Trojan

What is “Trojan.Cripack.Gen.1”?

Malware Removal

The Trojan.Cripack.Gen.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Cripack.Gen.1 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
oreganogf.su
jnfeqhkpihgc.com
ifkmqtsfiiqr.com
llenngpoefxy.com
ihxghiyqmhim.com
ivrvfntohghc.com
fjedebccuuhc.com
edpppqtducvy.com
vviihctbkvcs.com
nncdklilyiyy.com
yqyevqhdefnq.com
fsocnngvlmlk.com
nruvihxyohuk.com
hdbcbtuhgkop.com
ihlpqtddqqyh.com
ivfnfriiottw.com
fqybdemugqlc.com
lbqxyutcifgd.com
kbxvuudqrkps.com
ydlqrjkmxpom.com
ifkpuxhxsmns.com
llohutwpphii.com
iueujsttpqbo.com
fcssnmrroyee.com
vtggbwwwcgwl.com
pxplhwghuvyp.com
ejkddohpkjiv.com
deibimkmpjfp.com
piuenoohnnip.com
coopvuefggcs.com
gdcrgscjcmbe.com
gvkncwdeqjpq.com
jtwnmdkcpwsy.com
ddkbrjyisdqj.com
yyusqgyikkqo.com
vsdmmhijctyy.com
ohqrqhknhimn.com
cnmdghkobfml.com
fvvbbshonjlg.com
qxpsvixxyuvf.com
fibqqqrsfbcx.com
dwocfrpxggxe.com
ppmjkurkyyyv.com
hiyxyrjrhssn.com
mtwvmfgmlftm.com
jbbkcbghsxpg.com
inrqrchmcsek.com
ttgsdsvvoorb.com
novjcdumnqxo.com
dssokebuunun.com
losvfjjtsvun.com
yyxqjkcritwv.com
vudxjmuyijbb.com
mwgdtduufbvw.com
jrrdxypedxxl.com
hptlmbkhkksm.com
iqqefwwokdil.com
fcogtdwvmbbn.com
vrrqjggwnnrb.com
jkfuxonwgouc.com
uyponnqyyxgl.com
ckjjrjimbcdy.com
cddlcdhdbbsx.com
crfbeurgbfjx.com
jmmlxgqubqtl.com
ipybooblcdgk.com
innorqeefgny.com
tdttdgwcxsjs.com
jhiedkssjudg.com
umpqqimxiiyd.com
fedmbbkfckiu.com
ivvjkjulpiir.com
fnrnvbbttxkk.com
ihgfjcllxpfh.com
iuqtscrebkke.com
fpeernhdqxxs.com
kdnunqbgwvog.com
lqyvwoijbcdj.com
muvtbopsvyui.com
fdcswpqohqbf.com
wbtjyefihshv.com
yntltsnnfefj.com
oowlmjbxyqpl.com
nopiovoglofw.com
dcsopmdttomi.com
xvfnwkqtlkfg.com
lpiehoppeeqv.com
yvstqvutdccb.com
fmuurskurubr.com
hkyhmddxqnyx.com
dtchlxhpsbtc.com
mmcsswwnevrj.com
ixpqffrttcjm.com
jvcpgvwhmxog.com
hblhidcbihee.com
dunnvbfiimur.com
nendmuueeeun.com
iggfkpqifnbc.com
iqkttdtwbbcy.com
fchyyvwwlepo.com
vvnbgvyfghib.com
nodyyxwrqxwx.com
dttocsbclbxr.com
mlueujcxpqdl.com
iqimuiyjskhh.com
fnihghxqinmq.com
iyufhidtuett.com
vsthfudtsdxi.com
ootupsrkbsnc.com
nqyyqterbycp.com
hedjkgbbtlye.com
gxuvgiuxvdcg.com
nklhgjefgnmk.com
inmiggfgrjir.com
twxpchiswrrs.com
qrmpxlbnuudd.com
cbhgkltbowhu.com
fpmctgnodqif.com
kfrqyydlulkx.com
ijglmggyfcdw.com
umfkkbbjnidd.com
fvnnenuctsgs.com
qqjfmloluqed.com
bfjnipguxknm.com
eiilsjifbbcv.com
chxlwccddqbi.com
bkwvgvorchef.com
jmersyomvshk.com
iyyhwxmngpey.com
vswvuuuhwrks.com
ooofdgcbidjb.com
nhplldbrddpc.com
ybrswbrbspkq.com
hiejbqyhxyqy.com
mufwkruveypc.com
fetxdxkrodtt.com
ibredefolmbb.com
hdvfgknyeeyy.com
ipwpmhinolbf.com
ihpqyxtnvmmg.com
iulefedcsscl.com
feuyyrbininc.com
iyjwspmjkpui.com
vnofmlliturb.com
hejrfjjisxhg.com
gllhinwfvjrb.com
mjcbderbqhon.com
yijuxhqxorgw.com
uvfyywxtwjkw.com
srrghofuvwhy.com
jmycvutwopqj.com
iyijgbsfehgl.com
vneddnrgppgy.com
htxttwvyrwwt.com
hpgfktuovfkj.com
ihmbbrgkccxp.com
iyqipjkdqhir.com
vcwyowpefhyq.com
gghmruuyteie.com
mwjihiuvjokq.com
jvrrscsrcgsm.com
hlgrjdthppxh.com
etsiponmlcbx.com
ntwwgnglhdnk.com
ddechhtoniyh.com
yuhttpmnfble.com
feoudyfqoggs.com
idlvotpyyucx.com
ifuydtmdufiy.com
liooowpcnool.com
wgjxuyptmcmx.com
myxhqytufntx.com
vuuyvuefuxgg.com
myunkqnvjxtx.com
vsdpxvjyybno.com
ohwfvvlufiiy.com
ctsifrdiyxsl.com
lqripqhporwf.com
muyvwhitsrur.com
fghnnjiunkhw.com
begwscjrclls.com
ddviibgkhkjq.com
yuedcsrbgmxd.com
fcbfhcrxucju.com
vcrmdmbgpkfm.com
gbcgbpdbnmtw.com
yibjbckumcrj.com
uegofuyttnub.com
bjwtqywfmlwv.com
itsrryknmyiu.com
jogoddopogjy.com
dilnnovlkwkl.com
bkkonmppuyec.com
jmsgmnmluffr.com
iqmvnklttxyq.com
fctgjedkjgho.com
vvvmcdpcbqld.com
nvnvuyenpwwv.com
hgfcpeqfgnim.com
iyxwwjmhkojy.com
vutiqujkxhuy.com
mxdmdcejkrfe.com
jnnnvcccimmn.com
irfclpxrkoei.com
fbbelonrfjfm.com
yelcjqudkdll.com
stpsrgkxljkf.com
nvpxdpixiibu.com
hjebnndhhudg.com
myqeuuyxyjwf.com
vcobcnmllxhd.com
ghcnueooonrc.com
mlquxmmskvww.com
iscdpedshqqy.com
jjjedhfbpcbc.com
eyevikxxumts.com
sgqqyqqrkvhr.com
bcbhknmhhovw.com
bceijrbwmwjj.com
bscppwntpcne.com
rfnbkoneufkt.com
bllbcbjfeppm.com
kkcfenodtfom.com
ncxxjscwrcdg.com
ewhtdkpeyuhg.com
qurrkvobbudk.com
cmlibkkkgwem.com
eefetwoyvnjb.com
wqiqxbbffojb.com
ynqjiqyeevfs.com
ookncxqqrylk.com
ndfrgfchefip.com
edopdeuxxfff.com
vrmnqvflmnqe.com
jkbcdlkjvvpw.com
urstutstdcdc.com
ovphhwmlyvso.com
bkexcscjncjs.com
jjphdxhsjgji.com
eprgwwfuupve.com
jcsrqutwpnui.com
jhcfbbbedbrt.com
uydenwrbqxmi.com
ccbkjqqpnpvn.com
bbsfrdlxwcbf.com
ubedcigfbvih.com
osdudcrirrid.com
nfwmpwvmdtwl.com
iojjykebcbeb.com
ivorylknkkle.com
fghfpjqdtlpy.com
bedchimcbhqv.com
dyyyypotilkp.com
rhknmhgfehfh.com
ddhpkjdbmcmm.com
yinerohqrqhn.com
ufrqlipdydio.com
cqykjybkqmxl.com
igsdtckorhyj.com
ildgkgfnqebr.com
ffifrfuqhldn.com
ixwnmluvkhir.com
jghynnystmev.com
uulgfbqyyolx.com
rrnrmlrobmbo.com
nnqmjkrddllq.com
yutcxqpelxqm.com
fbvvofwxpihg.com
yyrrojdehgwx.com
vediqyxybkub.com
qmmtjjhgvuvw.com
fcdwsjbnwtuv.com
vvwxonbijbyv.com
nfobejjiyxwf.com
igkosxpkliqc.com
iqjkhkjetdmn.com
fnnfsbbqknqh.com
iyuqydghgfgx.com
vsdmyffoldcl.com
ohqqihuoofev.com
cnmdgkwsdxpk.com
fvvbtgwxwfwo.com
qxpwvgswgree.com
fifehgexcfwr.com
dcebjiffixxw.com
xxtjkpirmmxc.com
hkpympcenitv.com
dkylqqkxgxpm.com
dtgjjupponkk.com
mmyhekhhtttn.com
iycyctbcdefk.com
vgiqrwuwwosx.com
dgjrpxuvwopd.com
iiwhcoqiyyot.com
uhgdgvdtwqyh.com
uyfwgruupcvv.com
cdjoyhdkiqdp.com
cbbrqhevcdpt.com
fviqikkrhhou.com
qyetkxkhitdd.com
gklxsoggxkjl.com
mjfbbcdlibjf.com
yfedjskkdvsb.com
lrbjfejmpenu.com
hqiihmjqpwxs.com
corrgxhpkhqy.com
ghpxwyvnqxif.com
mqpuvuutkkoo.com
fetgclssbnqu.com
ibrskjijjyhy.com
hdhlpfkedsse.com
ibiytyibouoo.com
hkdcnnllywom.com
dtijetxnmtxw.com
mcgchnfklepw.com
ibkpkxgwqonq.com
hxcbbiipmnsp.com
hlptuyitmwhe.com
eufhcfqynwxj.com
ocvookfelkpq.com
mngfbedbcnst.com
uuqbscjoders.com
rumdyqdtxgnq.com
dgodgwwpggbb.com
ithiytossrun.com
jbfqfkrqjowd.com
ibpxhkhrnwhc.com
hbbcjfebefvr.com
depvvocbyhpp.com
pkrvbtgstsrq.com
hgeuoojilkbb.com
ieenghefistu.com
kgehovdniwjo.com
ooxjmqbcdgjb.com
nqecnbhwmbsd.com
hbfmqehqsbue.com
duitogrwxquw.com
nxgolllclnsh.com
thfbcgwtuunj.com
bbdgrbifuent.com
uyufxuffevgg.com
cdgkjmeyqhkg.com
cfvmltvyyyul.com
irmrriygjeot.com
fghfrmerwhfm.com
bededpbhxusj.com
dyujjrsdtcpt.com
rmmmbfddqmno.com
hqxscdeuuuqy.com
cypmbvkwjihg.com
qbemksrytrrv.com
cbegoxmfwqej.com
frnmlbrjgghn.com
mlimkhlmhtgg.com
ippejqhwfcdi.com
innivvvjodqf.com
tddcitskdyrh.com
jjfyqpfijjbj.com
eeiltwwgmgqt.com
wsonydgrbvvu.com
wpodcjmbcheb.com
nbytcctpxpxf.com
iurnncberhwc.com
fowjvetstupk.com
jdihdihgffog.com
kfeueelbkdyh.com
idemivddssco.com
ibkjrllyfeun.com
hxxipcolqhdc.com
hkkldijkdcgl.com
dklvexhppstq.com
dgrfkklmpobr.com
ivmmpxyupotu.com
fgtlmlojsxij.com
bqqhkbilkccm.com
ptdtslhypjwg.com
rwvohemyymkw.com
felhncghkjmu.com
iyrorinkhixh.com
vedooeslmhpd.com
qmrcldwjjwne.com
feippkkxuvoh.com
iflkjstxxpce.com
llirqnolmpii.com
ipcccbehcbji.com
ihccdqhqjbtu.com
ieieqverstmq.com
kwwnvssbemer.com
nfpuhrsvjnyq.com
ihddhqjjhemq.com
ieefgrutpkfe.com
kgdecfeuijsx.com
ommppfoolidu.com
jrmnuwkkffls.com
heeuuevncjrr.com
gxqndxqbudon.com
nqdsrcdldcri.com
hgcsspqnkvnh.com
iqrkhijrbjhe.com
femysdwcidej.com
ihsxwplgcndt.com
ilcbfedtlnol.com
fcqfvdtpqxdd.com
vooskletueot.com
klifnnnoofkk.com
nkkolmlkxhib.com
idbqtdyymddw.com
ihbeeopyywve.com
iqmhmmihgpgv.com
fcpuyxrjmfvy.com
vnuhkhvfhdrq.com
hefdglxtwtby.com
gxokggkcenst.com
nkkydcbswuvw.com
iddcrudowhef.com
ibkhhkrspyyv.com
hxgvccsorggk.com
htosodirbwkg.com
hidffwxnrstw.com
mndwbwswfqhh.com
uuupdtdnskfl.com
rvjsbqxiyqnk.com
ednmfesfmrxi.com
vrgwonvoupqm.com
jbkjinkffklh.com
igtmmmnepcpq.com
innvvuktmehd.com
tdxqpolmdgde.com
jlmjgdebwlpo.com
ufuxwrykdmyj.com
ctsjmdklpoth.com
lqyhxxscwwki.com
muuyfgrbrrnf.com
fcfedogktbuh.com
vnnmpkwcwjee.com
hgpsrkpuvucc.com
iqnjbbvuqrbi.com
feuiijugdgnm.com
iyjwsnmnolji.com
vnofmqnfkwxg.com
hejrewppuvsl.com
gllxqbmhkrex.com
mjfgsshddevo.com
yfwmumuuerxi.com
lljcfelopumu.com
ibcxxxxllmry.com
hxsxvvuturbi.com
hibbdhkjimwx.com
mmebcrelonmf.com
iyfotukstqfx.com
vfchijcqmnef.com
rviiuydcxurc.com
edemnvoxxbcq.com
vvcfvjqxsvhh.com
nkxifrlyvqqb.com
iymejmxcbgvv.com
vcwsslmnoopt.com
gghmqhoglsrd.com
mwjyymnutsbj.com
jvppsjvqjqen.com
hjeibmqqivlt.com
mymellygynne.com
vcwwwjjgyphw.com
ggbefgffkgbp.com
myunmddfccyt.com
vsdeeirkjhgo.com
ohdduewlkckw.com
cbfedxppwnnc.com
ffclemedgpdl.com
itthxqpmcsjx.com
jnjknilkknkp.com
inwhwktgphkp.com
tmrrwdsoofim.com
loorvotqxxvf.com
yyhxxdqjbcdi.com
vjbcojiteonn.com
hlecdpwjwldn.com
ennbmlkbedgf.com
hxthjkptsreo.com
hkebccbwlpkh.com
ddwjklejihgm.com
ypllkttgbiud.com
jcnogqeeexyp.com
jcnghpobkhog.com
jcgbgfvbrbit.com
jvvunmltcuef.com
hpkdydelhgww.com
imyxlmqffyuk.com
udtviuvwruus.com
ikjrqpmdmtss.com
ernstmrspspg.com
lmljklejgder.com
mjgkhrtfiijj.com
yodkeoogbrjw.com
ykddtobetore.com
uejbcpbrwllj.com
bhxhkvmqvuxb.com
gsswxsfsgwft.com
mueeufmpkhxh.com
fccstkybnqps.com
vllxxpcbopyl.com

How to determine Trojan.Cripack.Gen.1?


File Info:

crc32: 27AE80D1
md5: fdceaca16ac428394c7dc7169df189f6
name: FDCEACA16AC428394C7DC7169DF189F6.mlw
sha1: 0e486ba73cb5f7937d8c661390621bcaa6268524
sha256: 55ee934fb234b1f2a35f1a1b9acee59769415ec67b14dca3e96ad706b72a6b28
sha512: 1c19b924ed84e9e9ee4d3b0f0cbe63326004fd38727aede3e1ddaad4e92bb180b42671211f14d1d4c63af5fb1a31dd1e19156edcda5ed8367d53c00892ea1b0d
ssdeep: 3072:9zrldB+0cI22OJ9xbNHdMPBj25p6HRxDTWUbgv3oY:ZBdB+0cZ2MSieZ633
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Cripack.Gen.1 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Tinba.125
MicroWorld-eScanTrojan.Cripack.Gen.1
CAT-QuickHealTrojan.Tinba.9322
McAfeeGenericR-KDF!FDCEACA16AC4
CylanceUnsafe
VIPRETrojan.Win32.Carberp.i (v)
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Cripack.Gen.1
InvinceaML/PE-A + Troj/Glupteba-F
BitDefenderThetaGen:NN.ZexaF.34634.lq1@aqUsthec
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.CYVP
ZonerTrojan.Win32.28048
TotalDefenseWin32/Tinba.LIBCXW
AvastWin32:Evo-gen [Susp]
ClamAVWin.Dropper.TinyBanker-9787442-1
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Tinba.dobaag
RisingTrojan.Win32.Tinba.s (CLASSIC)
Ad-AwareTrojan.Cripack.Gen.1
SophosTroj/Glupteba-F
F-SecureTrojan.TR/ATRAPS.Gen4
McAfee-GW-EditionGenericR-KDF!FDCEACA16AC4
FireEyeGeneric.mg.fdceaca16ac42839
EmsisoftTrojan.Cripack.Gen.1 (B)
IkarusTrojan.Krypt
JiangminTrojan/Banker.Tinba.fb
AviraTR/ATRAPS.Gen4
MAXmalware (ai score=85)
Antiy-AVLTrojan[Banker]/Win32.Tinba
MicrosoftTrojan:Win32/Tinba.F
ArcabitTrojan.Cripack.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Cripack.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.C754701
VBA32BScope.Trojan.Tinba
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Deshacop.XO!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware
Cybereasonmalicious.16ac42
Qihoo-360HEUR/QVM07.1.455B.Malware.Gen

How to remove Trojan.Cripack.Gen.1?

Trojan.Cripack.Gen.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment