Malware

Mal/Generic-R + Troj/Dridex-ABY (file analysis)

Malware Removal

The Mal/Generic-R + Troj/Dridex-ABY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Dridex-ABY virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/Dridex-ABY?


File Info:

crc32: B04F0D62
md5: d49772c85d426ce5fe41cf8c5529a5ff
name: D49772C85D426CE5FE41CF8C5529A5FF.mlw
sha1: 4eaa4a005cd6825706634cf5fb9b95c4f546778e
sha256: 73541b82ca26c8c60a84354c657c42bd2ece5cfad3f49437a927b4265234b9da
sha512: ac76de00fd7f4cfaaac884990f02ff26883500d4a7c1c37e13a173de04b7228847527bca4737aa32e9498a05f473ac1a27ce98f35dead85fcc95e9c54efc924e
ssdeep: 12288:NdMIwS97wJs6tSKDXEabXaC+jhc1S8XXk7CZzHsZH9dq0TbEA:jMIJxSDX3bqjhcfHk7MzH6zn
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005 - 2009 Nir Sofer
InternalName: TeltwFoo
FileVersion: 9.74
CompanyName: NirSoft
ProductName: TeltwFoo
ProductVersion: 9.74
FileDescription: ProduKey
OriginalFilename: TeltwFoo.exe
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/Dridex-ABY also known as:

LionicTrojan.Win64.Injexa.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.15424
ClamAVWin.Packed.Dridex-9842637-1
CAT-QuickHealTrojan.Win64RI.S20908814
ALYacTrojan.GenericKDZ.75562
CylanceUnsafe
ZillyaTrojan.Injexa.Win64.129
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win64/Dridex.8c122b6c
K7GWTrojan ( 0057c4f81 )
K7AntiVirusTrojan ( 0057c4f81 )
CyrenW64/MSIL_Kryptik.ELJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.CJV
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin64:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win64.Injexa
BitDefenderTrojan.GenericKDZ.75562
ViRobotTrojan.Win32.Z.Dridex.1368064.D
MicroWorld-eScanTrojan.GenericKDZ.75562
TencentMalware.Win32.Gencirc.10ce569e
Ad-AwareTrojan.GenericKDZ.75562
SophosMal/Generic-R + Troj/Dridex-ABY
McAfee-GW-EditionBehavesLike.Win64.Drixed.tm
FireEyeGeneric.mg.d49772c85d426ce5
EmsisoftTrojan.GenericKDZ.75562 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injexa.hs
AviraHEUR/AGEN.1143679
Antiy-AVLTrojan/Generic.ASMalwS.3333576
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win64/Dridex.EF!MTB
GridinsoftTrojan.Win64.Kryptik.oa!s1
ArcabitTrojan.Generic.D1272A
GDataTrojan.GenericKDZ.75562
AhnLab-V3Trojan/Win.Generic.R426521
Acronissuspicious
McAfeeDrixed-FJX!D49772C85D42
MAXmalware (ai score=86)
VBA32Trojan.Win64.Dridex
MalwarebytesTrojan.Dridex
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DIP21
YandexTrojan.Kryptik!+iftt+1JHMo
IkarusTrojan.Win64.Dridex
MaxSecureBanker.Win64.Emotet.sb
FortinetW64/Kryptik.CJV!tr
AVGWin64:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Mal/Generic-R + Troj/Dridex-ABY?

Mal/Generic-R + Troj/Dridex-ABY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment