Trojan

About “Trojan:Win32/Dridex.NL!MTB” infection

Malware Removal

The Trojan:Win32/Dridex.NL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.NL!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Dridex.NL!MTB?


File Info:

crc32: 3E0071E1
md5: 9d9c1d19818e75ccf8c9de90709f26ce
name: 9D9C1D19818E75CCF8C9DE90709F26CE.mlw
sha1: c2c3eef61cd0750851b1113b7f5d657e9d7a5627
sha256: cc242ab99ab6100dcdc98f004f26041fdd5b67015630d73bff76b03a3d2d607f
sha512: 2317e9ede6cbc0dc179d0e17ea7bb49192603586814dc9fd456c7449829e55c265351bd1aa4643b1ea610f99f1ba5109f99eb4e256f96e4ce2e13f9069e2d9e7
ssdeep: 12288:7SDs0Ljpezsf/Lrxn9AiQwvM8hZDgh6cVBsepVEsY7/ICmco0ADXEwRsZ:WDrszsHxfjv7Dg1Dc7/IxEwRs
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Quite cover xa9 2017 Life self
Unit invent: Multiply chance
InternalName: WeType
FileVersion: 6.4.1.612
CompanyName: Mark duck
ProductName: save.dll
ProductVersion: 6.4.1.612
FileDescription: Quite cover
Translation: 0x0409 0x04b0

Trojan:Win32/Dridex.NL!MTB also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36250410
FireEyeGeneric.mg.9d9c1d19818e75cc
ALYacTrojan.GenericKD.36250410
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005669021 )
BitDefenderTrojan.GenericKD.36250410
K7GWTrojan ( 005669021 )
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
AlibabaTrojanBanker:Win32/Dridex.5c12c327
Ad-AwareTrojan.GenericKD.36250410
EmsisoftTrojan.Agent (A)
ComodoMalware@#1nixyn5b82aq5
F-SecureTrojan.TR/AD.Dridex.jcckv
DrWebTrojan.Dridex.735
TrendMicroTROJ_FRS.0NA104AR21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Dridex
AviraTR/AD.Dridex.jcckv
MAXmalware (ai score=88)
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Dridex.NL!MTB
ArcabitTrojan.Generic.D229232A
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataTrojan.GenericKD.36250410
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R364374
McAfeeGenericRXNL-NM!9D9C1D19818E
MalwarebytesTrojan.Dridex
PandaTrj/Agent.PM
ESET-NOD32Win32/Dridex.DD
TrendMicro-HouseCallTROJ_FRS.0NA104AR21
FortinetW32/Kryptik.FANW!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
Qihoo-360Win32/Trojan.8a8

How to remove Trojan:Win32/Dridex.NL!MTB?

Trojan:Win32/Dridex.NL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment