Malware

Heur.Crifi.1 information

Malware Removal

The Heur.Crifi.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Crifi.1 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.dyndns.org

How to determine Heur.Crifi.1?


File Info:

crc32: DD945ABC
md5: fc81195269575a53a7087546563c1d5b
name: FC81195269575A53A7087546563C1D5B.mlw
sha1: 425b0da0eee8a50096c0f1c12ea4e3d2542e2fba
sha256: dd9f9e09070ce4a91afae289dcf30ebeb0385316c79c83218d63829897456fef
sha512: 5809c737d2a435a72976ae71fab79688c0912ecf03d9c64126ebcef7b074faf7b723c2d394c174f949fe48c64a86cd61ab60e45a1d9e4ae5d6380dab73766384
ssdeep: 24576:CRRRRRRRRRRRRRRRRRRRRtpperrOUj6k7ZqC30J28nu/kbRg8SPhg9R8Ej:CRRRRRRRRRRRRRRRRRRRRt/k7ZxLug8
type: PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive

Version Info:

0: [No Data]

Heur.Crifi.1 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Crifi.1
FireEyeGeneric.mg.fc81195269575a53
ALYacGen:Heur.Crifi.1
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Heur.Crifi.1
Cybereasonmalicious.269575
BitDefenderThetaAI:Packer.13DECCFB23
CyrenW32/Trojan.MQTJ-5716
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Autorun.Spy.Agent.AU
BaiduWin32.Trojan.Autoit.cb
APEXMalicious
AvastAutoIt:Agent-ANS [Trj]
ClamAVWin.Trojan.Autoit-6922942-0
KasperskyTrojan.Win32.Inject.aadtw
AlibabaTrojan:MSIL/Autorun.13c43f6e
NANO-AntivirusTrojan.Script.Inject.eeltyx
AegisLabTrojan.Win32.Inject.4!c
TencentWin32.Trojan.Inject.Efuf
Ad-AwareGen:Heur.Crifi.1
EmsisoftGen:Heur.Crifi.1 (B)
ComodoMalware@#2wpcfcf4mlvmn
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.Spy.20053
ZillyaTrojan.Inject.Win32.196845
TrendMicroWORM_GOLROTED.AAAFF
McAfee-GW-EditionRDN/Generic PWS.fv
SophosMal/Generic-R + Troj/Agent-ASAU
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
KingsoftWin32.Troj.Inject.(kcloud)
ArcabitTrojan.Crifi.1
AhnLab-V3Trojan/Win32.Inject.C1480933
ZoneAlarmTrojan.Win32.Inject.aadtw
GDataScript.Trojan-Spy.Heye.B
CynetMalicious (score: 100)
McAfeeRDN/Generic PWS.fv
PandaTrj/CI.A
ZonerTrojan.Win32.92739
TrendMicro-HouseCallWORM_GOLROTED.AAAFF
RisingTrojan.Injector!8.C4 (TOPIS:E0:CfIgSiVctlT)
IkarusTrojan-Spy.Golroted
FortinetW32/Autoit.CKP!tr
AVGAutoIt:Agent-ANS [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360HEUR/QVM06.2.Malware.Gen

How to remove Heur.Crifi.1?

Heur.Crifi.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment