Trojan

Trojan:Win32/Dridex.GA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Dridex.GA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.GA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Dridex.GA!MTB?


File Info:

crc32: 73DC00D9
md5: 90feca61ad1a2de0454fc58d93bb5ab6
name: 90FECA61AD1A2DE0454FC58D93BB5AB6.mlw
sha1: f4e5e965dfcbdb5adeb3e172694eaa0bf209198b
sha256: 901782479cf975a8b2811264fd34f2e6fde694dcb968ce8bf502cb054ac9eb5a
sha512: 328bba1691113bddb29847222709075402887532abc5499ce5e88c2a5b369d2085a7dee7bbc1fac9dab19bd8f723a64f6e1f81c928d1286ed432052d8364e6ba
ssdeep: 3072:1ZUVAk9rsXo3/Ifz/uUXF2mSPBxv1tM7lt8jPU6/pyagsuAtuUucGZ2:1UAk9I4vgz/V2dulz6/hvHhG
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2018 The PHP Group
InternalName: APO8_12L dfdefvmbd
FileVersion: 8.7.8
CompanyName: The PHP Group
URL: http://www.php.net
LegalTrademarks: PHP
Comments: Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
ProductName: APO
ProductVersion: 8.7.8
FileDescription: OCI8
OriginalFilename: apo_soh8_12d.dll
Translation: 0x0409 0x04b0

Trojan:Win32/Dridex.GA!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Zusy
ALYacTrojan.GenericKDZ.75877
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.87492
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Dridex.DU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLKF
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Trojan.Zusy-9872297-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderTrojan.GenericKDZ.75877
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKDZ.75877
Ad-AwareTrojan.GenericKDZ.75877
SophosML/PE-A
BitDefenderThetaGen:NN.ZedlaF.34758.lu8@aWX@83ni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionDrixed-FJX!90FECA61AD1A
FireEyeGeneric.mg.90feca61ad1a2de0
EmsisoftTrojan.GenericKDZ.75877 (B)
JiangminTrojan.Yakes.airh
AviraTR/Redcap.hfncd
Antiy-AVLTrojan/Generic.ASMalwS.3391618
MicrosoftTrojan:Win32/Dridex.GA!MTB
ArcabitTrojan.Generic.D12865
GDataTrojan.GenericKDZ.75877
AhnLab-V3Trojan/Win.Generic.R425913
McAfeeDrixed-FJX!90FECA61AD1A
MAXmalware (ai score=81)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.Dridex
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.85 (RDMK:wnPP7/lJshXFu+pj/QveEQ)
IkarusTrojan-Banker.Dridex
FortinetW32/Dridex.0E17!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan:Win32/Dridex.GA!MTB?

Trojan:Win32/Dridex.GA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment