Trojan

Should I remove “VHO:Trojan-Downloader.Win32.Cridex”?

Malware Removal

The VHO:Trojan-Downloader.Win32.Cridex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Downloader.Win32.Cridex virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Collects information about installed applications
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine VHO:Trojan-Downloader.Win32.Cridex?


File Info:

crc32: 28CFEBF2
md5: a9061ada7e7f9927090e10b5dbf31c38
name: A9061ADA7E7F9927090E10B5DBF31C38.mlw
sha1: 9a1bf454713bff1a4a950d496f7a562d99a66c30
sha256: c99b4a39f1f0eed0b89576edc9d847c300ab9377ccb1891f8634f9a195222821
sha512: 7592651bfa304ce92b8adcc01ce2e4ad6d84bf53879d58457288c60d035f2f7cd89e40fdad471c3066b3f963724fe3c648075c4eb10b5e468a37f03a7668ad11
ssdeep: 6144:VK6cyPiWCgknQ/HuyIzuTVzsMM56519p+6yTrkGxM2QDP/ly+VQyMJ8+vp:VM+ZdkmHubeaCo6ak72A/sUQBJ8+vp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012
InternalName: Java(TM) Web Start Launcher
FileVersion: 10.4.0.20
Full Version: 10.4.0.20
CompanyName: Oracle Corporation
ProductName: Java(TM) Platform SE 7 U4
ProductVersion: 7.0.40.20
FileDescription: Java(TM) Web Start Launcher
OriginalFilename: javaws.exe
Translation: 0x0000 0x04b0

VHO:Trojan-Downloader.Win32.Cridex also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.735
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.76770
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.4713bf
CyrenW32/Kryptik.EVP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLXO
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Genkryptik-9883301-0
KasperskyVHO:Trojan-Downloader.Win32.Cridex.gen
BitDefenderTrojan.GenericKDZ.76770
MicroWorld-eScanTrojan.GenericKDZ.76770
Ad-AwareTrojan.GenericKDZ.76770
SophosML/PE-A + Mal/EncPk-APV
BitDefenderThetaGen:NN.ZexaF.34058.fL0@ay0mgIni
VIPRETrojan.Win32.Generic.pak!cobra
FireEyeGeneric.mg.a9061ada7e7f9927
EmsisoftTrojan.GenericKDZ.76770 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3444218
MicrosoftTrojan:Win32/Dridex!ml
GDataTrojan.GenericKDZ.76770
AhnLab-V3Trojan/Win.QakBot.R435578
McAfeeGenericRXAA-AA!A9061ADA7E7F
MAXmalware (ai score=88)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.Dridex
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.CD27 (CLASSIC)
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.FHRA!tr
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM20.1.17FB.Malware.Gen

How to remove VHO:Trojan-Downloader.Win32.Cridex?

VHO:Trojan-Downloader.Win32.Cridex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment