Trojan

What is “Trojan-Downloader.Win32.Cridex.hdk”?

Malware Removal

The Trojan-Downloader.Win32.Cridex.hdk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Cridex.hdk virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Downloader.Win32.Cridex.hdk?


File Info:

crc32: 84706238
md5: 457a2d0c13db31222c66c3e623d88063
name: 457A2D0C13DB31222C66C3E623D88063.mlw
sha1: 15bd1122fe1a910c3b8f255bbe74de5ffed57fd2
sha256: a1658b979357f174c83dcd9867941d8cd917beb3ea67720fa43b6340b27762ba
sha512: 5eeb2bfcfedd0703134196a3135bba5bbc59d67ab51bc847c837e4243c1c1a7fa1971a5602af5f6d946ef1a0f5c5f5f1f1807fa5e5d6dc723b6d5888336875c3
ssdeep: 6144:xPu6XDv7Hzfr3jPbn8YUwsIEgc40Q1xNJlh95VRtpFKeiW6OSGq+C2a/D3bvznL:8dee883YdbY+5QyTE1PMMa+
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 2005-2015
InternalName:
FileVersion: 1.0.0.634
CompanyName: IObit
LegalTrademarks: IObit
Comments:
ProductName: Display
ProductVersion: 2.0.0.0
FileDescription: Advanced SystemCare Display
OriginalFilename:
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Cridex.hdk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.457a2d0c13db3122
ALYacSpyware.Banker.Dridex
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005739f41 )
K7AntiVirusTrojan ( 005739f41 )
BitDefenderThetaGen:NN.ZedlaF.34658.wy8@amkQQxnj
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Cridex.hdk
AlibabaTrojan:Win32/Kryptik.0f13c385
AegisLabHacktool.Win32.Krap.lKMc
SophosMal/Generic-S
ComodoTrojWare.Win32.Genome.zknzw@0
F-SecureTrojan.TR/Crypt.Agent.bflkt
DrWebTrojan.Dridex.735
TrendMicroTrojan.Win32.MALREP.THKBFBO
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
EmsisoftTrojan.Cridex (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.bflkt
Antiy-AVLGrayWare/Win32.Kryptik.ehls
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Heur!.03012020
ZoneAlarmTrojan-Downloader.Win32.Cridex.hdk
GDataWin32.Trojan-Downloader.Dridex.IT73GL
CynetMalicious (score: 100)
McAfeeRDN/GenericM
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesPUP.Optional.AdvancedSystemCare
ESET-NOD32Win32/Dridex.DD
TrendMicro-HouseCallTrojan.Win32.MALREP.THKBFBO
RisingTrojan.Kryptik!8.8 (TFE:5:JnXtHsfHJMO)
IkarusTrojan-Proxy.Agent
eGambitUnsafe.AI_Score_60%
FortinetW32/Kryptik.HHRQ!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
Qihoo-360Generic/HEUR/QVM39.1.84CF.Malware.Gen

How to remove Trojan-Downloader.Win32.Cridex.hdk?

Trojan-Downloader.Win32.Cridex.hdk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment