Trojan

Trojan:Win32/Cridex.GC!MTB removal guide

Malware Removal

The Trojan:Win32/Cridex.GC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cridex.GC!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Cridex.GC!MTB?


File Info:

crc32: F9C00CBE
md5: 08e7d64528c8d35fc423ec203fd0c137
name: upload_file
sha1: dbb4431822202d599f4d41e843ea1dbf2e02fbc1
sha256: c20ae8eb0c628595af2c957c19f3764f31f992523ec659a7caabe3fa589b6494
sha512: 56cb70099b10abbeba5f133d11ddbfb42b673fd36b2fde92cdeed643fd5ddde97f7228f62b45c6cc94c2876a96c2306e21c3c8d3b03d85ec4e49e396120f3fb7
ssdeep: 3072:kjY9xJ5k3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3veJ:f9DeCBa1kf0S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: wmlaunch.exe
FileVersion: 11.0.5721.5262 (WMP_11.090130-1421)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 11.0.5721.5262
FileDescription: Windows Media Player Launcher
OriginalFilename: wmlaunch.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Cridex.GC!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.725518
FireEyeGeneric.mg.08e7d64528c8d35f
Qihoo-360HEUR/QVM20.1.E5DC.Malware.Gen
McAfeePacked-GBS!08E7D64528C8
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005652be1 )
BitDefenderGen:Variant.Razy.725518
K7GWTrojan ( 005652be1 )
Cybereasonmalicious.822202
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
RisingTrojan.Kryptik!1.C974 (RDMK:cmRtazrQ+ok7SCwkZ0d1eBusFxNb)
Ad-AwareGen:Variant.Razy.725518
EmsisoftGen:Variant.Razy.725518 (B)
Invinceaheuristic
SophosMal/EncPk-APV
IkarusTrojan-Spy.Agent
FortinetW32/Cridex.VHO!tr
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Razy.DB120E
MicrosoftTrojan:Win32/Cridex.GC!MTB
BitDefenderThetaGen:NN.ZexaF.34138.kr1@aqcT4Rbi
ALYacGen:Variant.Razy.725518
MAXmalware (ai score=87)
VBA32BScope.Trojan.Inject
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EPEX
SentinelOneDFI – Malicious PE
GDataGen:Variant.Razy.725518
AVGWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Cridex.GC!MTB?

Trojan:Win32/Cridex.GC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment