Trojan

About “Trojan:Win64/Cridex.DA!MTB” infection

Malware Removal

The Trojan:Win64/Cridex.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Cridex.DA!MTB virus can do?

  • Unconventionial language used in binary resources: Korean
  • Anomalous binary characteristics

How to determine Trojan:Win64/Cridex.DA!MTB?


File Info:

crc32: 166570E3
md5: 3b3d425463a5ba2a67aaa0f771ed9d63
name: 3B3D425463A5BA2A67AAA0F771ED9D63.mlw
sha1: 3caa887652c79ebe1aa18eb51e07e801b7bf9bd5
sha256: e42bf6699c3a23b2076edeac9fa738142319bebb2cd60fd9fe5701d62ba69cfb
sha512: 1406570d260ae1173f614529a50ac97dc031b1dd7bc04360c44dfb4db0dd547f631fae7579016aa15f79466692baaeb02b556ca342eea2fc79fdece5ec5292d8
ssdeep: 12288:QzgwMY/i+zimmG/4Xk+dRUX3eM5Cbxf2/:QzLMY/i+OuwXlnUnebh2
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright 2001 Wizet, ZMS
InternalName: Canvas
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Canvas Module
OLESelfRegister:
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: Canvas Module
OriginalFilename: Canvas.DLL
Translation: 0x0409 0x04b0

Trojan:Win64/Cridex.DA!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.17524
CynetMalicious (score: 100)
ALYacGen:Variant.Mikey.117894
ZillyaTrojan.Emotet.Win64.54
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW64/Trojan.FPD.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.BLQ
APEXMalicious
AvastWin64:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mikey.117894
MicroWorld-eScanGen:Variant.Mikey.117894
TencentMalware.Win32.Gencirc.10b5745d
Ad-AwareGen:Variant.Mikey.117894
SophosML/PE-A + Troj/Dridex-ABY
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY64_HPDRIDEX.SM1
McAfee-GW-EditionBehavesLike.Win64.Drixed.jh
FireEyeGeneric.mg.3b3d425463a5ba2a
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.eevvg
WebrootW32.Trojan.Dridex
AviraHEUR/AGEN.1134838
Antiy-AVLTrojan/Generic.ASMalwS.295BCFF
MicrosoftTrojan:Win64/Cridex.DA!MTB
GDataGen:Variant.Mikey.117894
Acronissuspicious
McAfeeGenericRXAA-AA!3B3D425463A5
MAXmalware (ai score=86)
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTSPY64_HPDRIDEX.SM1
YandexTrojan.GenAsa!li4JMqMpfNA
IkarusTrojan.Win64.Dridex
MaxSecureBanker.Win64.Emotet.sb
FortinetW64/Dridex.ABT!tr
AVGWin64:Malware-gen
Qihoo-360Win64/Trojan.Dridex.H8sASu8A

How to remove Trojan:Win64/Cridex.DA!MTB?

Trojan:Win64/Cridex.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment