Trojan

Trojan.Redosdru malicious file

Malware Removal

The Trojan.Redosdru is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Redosdru virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Redosdru?


File Info:

name: BFCFAA20850E9891B543.mlw
path: /opt/CAPEv2/storage/binaries/02df20704791ed523be1e86d079200415c852094f4ead176e8c51bf968f04fb0
crc32: 18EEC29C
md5: bfcfaa20850e9891b5439e5fc6699ff1
sha1: 495abe24d244b829650bf2c63ad4ac0c203b562b
sha256: 02df20704791ed523be1e86d079200415c852094f4ead176e8c51bf968f04fb0
sha512: e50c946129e7dc39bbf85ba9fe0b2ffe7bff540ead25c21c72b71898859ec02bdd4f7fff559c3b9baf9cae8b149a2fed4d9608e052e2b503a390db2862888288
ssdeep: 24576:kthyLwtOMYxUZq1BCX7sE068zE1/NbRINd/jiCHJmiLRCYzPN/nm8VysAls5xPEA:kthSB68zAxcfUiLRTAZvZqIzfZy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD958E62B7915476C02316785D3B57A9A939BF002F38A9C77BF06E4C6E363C07939293
sha3_384: ed8211acc265128469a86613066e5d81fc9027333262b20388fe24e8cde6879687ec5db31911e03de9034dc392cf6f9c
ep_bytes: 558bec83c4f053b838a04800e8ffb8f7
timestamp: 2011-06-27 08:23:03

Version Info:

0: [No Data]

Trojan.Redosdru also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Bifrost.15005
McAfeeArtemis!BFCFAA20850E
CylanceUnsafe
SangforSuspicious.Win32.Evo.atgen
AlibabaAdWare:Win32/DRMSoft.00ac6403
K7GWTrojan ( 004b94301 )
K7AntiVirusTrojan ( 004b94301 )
CyrenW32/Trojan.DD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.DRMSoft.B suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CKD21
Paloaltogeneric.ml
ClamAVWin.Trojan.Bifrose-17928
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Bifrost.dnmhjg
AvastWin32:Malware-gen
ComodoMalware@#1a8msnh4p37oz
McAfee-GW-EditionBehavesLike.Win32.PUP.th
SophosGeneric PUA EJ (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.Generic.ezee
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.Agent.C2393728
VBA32Trojan.Redosdru
MalwarebytesGeneric.Trojan.Banker.DDS
APEXMalicious
YandexTrojan.GenAsa!Unqd7e7rMuk
IkarusPUA.DRMSoft
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.4d244b

How to remove Trojan.Redosdru?

Trojan.Redosdru removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment