Threat Database Trojans Trojan.Cridex.NC

Trojan.Cridex.NC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,340
Threat Level: 80 % (High)
Infected Computers: 25
First Seen: October 11, 2021
Last Seen: May 16, 2026
OS(es) Affected: Windows

The detection of Trojan.Cridex.NC on your system indicates a potential security threat that requires immediate attention. This malware is designed to compromise your computer's security and potentially steal sensitive information or disrupt its operation. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Cridex.NC?

Trojan.Cridex.NC is a type of malware that can infect your computer through various means, such as opening malicious email attachments, visiting compromised websites, or downloading infected software. Once installed, it can hide itself and operate stealthily, making it challenging to detect without proper security tools. The name Trojan.Cridex.NC suggests it may be related to a broader category of Trojan malware, but the specifics of its operation and impact can vary.

How Trojan.Cridex.NC Operates

Trojan malware, in general, operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can create backdoors for remote access, allowing attackers to control the infected computer, steal data, or use it for malicious activities like spreading spam or participating in botnets. The exact mechanisms used by Trojan.Cridex.NC may include modifying system settings, hiding files, or intercepting network communications, but these details can vary based on the specific implementation and goals of the malware authors.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms may include unexpected changes in system behavior, such as unusual pop-ups, slow performance, or frequent crashes. You might also notice unauthorized access to your personal data or unexpected network activity. Since Trojans can manifest in many ways, any unusual computer behavior should be investigated promptly.

How to Remove Trojan.Cridex.NC

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove Trojan.Cridex.NC and other potential threats.
  3. Manually uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

Removing Trojan.Cridex.NC from your computer requires careful and thorough action to ensure all components of the malware are eliminated. By following the steps outlined above and maintaining vigilance in your online activities, you can help protect your computer and personal data from future malware infections. Regularly updating your operating system, using strong antivirus software, and being cautious with emails and downloads are crucial steps in preventing such infections. If you are unsure about any part of the removal process, consider seeking help from a professional to ensure your system is completely clean and secure.

Analysis Report

General information

Family Name: Trojan.Cridex.NC
Packers: UPX
Signature status: Modified signature

Known Samples

MD5: b5084c78fbbb33d8d43d86d04d3d6aea
SHA1: 4f0768eb39efc1d6d4f511e3ac3071dc0f84d395
SHA256: 97DE0CFA9F1E4A5E1296123492BE9AA0E0C66BEECE246BE84A163550D15798BC
File Size: 613.19 KB, 613192 bytes
MD5: e4d06aebf82616516ae5e90548a35744
SHA1: c666e1ed5427962977e8ba669a3a9c1e3e0db0de
SHA256: D4828307FE93D7035F324212FF4637891D87903886EFE7ED7E7FF5F8D2C6235A
File Size: 613.20 KB, 613200 bytes
MD5: 2468e70764149e4254c42b17105e4cb3
SHA1: 26dafcd72829c0d627873a240b2f90b6534714c1
SHA256: E3F8E92FEEB7FA8B0A78F1B98C732815A6F979A7AA856290AEB39A931840D20E
File Size: 613.19 KB, 613192 bytes
MD5: d49760955ec995c4a464795886ca7981
SHA1: 505e13eb0e88f0a89cdec1f800bafadc4673959b
SHA256: 0EE8E37D7A82F70FF7F1E987E13590B6F4339C1EDC174A0F89148E0A2B53EA89
File Size: 613.20 KB, 613200 bytes
MD5: 413b7b1e4b8f2c8d5cf9d1bf763a7898
SHA1: 6da5c6facd0f56f90a9fbb8b6a752738506f74d6
SHA256: 0920AFD6ED890EFE8491BD33508239AC3486973E9D22F6020900D78AE7B3B0C9
File Size: 613.20 KB, 613200 bytes
Show More
MD5: b63476e3dd8723bf788e62de471feafd
SHA1: c5c35f2e8225ac4b7c9e7255c82845a393c3b6c5
SHA256: E9A3A3CFBB2DC5CD98089B439E03E35D389570DF89A172D1E11A926F1B4F08A5
File Size: 613.19 KB, 613192 bytes
MD5: e7318fe27b5f0e37610c7f5ecf24203d
SHA1: 83b522eb9c9796496bf2e39474d2dc4aa7e2585c
SHA256: 47680D4D47D6B8E93D10E5A88DA5C31FBFC85E541A2472307904AD69F51F3E35
File Size: 613.19 KB, 613192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Reason Software Company Inc.
File Description Reason Antivirus Installer
File Version
  • 1.0.0.34
  • 1.0.0.12
  • 1.0.0.6
Legal Copyright Copyright Reason Software Company Inc.
Original Filename master-502902f-ReasonAntivirusInstallerStub.exe
Product Name Reason Antivirus
Product Version
  • 1.0.0.34
  • 1.0.0.12
  • 1.0.0.6

File Traits

  • HighEntropy
  • Installer Version
  • packed
  • x86

Block Information

Total Blocks: 6,664
Potentially Malicious Blocks: 139
Whitelisted Blocks: 6,369
Unknown Blocks: 156

Visual Map

x x 0 0 ? 0 0 0 0 0 x 0 x 0 0 ? x 0 0 0 x 0 ? ? x 0 0 ? 0 0 0 0 0 0 0 0 x 0 ? ? ? x x ? 0 0 x x x x 0 0 0 x x x x x x x x 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 x 0 0 ? ? 0 0 0 0 0 0 0 0 0 x x x 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x ? x 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 ? 0 0 ? x 0 0 ? 0 x 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 1 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? 0 0 ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 x x 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? 0 ? x x ? x 0 ? ? 0 0 ? x x x x x 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 ? 0 x x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 ? ? x 0 ? ? ? 0 x x ? 0 ? ? x x x x ? x ? ? x x 0 x x ? x 0 0 0 0 0 0 ? 0 x x ? ? ? ? ? 0 x ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 x x ? 0 0 ? ? 0 0 x ? x ? 0 0 0 ? ? 0 0 0 ? x 0 ? 0 0 0 0 ? 0 ? ? 0 0 0 0 ? ? 0 0 0 ? 0 ? x 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x x 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 x x 0 0 x 0 x x 0 x 0 0 0 0 0 x 0 x x x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 x x x x 0 0 x x 0 0 0 0 x x 0 0 x 0 0 x x x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • ByteFence.A
  • Cridex.NC

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • getaddrinfo
  • socket
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Trending

Most Viewed

Loading...