Trojan

About “Trojan:Win32/Dridex.RAC!MTB” infection

Malware Removal

The Trojan:Win32/Dridex.RAC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.RAC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality

How to determine Trojan:Win32/Dridex.RAC!MTB?


File Info:

crc32: 4899AB29
md5: 19a092ed7018b8d9e12c06e78edaffde
name: 19A092ED7018B8D9E12C06E78EDAFFDE.mlw
sha1: 4aeed6ad2251af9bec02dd420e7802796653624d
sha256: 96cb74688d7b0980f4b00f548a6ec6043485a08a2f48416dd473c61e202150a4
sha512: 87cec5dfc15f91060e6ffdc163b3bc401159fb81fd5995b04fe917a7dfae6811942ec0ce3b0be2e3832daa334e4760a8705cc24893bfc1b80120981c226c7629
ssdeep: 6144:eWSKxhvIBVgosEkUMpVs6BJ0eDXpjhKBUOYrntfrz:eWZfABVgyX6VbfwUvn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2005 Info-Zip
InternalName: unzip
FileVersion: 5.51.1871.34282
License: see contrib/LICENSE
CompanyName: Info-Zip
PrivateBuild: Patchlevel 1
LegalTrademarks: Info-Zipxae, UnZipxae, unzipxae
WWW: http://www.info-zip.org/UnZip.html
ProductName: UnZip
SpecialBuild: GNU for Win32
ProductVersion: 5.51.1871.34282
FileDescription: UnZip SPECS UnZip: list, test and extract compressed files in a ZIP archive
OriginalFilename: unzip.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Dridex.RAC!MTB also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusTrojan ( 004ed6111 )
DrWebTrojan.Inject3.39536
CynetMalicious (score: 100)
CAT-QuickHealTrojan.QbotPMF.S13139236
ALYacTrojan.GenericKDZ.66977
CylanceUnsafe
ZillyaTrojan.Qbot.Win32.8143
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanBanker:Win32/Kryptik.de21692a
K7GWTrojan ( 004ed6111 )
Cybereasonmalicious.d2251a
TrendMicroTROJ_GEN.R057C0DE620
CyrenW32/Kryptik.BMN.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.HDHT
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Dropper.Qakbot-7759404-1
GDataTrojan.GenericKDZ.66977
KasperskyHEUR:Trojan-Banker.Win32.Qbot.pef
BitDefenderTrojan.GenericKDZ.66977
NANO-AntivirusTrojan.Win32.Inject3.hjzpmg
SUPERAntiSpywareBackdoor.Qbot/Variant
MicroWorld-eScanTrojan.GenericKDZ.66977
TencentMalware.Win32.Gencirc.10b9ece1
Ad-AwareTrojan.GenericKDZ.66977
SophosMal/EncPk-APV
ComodoTrojWare.Win32.Qbot.AS@8rff2f
F-SecureTrojan.TR/AD.Qbot.absl
BitDefenderThetaGen:NN.ZexaF.34136.Xn0@ayZ2NIgi
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.19a092ed7018b8d9
EmsisoftTrojan.GenericKDZ.66977 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Kryptik.BMN.gen!Eldorado
Endgamemalicious (high confidence)
AviraTR/AD.Qbot.absl
Antiy-AVLTrojan[Banker]/Win32.Qbot
MicrosoftTrojan:Win32/Dridex.RAC!MTB
JiangminTrojan.Banker.Qbot.oc
ArcabitTrojan.Generic.D105A1
AegisLabTrojan.Win32.Qbot.trof
ZoneAlarmHEUR:Trojan-Banker.Win32.Qbot.pef
TACHYONBackdoor/W32.Qbot.1866752
AhnLab-V3Malware/Win32.RL_Generic.R335115
Acronissuspicious
McAfeeW32/PinkSbot-GN!19A092ED7018
MAXmalware (ai score=80)
VBA32BScope.Trojan.Inject
MalwarebytesTrojan.Qbot
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SME
RisingBackdoor.Qakbot!8.C7B (C64:YzY0OvjAL4qDY11V)
YandexTrojan.Kryptik!LtneXwinRgk
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.100811769.susgen
FortinetW32/QBOT.CC!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.BO.37d

How to remove Trojan:Win32/Dridex.RAC!MTB?

Trojan:Win32/Dridex.RAC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment