How to detect and remove Citadel Malware
If you are worry about your computer was infected Citadel Malware, you can download a Microsoft Safety Scanner from Microsoft at http://www.microsoft.com/security/scanner/en-us/default.aspx and run a full system scan.
- Click "Download Now" to download Microsoft Safety Scanner.
- Double click to run msert.exe and select Accept all terms of the preceding license agreement check box, then click “Next”
- Select “Full scan” and click “Next” to start scanning
- Scanning in progress
- Scanning was completed and no viruses, spyware, and other potentially unwanted software were detected.
- If your computer was infected by Citadel Malware, it will be detected and removed by the scanner.
HKCERT received and analyzed some samples of Citadel Malware, the preliminary result show that most of the anti-malware softwares are able to detect Citadel malware. You can refer to the link below:
Different security vendor may have different naming standard. You may refer to the table below for the aliases of Citadel malware.
Security Vendor
| Aliases of Citadel Malware
|
Avast | Win32:Spyeye-AGL [Trj] Win32:Cutwail-BM [Trj] Win32:Injector-AXW [Trj] Win32:Zbot-QEP [Trj] Win32:Malware-gen Win32:Crypt-OZC [Trj]
|
AVG | Generic30.TDR Dropper.Generic7.AAZV SHeur4.AWRI Dropper.Generic7.COPV BackDoor.Generic16.VZX SHeur4.AXDN Dropper.Generic7.COPV
|
Avira (AntiVir) | TR/Dropper.Gen8 TR/Spy.ZBot.ajoumea TR/Crypt.XPACK.Gen7 TR/PSW.Zbot.1039
|
ESET NOD32 | a variant of Win32/Injector.XNG a variant of Win32/Injector.AALK a variant of Win32/Injector.AAHY a variant of Win32/Injector.AAHE a variant of Win32/Kryptik.ASFX a variant of Win32/Injector.AEDR
|
F-secure | Gen:Variant.Symmi.11463 Trojan.Encpk.Gen.1 Trojan.Generic.KD.813474 Trojan.Generic.KD.811923 Gen:Variant.Symmi.10415 Trojan.Generic.KDV.906991
|
Kaspersky | Trojan-FakeAV.Win32.Windef.rzx Trojan-Spy.Win32.Zbot.hpdg Trojan-Spy.Win32.Zbot.hczs Trojan-Spy.Win32.Zbot.haus Trojan-Spy.Win32.Zbot.hnkf Trojan-Spy.Win32.Zbot.jwcj
|
McAfee | Generic PWS.y!1tc PWS-Zbot.gen.anm Generic PWS.y!1s3 Artemis!ADCE83CD65A0 RDN/Generic.bfr!ce
|
Microsoft | Trojan:Win32/EyeStye.N VirTool:Win32/Injector.gen!DJ VirTool:Win32/CeeInject PWS:Win32/Zbot.gen!AJ PWS:Win32/Zbot
|
Sophos | Mal/Generic-S Mal/ZboCheMan-L Mal/EncPk-AFN Mal/EncPk-AIN
|
Symantec | Trojan.Gen Infostealer Packed.Generic.415 WS.Reputation.1 Trojan.Gen.2
|
TrendMicro | TROJ_GEN.R47CDKR TROJ_GEN.R2ECFA4 TROJ_GEN.FC2CKLK TROJ_GEN.RCBCFA2 TROJ_GEN.RCBCDA9 TROJ_SPNR.0BCO13
|
Share with