Trojan

Trojan-Banker.Win32.NeutrinoPOS.crc removal guide

Malware Removal

The Trojan-Banker.Win32.NeutrinoPOS.crc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.NeutrinoPOS.crc virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.NeutrinoPOS.crc?


File Info:

crc32: 916441CB
md5: 9bae99fb918f2ccf0143bce27dfb0108
name: 9BAE99FB918F2CCF0143BCE27DFB0108.mlw
sha1: 32d5a13fcb675e665e985dbdc8d4a297b58f06bc
sha256: 12186ae7c5cf0173a8fc1f92bd9e7df2357fbbb2a2edc15b2bd1a73626b48eb8
sha512: 7d5eb97b8ecc514362cc256cd7c2100d7dbfac9eb0c79dd71aa30e50e0b1fe1753f95b32a0b89a198ccfa5a145d9bfe1079319dbeff636461abf1469b85709a5
ssdeep: 3072:jgaW4SLbwUmoOkIV2vpA8EuqUNQm10/txlm6b7U3ayicb9EBNO/:jgz4SHwUxe2va8hNQm10nx7odic
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.NeutrinoPOS.crc also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23946
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrojan-FPYT!9BAE99FB918F
CylanceUnsafe
ZillyaTrojan.NeutrinoPOS.Win32.175
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GandCrab.1018b9af
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.b918f2
CyrenW32/Vigorf.I.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKXO
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.NeutrinoPOS.crc
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.NeutrinoPOS.fickun
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan-banker.Neutrinopos.Hwmw
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/Kryptik-CQ
ComodoTrojWare.Win32.NeutrinoPOS.OA@848f5a
BitDefenderThetaGen:NN.ZexaF.34796.kuW@aS3@1OpO
TrendMicroTrojanSpy.Win32.CLIPBANKER.SMB
McAfee-GW-EditionBehavesLike.Win32.Backdoor.ch
FireEyeGeneric.mg.9bae99fb918f2ccf
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.NeutrinoPOS.fs
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1121554
Antiy-AVLTrojan/Generic.ASMalwS.2817C1F
MicrosoftRansom:Win32/GandCrab.AX
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.Gandcrab.R237770
Acronissuspicious
VBA32TrojanBanker.NeutrinoPOS
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMB
RisingTrojan.Kryptik!1.B426 (CLASSIC)
IkarusTrojan.Crypt
FortinetW32/Kryptik.GKWI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Trojan-Banker.Win32.NeutrinoPOS.crc?

Trojan-Banker.Win32.NeutrinoPOS.crc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment