Trojan

Trojan:Win32/Dridex.G!rfn (file analysis)

Malware Removal

The Trojan:Win32/Dridex.G!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.G!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Collects information about installed applications
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Dridex.G!rfn?


File Info:

crc32: 7CE2873E
md5: 40e58f483070c29c01db0ca9e9c605f3
name: 40E58F483070C29C01DB0CA9E9C605F3.mlw
sha1: 4f7f135867508e95189e0a234d3ed67bef2c2053
sha256: 8b1f6c2ba9d2a5f4689ca641b90946a6226e15b03aa51232550beee4b8be1643
sha512: 22aa10fa3c3610bcadc9f962b6e55dc61a3207a092d574c814338cdc32f386a845f7d1873c20304868f11e9cbbe9f9069a2ef87aae4b846e300ececbe1c039b4
ssdeep: 24576:/nxqsL+DvNdnhMr5Lo6dOGcuQNrSH9d6N9eYWtZgDxxxSPnsqz7puATt5csRbu7:/cfk82uAJTI7TPswKwuO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Dridex.G!rfn also known as:

LionicTrojan.Win32.Cridex.7!c
DrWebTrojan.Dridex.735
CAT-QuickHealTrojan.GenericPMF.S24318178
ALYacTrojan.GenericKD.37887488
CylanceUnsafe
ZillyaTrojan.Dridex.Win32.1853
SangforTrojan.Win32.Cridex.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/Cridex.63d04313
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
CyrenW32/Cridex.AS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Dridex.DD
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
BitDefenderTrojan.GenericKD.37887488
MicroWorld-eScanTrojan.GenericKD.37887488
Ad-AwareTrojan.GenericKD.37887488
SophosMal/Generic-R + Mal/EncPk-AQC
TrendMicroTROJ_GEN.R002C0DJU21
McAfee-GW-EditionDrixed-FKG!40E58F483070
FireEyeTrojan.GenericKD.37887488
EmsisoftTrojan.GenericKD.37887488 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.Cridex.ayu
AviraTR/AD.Dridex.ledzq
Antiy-AVLTrojan/Generic.ASMalwS.34C5D65
MicrosoftTrojan:Win32/Dridex.G!rfn
GDataWin32.Trojan.PSE1.FP59PE
AhnLab-V3Malware/Win.Generic.R447627
McAfeeDrixed-FKG!40E58F483070
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.FL
MalwarebytesTrojan.Dridex
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJU21
YandexTrojan.Dridex!vfqpaYAKBHQ
IkarusTrojan.Win32.Dridex
FortinetW32/Dridex.DD!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Dridex.G!rfn?

Trojan:Win32/Dridex.G!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment