Trojan

Should I remove “Trojan:Win32/Dridex.E!MTB”?

Malware Removal

The Trojan:Win32/Dridex.E!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.E!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Dridex.E!MTB?


File Info:

name: 23C9C1DA888CC41FBA08.mlw
path: /opt/CAPEv2/storage/binaries/9bef7221d79a7f2c34d0c3737e9f00aeb982ab21a455fb90201fcfd45f3a17d4
crc32: 19B40C30
md5: 23c9c1da888cc41fba085581ee6bcfc6
sha1: d40595a39dd8b47d0f910d697b2da01894e630d8
sha256: 9bef7221d79a7f2c34d0c3737e9f00aeb982ab21a455fb90201fcfd45f3a17d4
sha512: bf8762c49c42408c127f49a3273b9acd55faf53064a7c5171d42ff0328c711ec691f5bb0154bde29cdbfa4d60b70ed00540205cc7c7edb727d03b1890e602d45
ssdeep: 1536:Bi6I/LpWZwIYKZ0QyXmA+v0F96aKSNa7mtvZdKhIsWQIA8zAFziXJXXczb:Y6INWmwZ9A+sJNaIK/rIAtzi5Hczb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F83F123A28CC117D89B6B3F14F3EE6EF7857E03CA13559774409A8F64B53A9961A302
sha3_384: 6ff2198a48a10ea7f2e1a405b814191dae632d16e08f81cb0ee129f06e5e8ca93de25f7355a3429384c08aafbe64fc2d
ep_bytes: 558bec83ec20575356e8e2fcffff8d3d
timestamp: 2013-11-05 16:34:31

Version Info:

CompanyName: Sfdye
FileDescription: Kyrsq Hwwt
FileVersion: 12.8.6301.53566
InternalName: Kyrsq
LegalCopyright: Copyright © Sfdye
OriginalFilename: Kyrsq.exe
ProductName: Kyrsq Dhrm
ProductVersion: 12.8.6301.53566
Translation: 0x0409 0x04b0

Trojan:Win32/Dridex.E!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Lazy.71858
FireEyeGeneric.mg.23c9c1da888cc41f
McAfeePWSZbot-FPK!23C9C1DA888C
Cylanceunsafe
ZillyaTrojan.Zbot.Win32.154890
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004e723f1 )
K7AntiVirusTrojan ( 004e723f1 )
ArcabitTrojan.Lazy.D118B2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BPTZ
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win32.BurHon.ol
BitDefenderGen:Variant.Lazy.71858
NANO-AntivirusTrojan.Win32.Zbot.cqvdze
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Burhon.Qnkl
EmsisoftGen:Variant.Lazy.71858 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Necurs.97
VIPREGen:Variant.Lazy.71858
McAfee-GW-EditionPWSZbot-FPK!23C9C1DA888C
SophosML/PE-A
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.Zbot.eabv
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
Kingsoftmalware.kb.a.995
XcitiumMalware@#2b1g2fyb4prwi
MicrosoftTrojan:Win32/Dridex.E!MTB
ZoneAlarmTrojan.Win32.BurHon.ol
GDataGen:Variant.Lazy.71858
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R90182
VBA32TrojanSpy.Zbot
ALYacGen:Variant.Lazy.71858
MAXmalware (ai score=87)
PandaGeneric Malware
RisingMalware.Undefined!8.C (TFE:1:bsjDDMTU1fJ)
YandexTrojanSpy.Zbot!k1qklDgh7QY
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.BSHF!tr
BitDefenderThetaGen:NN.ZexaF.36738.fu0@auKDE6gi
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Dridex.E!MTB?

Trojan:Win32/Dridex.E!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment