Trojan

Should I remove “Trojan:Win32/Dridex.RTH!MTB”?

Malware Removal

The Trojan:Win32/Dridex.RTH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.RTH!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Dridex.RTH!MTB?


File Info:

crc32: 9DE47975
md5: 96905e8602ff965a9aa7dd55a6e2d5d1
name: 96905E8602FF965A9AA7DD55A6E2D5D1.mlw
sha1: b4324e6a545374abe5c3c0a05121c4ef76a25488
sha256: d8d6e4d7529c3a2bd798b3a345d04f3bf208df32ae4d056adcf43a219cdd21fc
sha512: c637586eeafb608c693ad0108fc0ca0837163512dd531db54bc4d264596763fe65f4c7cd12729b2209ec139dd45bdbcd000536ea30b5f51b145f8758b40dd8cb
ssdeep: 3072:OWpY/Syz2ita3Un6oaxewXvR2GNYHj8z+7/VczU9vh46WIOY4zmo3zAGW+r:OWpY/S8Z83VewfR2GyxVcA5hvjRCmik
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2018
InternalName: r2thla
FileVersion: 6.5.0000.00
Full Version: 6.5.0_000-b00
CompanyName: Oracle Corporation
ProductName: Rtth(AE) Tefhwqho GZ 8
ProductVersion: 6.5.0000.00
FileDescription: Java(TM) Platform SE binary
OriginalFilename: r2thla.dll
Translation: 0x0000 0x04b0

Trojan:Win32/Dridex.RTH!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.776
ClamAVWin.Malware.Trojanx-9863334-0
McAfeeArtemis!96905E8602FF
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Dridex.3a1ed36d
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Emotet.BCM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKYX
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Yakes
BitDefenderTrojan.GenericKD.36930209
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.36930209
Ad-AwareTrojan.GenericKD.36930209
SophosMal/Generic-S + Mal/EncPk-APX
ComodoMalware@#358f7d0xh80ku
BitDefenderThetaGen:NN.ZedlaF.34690.ku8@aSUWewn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Drixed.cc
FireEyeGeneric.mg.96905e8602ff965a
EmsisoftTrojan.GenericKD.36930209 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.Agent.bzmvs
eGambitUnsafe.AI_Score_92%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Dridex.RTH!MTB
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.36930209
VBA32TScope.Malware-Cryptor.SB
MAXmalware (ai score=87)
MalwarebytesTrojan.Dridex
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan-Banker.Dridex
FortinetW32/EncPk.APX!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Dridex.RTH!MTB?

Trojan:Win32/Dridex.RTH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment