Trojan

Trojan-Banker.Win32.Cridex.oan information

Malware Removal

The Trojan-Banker.Win32.Cridex.oan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.oan virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
support.oracle.com
support.apple.com
trythisrandom.top
www.intel.com
help.twitter.com

How to determine Trojan-Banker.Win32.Cridex.oan?


File Info:

crc32: F69B28D1
md5: 7772aa0cbb22fbe815295d33d1235d4f
name: business.exe
sha1: ad03c2608d69576cabdd4f6442ea1cfed5333037
sha256: 8eb8ab2331a0ed117b49d51afed86b610a59e0b53cde9f0e1442e66c252d0282
sha512: af74b46524b9e450193626fdeddaaedf0c78f299cb715b7b6e41c611d77ba1f02a7e8e9b88e7a5e7c3ed06b4e73de1804ec1dbce182fdad9a4ea80a91fd4d0d0
ssdeep: 49152:AhiqPYhXOwx4M4FDJlwqJ3xhANbcHDu+Ct2RvBf2Vxu:AhiQUX6M4FlaqJ3xmNb6S+CQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2007-2015 Standmove Breadagain
InternalName: Blowto.exe
FileVersion: 9.8.81.44
CompanyName: www.trueShmind.com
LegalTrademarks: Please ring
Comments: Difficultdecimal Fac hardlove lift
ProductName: Please ring
ProductVersion: 9.8.81.44
FileDescription: Please ring
OriginalFilename: Blowto.exe
Translation: 0x0000 0x04b0

Trojan-Banker.Win32.Cridex.oan also known as:

MicroWorld-eScanTrojan.GenericKD.43297663
FireEyeTrojan.GenericKD.43297663
McAfeeDrixed-FIH!7772AA0CBB22
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005683131 )
BitDefenderTrojan.GenericKD.43297663
K7GWTrojan ( 005683131 )
ArcabitTrojan.Generic.D294AB7F
BitDefenderThetaGen:NN.ZexaF.34128.tM0@aiqRQQei
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.IcedId.F
TrendMicro-HouseCallTrojanSpy.Win32.CRIDEX.AB
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.Cridex.oan
AlibabaTrojanBanker:Win32/Cridex.38255cad
AegisLabTrojan.Win32.Cridex.7!c
APEXMalicious
RisingDownloader.IcedId!8.1132C (CLOUD)
SophosMal/Generic-S
ComodoMalware@#tx4s6bbojc8i
TrendMicroTrojanSpy.Win32.CRIDEX.AB
McAfee-GW-EditionDrixed-FIH!7772AA0CBB22
FortinetW32/Cridex.OAN!tr
EmsisoftTrojan.GenericKD.43297663 (B)
IkarusTrojan-Downloader.Win32.Icedid
CyrenW32/Trojan.LKYF-3980
JiangminTrojan.Banker.Cridex.zp
MaxSecureTrojan.Malware.101975456.susgen
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Vigorf.A
AhnLab-V3Malware/Win32.Generic.C4120411
ZoneAlarmTrojan-Banker.Win32.Cridex.oan
VBA32TrojanBanker.Cridex
ALYacTrojan.IcedID.gen
TACHYONBanker/W32.Cridex.2422272
Ad-AwareTrojan.GenericKD.43297663
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
TencentWin32.Trojan-banker.Cridex.Ahyg
GDataTrojan.GenericKD.43297663
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.312

How to remove Trojan-Banker.Win32.Cridex.oan?

Trojan-Banker.Win32.Cridex.oan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment