Trojan

Trojan-Downloader.Win32.Cridex.hga removal instruction

Malware Removal

The Trojan-Downloader.Win32.Cridex.hga is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Cridex.hga virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Cridex.hga?


File Info:

crc32: 6265B3AA
md5: 745251686380dcab3f59bc08dd22c104
name: 745251686380DCAB3F59BC08DD22C104.mlw
sha1: 1c24a87c82382aab87ffc88a869ceecebcac5b02
sha256: 45da19876d2355ab3cebec09738fc13bab1fca26fe06f7fef4f506505124ecd8
sha512: ff9027e7fb759c7e020086428eb55c394aa8f9845f54969cedfaee09c38b6ceb09f784d9fe07c978317f64c8a273b63fbb7ed64250d34bdf9319e8c064d081c2
ssdeep: 12288:eGTOGQ7DstX8FM9zxh/d/GMqLTXRxgGAyfndmLBK:Slsx8FMhReMqLzRxuem9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: lpksetip
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Language Pack ikstaller
OriginalFilename: lpksetip.exe
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Cridex.hga also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35532013
FireEyeGeneric.mg.745251686380dcab
ALYacTrojan.GenericKD.35532013
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35532013
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Downloader.Win32.Cridex.hga
AegisLabHacktool.Win32.Krap.lKMc
Ad-AwareTrojan.GenericKD.35532013
EmsisoftTrojan.GenericKD.35532013 (B)
F-SecureTrojan.TR/Crypt.Agent.hvgse
DrWebTrojan.Dridex.735
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.hvgse
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Generic.D21E2CED
ZoneAlarmTrojan-Downloader.Win32.Cridex.hga
GDataTrojan.GenericKD.35532013
CynetMalicious (score: 100)
McAfeePacked-GCB!745251686380
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.Dridex
PandaTrj/Agent.PM
ESET-NOD32a variant of Win32/Kryptik.HHZA
RisingTrojan.Ymacco!8.11BE1 (TFE:2:XnQ5bFFXdkF)
SentinelOneStatic AI – Malicious PE
FortinetW32/Cridex.HTH!tr
BitDefenderThetaGen:NN.ZedlaF.34670.zy8@aWywVwmi
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.AF87.Malware.Gen

How to remove Trojan-Downloader.Win32.Cridex.hga?

Trojan-Downloader.Win32.Cridex.hga removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment