Trojan

About “Trojan-Banker.Win32.Cridex.pef” infection

Malware Removal

The Trojan-Banker.Win32.Cridex.pef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Cridex.pef virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:443
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Banker.Win32.Cridex.pef?


File Info:

crc32: 4ED5428C
md5: 84cf069cc818b14d2f03f9c8d657f027
name: 84CF069CC818B14D2F03F9C8D657F027.mlw
sha1: b9712bcdf37f59916194e18059fa464bd157144c
sha256: eb325197613121baf63b8891870dbe2eb71d33eaf6952769d482acfa24584a62
sha512: a2cd83f9de521726e61ab87468f0371245cc010a5106bf21885c31cc064e31fb71749aab332f20265c15730600506f556c58d897b7ab233cd851116cf8002e31
ssdeep: 24576:CNzyRpXCppgDXcz1fKKsADCV4a6gj7brUU0:CN+Wacz1fAADO4a6GH
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Cridex.pef also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70356
FireEyeGeneric.mg.84cf069cc818b14d
ALYacTrojan.GenericKDZ.70356
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKDZ.70356
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.CAX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Packed.Generickdz-9771649-0
KasperskyHEUR:Trojan-Banker.Win32.Cridex.pef
NANO-AntivirusTrojan.Win32.Cridex.hxgjes
Ad-AwareTrojan.GenericKDZ.70356
TACHYONBanker/W32.Cridex.831488
EmsisoftTrojan.GenericKDZ.70356 (B)
F-SecureHeuristic.HEUR/AGEN.1138986
InvinceaML/PE-A + Troj/Dridex-ADD
McAfee-GW-EditionBehavesLike.Win32.Drixed.cc
SophosTroj/Dridex-ADD
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.Cridex.aij
AviraHEUR/AGEN.1138986
MicrosoftTrojan:Win32/Cridex.RB!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s2
ArcabitTrojan.Generic.D112D4
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.pef
GDataTrojan.GenericKDZ.70356
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Drixed.R352218
Acronissuspicious
McAfeeTrojan-FRGC!84CF069CC818
MAXmalware (ai score=84)
MalwarebytesTrojan.Banker
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HGIV
RisingTrojan.Kryptik!8.8 (TFE:1:7xfOIhEbMtB)
SentinelOneStatic AI – Malicious PE
MaxSecureBanker.Win64.Emotet.sb
FortinetW32/Kryptik.HGIV!tr
BitDefenderThetaGen:NN.ZedlaF.34634.YS4@aC3@aGni
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM39.1.3A86.Malware.Gen

How to remove Trojan-Banker.Win32.Cridex.pef?

Trojan-Banker.Win32.Cridex.pef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment