Trojan

Trojan:Win32/Cridex!MTB removal guide

Malware Removal

The Trojan:Win32/Cridex!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Cridex!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates

Related domains:

support.oracle.com
www.intel.com
gegemony4you.top
help.twitter.com
support.apple.com

How to determine Trojan:Win32/Cridex!MTB?


File Info:

crc32: EB6B933D
md5: 5009b8bcf024704c8b23e42c492f118c
name: bussines.exe
sha1: df607367a88b5610a224909efb8debeb0d90f487
sha256: 30f099660904079afcd445409cfd2eca735fab49dda522f03ed60d47f9f21bdc
sha512: 70c4d7c6b9124246def27e28b69f2eb30bac85a5c0e8b38cf593222bec02c561143ebf0995946d1c30ef5441a6152cf587ef2d70651482374017a321df1c8e3b
ssdeep: 49152:o8X7Gl0vopNbyrbGhp475YHHmfjlzukdQ+ILi2k4TmRB:Z4Gopkrbk4UHmfhzukfILi2k4Tm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Column tell Corporation. All rights reserved.
InternalName: arra.exe
FileVersion: 10.7.14.75 built by: 39959
CompanyName: Column tell Corporation
ProductName: Column tell xaeColumn tell xae 2014
ProductVersion: 10.7.14.75
FileDescription: Column tell Nine in
OriginalFilename: arra.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Cridex!MTB also known as:

DrWebTrojan.IcedID.27
MicroWorld-eScanTrojan.Agent.ERSF
FireEyeTrojan.Agent.ERSF
VIPREWin32.Malware!Drop
SangforMalware
K7AntiVirusTrojan ( 00567dac1 )
BitDefenderTrojan.Agent.ERSF
K7GWTrojan ( 00567dac1 )
BitDefenderThetaGen:NN.ZexaF.34122.cI0@a8MCeMai
CyrenW32/Trojan.NEPY-8655
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_FRS.VSNTF220
GDataTrojan.Agent.ERSF
KasperskyTrojan-Banker.Win32.Cridex.noh
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareTrojan.Agent.ERSF
SophosTroj/Keylog-AJN
TrendMicroTROJ_FRS.VSNTF220
EmsisoftTrojan.Agent.ERSF (B)
IkarusTrojan-Downloader.Win32.Icedid
WebrootW32.Malware.Gen
MAXmalware (ai score=99)
ArcabitTrojan.Agent.ERSF
ZoneAlarmTrojan-Banker.Win32.Cridex.noh
MicrosoftTrojan:Win32/Cridex!MTB
ALYacTrojan.IcedID.gen
ESET-NOD32a variant of Generik.CUCERQS
RisingMalware.Undefined!8.C (CLOUD)
FortinetW32/Generik.CUCERQS!tr
AVGFileRepMalware

How to remove Trojan:Win32/Cridex!MTB?

Trojan:Win32/Cridex!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment