Malware

How to remove “Heur.Crifi.2”?

Malware Removal

The Heur.Crifi.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Crifi.2 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristics of HawkEye keylogger.
  • Steals private information from local Internet browsers
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to create or modify system certificates
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyipaddress.com
smtp.mail.ru

How to determine Heur.Crifi.2?


File Info:

crc32: 5B757BCE
md5: f2ab596d44809e49eb9d9641518929f3
name: F2AB596D44809E49EB9D9641518929F3.mlw
sha1: 09c47e894da5ac29a7ed35e52a15c108869c54c9
sha256: a791e20675cd4bf92c082fb5e4f0ae6109c6be231193f37589a5cb57b4167017
sha512: 44953c435a9824d922f947985d8b18a90313296ffb7f622aa2666d8da37ec09892e1d2c793a50ec352865eb1b948c4cf613c2c96d9a50891822fbf8c07cb65d5
ssdeep: 12288:eu4pNPJqqmeY7Bi/RRNqYJVoI0b8sLX88lVm6FUWtOddGTlJI4VqSA3SuZTzG+fR:eBxTI7Bi/NV4LX5WlWt+6lBzuZ5+/IT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.2900.2180
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Heur.Crifi.2 also known as:

K7AntiVirusSpyware ( 004b90fc1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen1.46762
CynetMalicious (score: 100)
ALYacGen:Heur.Crifi.2
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWSpyware ( 004b90fc1 )
Cybereasonmalicious.d44809
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.ABV
APEXMalicious
AvastWin32:Dropper-gen [Drp]
ClamAVWin.Dropper.DarkComet-6305705-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Crifi.2
NANO-AntivirusTrojan.Win32.Crypted.eajavm
MicroWorld-eScanGen:Heur.Crifi.2
TencentWin32.Trojan.Yakes.Ectv
Ad-AwareGen:Heur.Crifi.2
SophosML/PE-A + Troj/MDrop-GWI
ComodoMalware@#14m6btsh9mx08
BitDefenderThetaAI:Packer.EFD4C6ED23
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXER.cc
FireEyeGeneric.mg.f2ab596d44809e49
EmsisoftGen:Heur.Crifi.2 (B)
SentinelOneStatic AI – Malicious SFX
JiangminTrojan.Yakes.gki
WebrootW32.Gen.BT
AviraTR/Crypt.XPACK.444848
Antiy-AVLTrojan/Generic.ASMalwS.1951FE4
MicrosoftTrojanSpy:MSIL/Golroted.B
SUPERAntiSpywareRansom.CryptoWall/Variant
GDataGen:Heur.Crifi.2
AhnLab-V3Dropper/Win32.Injector.C1869693
McAfeeArtemis!F2AB596D4480
MAXmalware (ai score=87)
VBA32Trojan.Yakes
MalwarebytesRansom.CryptoWall
PandaGeneric Suspicious
YandexTrojan.Yakes!0Nh0AaL7Yp4
FortinetW32/Yakes.OYLJ!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove Heur.Crifi.2?

Heur.Crifi.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment