Trojan

About “Trojan-Banker.Win32.Cridex.obk” infection

Malware Removal

The Trojan-Banker.Win32.Cridex.obk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.obk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Cridex.obk?


File Info:

crc32: A041E5E4
md5: 8e8bff959b3113eb15e93d82f13060cf
name: tmp792ykwa7
sha1: 9d87e2d17b4ffcd3634191c2b1e37afd157da576
sha256: 2c61bfc837090878f72a5336ebdd018d3aaf5cac7a4d4f71fbd89f54a74599d5
sha512: 074a94e81114a73e205ea0412c6ce718dda2b59b26d3234c262127ba304f631812fbec96594584acbe92f61a2964573b2d1c3edd4612b035ea1f36f0717a551b
ssdeep: 12288:BUeVJlfbhJTd58Sizh5uzMIts6DDt9USu0NMfMtQ:FJTdKSqGsQt2WNMM
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: RoseThose xa9 2017
InternalName: Art woman
FileVersion: 2.1.3.996
CompanyName: Win ToCase
ProductName: Horse.dll
ProductVersion: 2.1.3.996
FileDescription: RoseThose
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Cridex.obk also known as:

MicroWorld-eScanGen:Variant.Zusy.305852
FireEyeGeneric.mg.8e8bff959b3113eb
McAfeeGenericRXKY-JQ!8E8BFF959B31
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Zusy.305852
K7GWTrojan ( 005669021 )
K7AntiVirusTrojan ( 005669021 )
BitDefenderThetaGen:NN.ZedlaF.34128.Eu8@aOuyBrii
CyrenW32/S-50dbd228!Eldorado
AvastWin32:Trojan-gen
GDataGen:Variant.Zusy.305852
KasperskyTrojan-Banker.Win32.Cridex.obk
TencentMalware.Win32.Gencirc.10cdd2f1
Ad-AwareGen:Variant.Zusy.305852
SophosTroj/Agent-BESY
ComodoTrojWare.Win32.Kryptik.HACE@8so3pu
F-SecureTrojan.TR/Kryptik.vxpvh
McAfee-GW-EditionGenericRXKY-JQ!8E8BFF959B31
EmsisoftGen:Variant.Zusy.305852 (B)
IkarusTrojan.Win32.Krypt
F-ProtW32/S-50dbd228!Eldorado
JiangminTrojan.Banker.Cridex.zq
AviraTR/Kryptik.vxpvh
MAXmalware (ai score=82)
Antiy-AVLTrojan[Banker]/Win32.Cridex
ArcabitTrojan.Zusy.D4AABC
ZoneAlarmTrojan-Banker.Win32.Cridex.obk
MicrosoftTrojan:Win32/Zloader.ARJ!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.C4117784
VBA32TrojanBanker.Cridex
ALYacGen:Variant.Zusy.305852
MalwarebytesTrojan.Crypt
ESET-NOD32a variant of Win32/Kryptik.HDZG
RisingTrojan.GenKryptik!8.AA55 (C64:YzY0OrmWw1Wdh5Rj)
YandexTrojan.GenKryptik!
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.BEVR!tr
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM40.1.EC52.Malware.Gen

How to remove Trojan-Banker.Win32.Cridex.obk?

Trojan-Banker.Win32.Cridex.obk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment