Trojan

Trojan-Downloader.Win32.Cridex.gva removal tips

Malware Removal

The Trojan-Downloader.Win32.Cridex.gva is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Cridex.gva virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Cridex.gva?


File Info:

crc32: 2A6DB884
md5: 4fa396905538cf2975dda3aee5c466a4
name: upload_file
sha1: b2f19c153b41ad9969dbfd9ed0a0b46b1330a7ff
sha256: abc00bed0b42c8f67a598d1f858dd33e112ff04e0addfbf8f6f554a6b6eee54c
sha512: fe033ad226084599ec961a4f8342e386990457eb3c3ff21dd88f58c98762cf7e0cb1ccc2321a4afa61aaecb735e6f1922354a7a813167793a459ad63a1c2b666
ssdeep: 6144:1xI2j28bm2WJHEII+buAqQxZt4995XkN6y1Ya5PDlHPspG:eRJku/L05dyVrvn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2007 by Don HO
InternalName: gup.exe
FileVersion: 4.1
CompanyName: Don HO don.h@free.fr
ProductName: GUP
ProductVersion: 4.1
FileDescription: GUP : a free (LGPL) Generic ipdater
OriginalFilename: gup.exe
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Cridex.gva also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44185682
FireEyeGeneric.mg.4fa396905538cf29
CAT-QuickHealTrojandownloader.Cridex
McAfeeRDN/none
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.44185682
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan-Downloader.Win32.Cridex.gva
AlibabaTrojanDownloader:Win32/Cridex.4b97dbe0
ViRobotTrojan.Win32.Z.Shade.397824
RisingTrojan.Generic@ML.99 (RDML:m76DKqv5Y4f1JOzeQyaNSw)
Ad-AwareTrojan.GenericKD.44185682
ComodoMalware@#1hwngui47p3cl
MaxSecureTrojan.Malware.108997572.susgen
DrWebTrojan.Dridex.735
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionRDN/none
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
WebrootW32.Trojan.Dridex
AviraTR/AD.Dridex.wqrhu
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Ymacco.AAAB
ArcabitTrojan.Generic.D2A23852
ZoneAlarmTrojan-Downloader.Win32.Cridex.gva
GDataTrojan.GenericKD.44185682
VBA32BScope.TrojanRansom.Shade
ALYacTrojan.GenericKD.34863700
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HGZC
TencentWin32.Trojan-downloader.Cridex.Phgt
IkarusTrojan.SuspectCRC
FortinetW32/Cridex.GVA!tr.dldr
BitDefenderThetaGen:NN.ZedlaF.34590.yu8@a8DCpAji
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Downloader.ddd

How to remove Trojan-Downloader.Win32.Cridex.gva?

Trojan-Downloader.Win32.Cridex.gva removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment