Malware

Win32/Injector.CRDE removal

Malware Removal

The Win32/Injector.CRDE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.CRDE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:32767, 127.0.0.1:32768
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Queries information on disks, possibly for anti-virtualization
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.ipify.org
time-a.nist.gov

How to determine Win32/Injector.CRDE?


File Info:

crc32: 85313336
md5: b988afbb1df5f268d64a2ef604c92cdf
name: upload_file
sha1: b9320b32b14219e2829eaa6a69b046e6d68b39dd
sha256: dfb2cb14a2f6a3281514226cec06bb2bb99e9ebbeb583a9b6f80ec8b4d6fe15f
sha512: ff4d78db6deac88a8094e4921bc4c8bf8a245b97e4e7c2e3c6f9855b900f4f667980e4543ebb53842778405841e2b575d414c05bc893211c1555cc0cd64e51f5
ssdeep: 6144:D4fSYF93q3hpLdtWiUaMA4hcobyNZWBNsqMEu//h1p4RWGp7YWe7Ds5iuPX8:7gcXtZtchI4s1fpQE1Xs5rE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.CRDE also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
Qihoo-360Win32/Virus.NetTool.aae
McAfeeGenericATG-FCOY!B988AFBB1DF5
CylanceUnsafe
AegisLabRiskware.Win32.TorTool.1!c
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057214c1 )
K7AntiVirusTrojan ( 0057214c1 )
InvinceaMal/Generic-S (PUA)
SymantecML.Attribute.HighConfidence
APEXMalicious
Kasperskynot-a-virus:NetTool.Win32.TorTool.cpd
AlibabaNetTool:Win32/TorTool.f63c89a9
RisingTrojan.Generic@ML.100 (RDML:g4wf46faRZVtD2bNy2aUxg)
F-SecureTrojan.TR/Injector.oksyb
McAfee-GW-EditionBehavesLike.Win32.Sivis.gc
FireEyeGeneric.mg.b988afbb1df5f268
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
AviraTR/Injector.oksyb
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmnot-a-virus:NetTool.Win32.TorTool.cpd
GDataWin32.Trojan-Spy.Kronos.C9WTIC
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.EuW@aWRUugai
ESET-NOD32a variant of Win32/Injector.CRDE
TrendMicro-HouseCallTROJ_GEN.R002H0DJU20
TencentWin32.Trojan.Tortool.Pgwm
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.FCAB!tr
Cybereasonmalicious.2b1421
Paloaltogeneric.ml

How to remove Win32/Injector.CRDE?

Win32/Injector.CRDE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment