Trojan

Should I remove “Trojan-Downloader.Win32.Cridex.ren”?

Malware Removal

The Trojan-Downloader.Win32.Cridex.ren is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Cridex.ren virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the DridexV4 malware family

How to determine Trojan-Downloader.Win32.Cridex.ren?


File Info:

name: F7703084B13482C646F3.mlw
path: /opt/CAPEv2/storage/binaries/b98be8d2e7d160dacbd6cf682aa3fa9f0a0a68ae2d0f89b25376519f0883e495
crc32: E10EAA2C
md5: f7703084b13482c646f3851e18d8951a
sha1: 939ff0c3db869fa5656b6905f824fdb69050e43c
sha256: b98be8d2e7d160dacbd6cf682aa3fa9f0a0a68ae2d0f89b25376519f0883e495
sha512: 1c9e8a129bf0a634582343f14283d5bf152adc58f51230bf288482f49c5605c62b320ae1577571faf039a2b6c070985c251fa0f4a804e1dc98e287f087273498
ssdeep: 12288:o7fimEsIsmY4K08oM1Wd8t5KQhNdv5z0:o7aVRBn7x6jty
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1E8A4AF469D16A00DE80DA43DB24CB29AE9F862F7F57861F3542EB33E2DD30928F17459
sha3_384: 73decfcf4bed9bcdcc3fa99ee0091a580ac7ab06b5da3b73fa2e8b454ab0df11374507003a1249b31cc548fa3de5d4ae
ep_bytes: 40ba030000000fc2c80283c00c83c00c
timestamp: 2021-12-05 06:19:14

Version Info:

CompanyName: Oracle Corporation
FileDescription: Oracle Call Interface
FileVersion: 7.2.1.0.0
Legal Copyright: Copyright © Oracle Corporation 1979, 2001. All rights reserved.
OriginalFilename: Lov.dll
Translation: 0x0409 0x04b0

Trojan-Downloader.Win32.Cridex.ren also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cridex.a!c
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.829
MicroWorld-eScanTrojan.GenericKD.47579464
FireEyeGeneric.mg.f7703084b13482c6
McAfeeDrixed-FJX!F7703084B134
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Cridex.b966fd30
K7GWTrojan ( 0058b7b31 )
K7AntiVirusTrojan ( 0058b7b31 )
BitDefenderThetaGen:NN.ZedlaF.34114.Du8@aubnjJli
CyrenW32/Kryptik.FXC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNRW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Cridex.ren
BitDefenderTrojan.GenericKD.47579464
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.11dcee1b
Ad-AwareTrojan.GenericKD.47579464
TACHYONTrojan-Downloader/W32.Cridex.487424.G
SophosMal/Generic-R + Troj/Loskop-B
ZillyaTrojan.Kryptik.Win32.3641524
TrendMicroTrojanSpy.Win32.DRIDEX.YXBLGZ
McAfee-GW-EditionDrixed-FJX!F7703084B134
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47579464
JiangminTrojan.Multi.fup
AviraTR/Crypt.Agent.isixz
Antiy-AVLTrojan/Generic.ASMalwS.34E67DA
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2D60148
MicrosoftTrojan:Win32/Dridex.CE!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.FJX.R456534
ALYacTrojan.GenericKD.47579464
MAXmalware (ai score=88)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Dridex
TrendMicro-HouseCallTrojanSpy.Win32.DRIDEX.YXBLGZ
YandexTrojan.DL.Cridex!murxyWFY7+o
IkarusTrojan.Agent
MaxSecureTrojan.Malware.74599959.susgen
FortinetW32/Drixed.FJX!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan-Downloader.Win32.Cridex.ren?

Trojan-Downloader.Win32.Cridex.ren removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment