Trojan

Trojan:Win32/Dridex.GKM!MTB information

Malware Removal

The Trojan:Win32/Dridex.GKM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.GKM!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Collects information about installed applications
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Dridex.GKM!MTB?


File Info:

crc32: 882EDF80
md5: 4722db65a35b9a9190aa3ff2ee81c70f
name: 4722DB65A35B9A9190AA3FF2EE81C70F.mlw
sha1: 0d6d713409aed62d3a50b429faba49a983af084b
sha256: fc8724525d089bab1e6259f660fd4a36f7e54caf2aa3a39410b858381af8dabd
sha512: f13f5897439e86d1b633c668424f34cd41419b3014efaf5b73f571fcbe4672ced0c5560a353239b07d8b57668e0daf193be6c05dc8f254e3ea934073d3ee79b8
ssdeep: 12288:QELC62WDPaiGYQHZsTR2sDxEUW1ZdGOLZvFr:QEV2kCimZER2sD2zpZvd
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2013 Creasematch Corporation. All rights reserved
InternalName: Road.dll
FileVersion: 4.5.7.109
CompanyName: Creasematch
ProductName: Creasematch See lot
ProductVersion: 4.5.7.109
FileDescription: See lot
OriginalFilename: Road.dll
Translation: 0x0409 0x04b0

Trojan:Win32/Dridex.GKM!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Dridex.735
MicroWorld-eScanTrojan.GenericKD.45635743
McAfeeTrojan-FTDK!4722DB65A35B
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
BitDefenderTrojan.GenericKD.45635743
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D2B8589F
CyrenW32/Kryptik.DCY.gen!Eldorado
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_FRS.0NA103AS21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Cridex.gen
AlibabaTrojan:Win32/Dridex.726640c4
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKD.45635743
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Dridex.tzrpe
TrendMicroTROJ_FRS.0NA103AS21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.4722db65a35b9a91
EmsisoftTrojan.Agent (A)
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Gen
AviraTR/AD.Dridex.tzrpe
MicrosoftTrojan:Win32/Dridex.GKM!MTB
ZoneAlarmHEUR:Trojan-Downloader.Win32.Cridex.gen
GDataTrojan.GenericKD.45635743
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4314027
ALYacTrojan.GenericKD.45635743
MAXmalware (ai score=86)
MalwarebytesTrojan.Dridex
APEXMalicious
ESET-NOD32a variant of Win32/GenKryptik.FARD
RisingTrojan.GenKryptik!8.AA55 (TFE:5:TG0aiRGJ4KJ)
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.FARD!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/dridex.A

How to remove Trojan:Win32/Dridex.GKM!MTB?

Trojan:Win32/Dridex.GKM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment