Malware

Troj/Dridex-AII (file analysis)

Malware Removal

The Troj/Dridex-AII is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Dridex-AII virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Troj/Dridex-AII?


File Info:

crc32: BF2CEDAC
md5: 33ff391082cedc51e94a9894dcc0b0ea
name: 33FF391082CEDC51E94A9894DCC0B0EA.mlw
sha1: c07ec046207792071f2dec8a840a815e24bcf119
sha256: ca58532d61b29179bdb4d768eac6e6f8bafc51b287551175e8939cccce374646
sha512: 2c1695f85183d1cbe12446dbcdb44a9a30791b1e9e46dd15686f91bcba8b20dc972aadc50724fea412b5cbc3691726b2f56f7eb40c9de64e09f856cbc67c7d73
ssdeep: 12288:BVI0W/TtlPLfJCm3WIYxJ9yK5IQ9PElOlidGAWilgm5Qq0nB6wtt4AenZ1:wfP7fWsK5z9A+WGAW+V5SB6Ct4bnb
type: PE32+ executable (DLL) (console) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserv
InternalName: bitsp
FileVersion: 7.5.7600.16385 (win7_rtm.090713-
CompanyName: Microsoft Corporati
ProductName: Microsoftxae Windowsxae Operating S
ProductVersion: 6.1.7600
FileDescription: Background Intellig
OriginalFilename: kbdy
Translation: 0x0409 0x04b0

Troj/Dridex-AII also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43395
ClamAVWin.Packed.Razy-9769561-0
ALYacTrojan.GenericKDZ.76753
CylanceUnsafe
ZillyaTrojan.Injexa.Win64.17
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005601a91 )
K7AntiVirusTrojan ( 005601a91 )
CyrenW64/S-9d36de06!Eldorado
ESET-NOD32a variant of Win64/Kryptik.BWL
APEXMalicious
AvastWin64:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win64.Occamy.pef
BitDefenderTrojan.GenericKDZ.76753
MicroWorld-eScanTrojan.GenericKDZ.76753
TencentMalware.Win32.Gencirc.10b8f418
Ad-AwareTrojan.GenericKDZ.76753
SophosTroj/Dridex-AII
TrendMicroTrojanSpy.Win64.DRIDEX.SMF
McAfee-GW-EditionBehavesLike.Win64.Drixed.tz
FireEyeGeneric.mg.33ff391082cedc51
EmsisoftTrojan.GenericKDZ.76753 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injexa.s
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.30014E7
MicrosoftTrojan:Win64/Dridex.DK!MTB
GridinsoftTrojan.Win64.Banker.oa!s1
ArcabitTrojan.Generic.D12BD1
GDataTrojan.GenericKDZ.76753
AhnLab-V3Malware/Win64.RL_Trojanspy.R328983
Acronissuspicious
McAfeeDrixed-FIC!33FF391082CE
MAXmalware (ai score=88)
VBA32Trojan.Win64.Dridex
MalwarebytesBackdoor.Qbot
TrendMicro-HouseCallTrojanSpy.Win64.DRIDEX.SMF
RisingTrojan.Kryptik/x64!1.D984 (CLASSIC)
YandexTrojan.GenAsa!RYtjI3PRurw
IkarusTrojan.Win64.Dridex
MaxSecureBanker.Win64.Emotet.sb
FortinetW64/Kryptik.CBK!tr
AVGWin64:BankerX-gen [Trj]

How to remove Troj/Dridex-AII?

Troj/Dridex-AII removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment