
Way: Question
FileDescription: Againstsuffix
OriginalFilename: office.dll
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Cridex.qux also known as:

MicroWorld-eScanTrojan.GenericKD.43681651
FireEyeGeneric.mg.b0f74b47997f07b2
CAT-QuickHealTrojan.Cridex
McAfeeRDN/PWS-Banker
CylanceUnsafe
SangforMalware
AlibabaTrojanBanker:Win32/Cridex.0b17cf33
K7GWTrojan ( 0056cb401 )
K7AntiVirusTrojan ( 0056cb401 )
TrendMicroTROJ_GEN.R032C0DHI20
CyrenW32/Trojan.EXTG-4253
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Banker.Win32.Cridex.qux
BitDefenderTrojan.GenericKD.43681651
NANO-AntivirusTrojan.Win32.Cridex.hslpnp
RisingTrojan.Kryptik!1.CAD4 (CLASSIC)
Ad-AwareTrojan.GenericKD.43681651
ComodoTrojWare.Win32.Genome.ewxgs@0
F-SecureTrojan.TR/Kryptik.vpmpx
DrWebTrojan.IcedID.30
VIPRETrojan.Win32.Generic!BT
SophosMal/Generic-S
Paloaltogeneric.ml
WebrootW32.Trojan.Valak
AviraTR/Kryptik.vpmpx
Antiy-AVLTrojan[Banker]/Win32.Cridex
MicrosoftTrojan:Win32/IcedId.DA!MTB
ViRobotTrojan.Win32.Z.Icedid.134146.A
ZoneAlarmTrojan-Banker.Win32.Cridex.qux
GDataTrojan.GenericKD.43681651
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZedlaF.34196.iu9@aC1je8ki
ALYacTrojan.IcedID.gen
MAXmalware (ai score=83)
VBA32TrojanBanker.Cridex
MalwarebytesTrojan.IcedID
ESET-NOD32a variant of Win32/GenKryptik.EQOO
TrendMicro-HouseCallTROJ_GEN.R032C0DHI20
TencentMalware.Win32.Gencirc.11acc0e4
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_75%
FortinetW32/GenKryptik.EQOO!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.a78

How to remove Trojan-Banker.Win32.Cridex.qux?

Trojan-Banker.Win32.Cridex.qux removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment