Trojan

Trojan:Win32/Dridex.GC!MTB malicious file

Malware Removal

The Trojan:Win32/Dridex.GC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.GC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Dridex.GC!MTB?


File Info:

crc32: 46354760
md5: c2b80fa119a1f182a24569df973f6b44
name: C2B80FA119A1F182A24569DF973F6B44.mlw
sha1: 68fd23b3b2acb7969ad4958a0eae8408b0c6aedc
sha256: 7c80c1cbca689063977ae3ea76bf38553e02819ecb28b48ec2b1c7d4633e6052
sha512: 9bfb043bdd2525cac8e206acdc225239655b01b51103c8da6adb5eca7f2aef515c77945984f3564aa0f3c3650009ed7d052b805dcf63434352f0a8f2935bc1c9
ssdeep: 3072:3JWgjeWy6Qn2EjqWHBFtvLSmZIMr1ckoXYZK1+5RUQ3cg5NwrSl+2wxvvVDqwl+:30gdy6I29sSqD15oXYZTBMYwrSl+2wx
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2018 The PHP Group
InternalName: HSY8_12B heunwssnr
FileVersion: 4.4.7
CompanyName: The PHP Group
URL: http://www.php.net
LegalTrademarks: PHP
Comments: Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
ProductName: HSY
ProductVersion: 4.4.7
FileDescription: OCI8
OriginalFilename: hsy_utu8_12u.dll
Translation: 0x0409 0x04b0

Trojan:Win32/Dridex.GC!MTB also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/EmotetedCryptc.180910
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLPT
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.46590839
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.46590839
Ad-AwareTrojan.GenericKD.46590839
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZedlaF.34790.lu8@aCHJXOii
VIPRETrojan.Win32.Tracur.d (v)
McAfee-GW-EditionDrixed-FJX!C2B80FA119A1
FireEyeGeneric.mg.c2b80fa119a1f182
EmsisoftTrojan.GenericKD.46590839 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Dridex.GC!MTB
GDataTrojan.GenericKD.46590839
Acronissuspicious
McAfeeDrixed-FJX!C2B80FA119A1
MAXmalware (ai score=88)
RisingTrojan.Generic@ML.94 (RDML:3PF5Qj0DKvFIOulPeawmOw)
IkarusWin32.Outbreak
FortinetW32/Kryptik.HLPT!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Dridex.GC!MTB?

Trojan:Win32/Dridex.GC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment