Trojan

About “Trojan:Win32/Dridex.NB!MTB” infection

Malware Removal

The Trojan:Win32/Dridex.NB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.NB!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Dridex.NB!MTB?


File Info:

crc32: 1345BE3A
md5: beed816fa137d8fab585a7d3d957d9ae
name: BEED816FA137D8FAB585A7D3D957D9AE.mlw
sha1: 6dc33140b823afd13f73834a995288d9278ca663
sha256: 57c85bae5b0bed1a16cdd9048a80126a8f1f4ee7968524922c13b7ff30a00b26
sha512: 7aa173161dfc9dbf36811ef0af4e9e018a33e611354127693e512c554171ea2047a1f84ceb6bb7c06b59bfeaea4d2ac9bb5e75b6488a82091daa5fe0129dae0e
ssdeep: 3072:v1V+vpDx7DUQrMrXxomqF0uMfbaqPR7sOdBvFBnBXit/ba82MnJI:NMXDUQrOqFXMzaqNs8vATa82M
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2002-2008 Safer Networking Limited. All rights reserved.
InternalName:
FileVersion: 4, 0, 0, 0
CompanyName: Safer Networking Limited
Comments: Dummy associated to files that should not be opened.
ProductName: Dhamle - Astetd & Loydoet
ProductVersion: 4, 0, 0, 0
FileDescription: Dummy
OriginalFilename: dhamleen.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Dridex.NB!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45036719
FireEyeGeneric.mg.beed816fa137d8fa
McAfeeDrixed-FJX!BEED816FA137
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45036719
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecPacked.Generic.517
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:vox9VNXRa96S+HxBOkEDvg)
Ad-AwareTrojan.GenericKD.45036719
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionBehavesLike.Win32.Drixed.cc
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.opbpm
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Dridex.NB!MTB
ArcabitTrojan.Generic.D2AF34AF
GDataTrojan.GenericKD.45036719
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4264890
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.34700.ku8@aOMfeJxi
MalwarebytesTrojan.Dridex
ESET-NOD32a variant of Win32/Kryptik.HIHI
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HIHI!tr
Qihoo-360HEUR/QVM40.1.FC6C.Malware.Gen

How to remove Trojan:Win32/Dridex.NB!MTB?

Trojan:Win32/Dridex.NB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment