Trojan

Trojan:Win32/Dridex.BAM!MTB removal tips

Malware Removal

The Trojan:Win32/Dridex.BAM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.BAM!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the DridexV4 malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Dridex.BAM!MTB?


File Info:

name: 321B886A90EF0131DE41.mlw
path: /opt/CAPEv2/storage/binaries/ebb649d15d48c0800ece9e50359b24b38a8580254a82aa0c3726d2e17c0179cb
crc32: A5212CD2
md5: 321b886a90ef0131de41fba18c68fbc1
sha1: 3303afa8fc26af3267782778a953037b33f80304
sha256: ebb649d15d48c0800ece9e50359b24b38a8580254a82aa0c3726d2e17c0179cb
sha512: 2a5659d9b5e4f00ceb2cb2ecdf9c3d4ee9f04c91f79b6543d93aacb9cd69b74f6864def308d755bc22ec371b884fbac4ee0a5ebacd02c7f2a6d68f7d69074502
ssdeep: 3072:qgkQz1PuOprc+kq6VNOe3qbarVEpZlcbBacS9nOdgSdA4l:jPFkq6zOe5ilSanOBd
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T12504CF44D5CBA0FEE49FD57C9BCB602D59293E4A7F0CD9FEA284CE5AE78090189178C1
sha3_384: f247f3a16fe7f7e699dad3d30f77c3b1f03c99f097a841950c4273a9c703511607dec8144f908a34304dfa4bf90dda71
ep_bytes: 891d24b9021001252cb90210e82fb9ff
timestamp: 2021-08-09 16:57:21

Version Info:

Comments:
CompanyName: The PHP Group
FileDescription: PHP Script Interpreter
FileVersion: 4.4.4.4
InternalName: php
LegalCopyright: Copyright © 2006 The PHP Group
LegalTrademarks: php
OriginalFilename: php4ts.dll
PrivateBuild:
ProductName: PHP Thread Safe
ProductVersion: 4.4.4
SpecialBuild:
URL: http://www.php.net
Translation: 0x0409 0x04b0

Trojan:Win32/Dridex.BAM!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Cridex.14!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AgentRI.S21748802
SkyhighBehavesLike.Win32.Drixed.cc
McAfeeDrixed-FJX!321B886A90EF
Cylanceunsafe
VIPREGen:Variant.Mikey.126852
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Mikey.126852
K7GWTrojan ( 00580b281 )
K7AntiVirusTrojan ( 00580b281 )
ArcabitTrojan.Mikey.D1EF84
SymantecPacked.Generic.657
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HMAI
APEXMalicious
ClamAVWin.Trojan.Zusy-9885000-0
KasperskyHEUR:Trojan.Win32.Sdum.gen
AlibabaTrojan:Win32/Dridex.19ee7ae3
NANO-AntivirusTrojan.Win32.Cridex.jrbldh
SUPERAntiSpywareTrojan.Agent/Gen-Dridex
MicroWorld-eScanGen:Variant.Mikey.126852
AvastWin32:MalwareX-gen [Trj]
TencentTrojan-Banker.Win32.Cridex.ka
EmsisoftTrojan.Crypt (A)
F-SecureHeuristic.HEUR/AGEN.1302339
ZillyaTrojan.Sdum.Win32.6221
FireEyeGeneric.mg.321b886a90ef0131
SophosTroj/Loskop-B
IkarusTrojan-Banker.Dridex
JiangminTrojanDownloader.Cridex.agx
GoogleDetected
AviraHEUR/AGEN.1302339
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Agent.cks
MicrosoftTrojan:Win32/Dridex.BAM!MTB
ZoneAlarmHEUR:Trojan.Win32.Sdum.gen
GDataGen:Variant.Mikey.126852
VaristW32/Dridex.EV.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R436318
BitDefenderThetaGen:NN.ZedlaF.36744.lu8@ay4v4Mgi
ALYacGen:Variant.Mikey.126852
VBA32Trojan.Win32.Dridex
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:4:e83qg6SzLjL)
YandexTrojan.Kryptik!Y0XimT3pWBQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HMET!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Dridex.BAM!MTB?

Trojan:Win32/Dridex.BAM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment