Trojan

Trojan:Win32/Dridex.VSF!MTB malicious file

Malware Removal

The Trojan:Win32/Dridex.VSF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.VSF!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Dridex.VSF!MTB?


File Info:

crc32: F993C510
md5: 429d63af6c900c0c2f7c2b82dec86a7e
name: 429D63AF6C900C0C2F7C2B82DEC86A7E.mlw
sha1: 6f3c788b9223c6d99d34235c86bcc00056a2c73f
sha256: b6c782d71a48aaf6b23d0c9f2f6490c008d8f3f87d43b3c1a6f18343ddc63874
sha512: 0f1cc54093f788e6549cc0149f2d0d3c52e82b76222a4563c995c3bc8c207f4a2583f585b4f0ae522c85a5994a9953238c094e589cfcab3f4688ac9dd244ff4c
ssdeep: 6144:wIStqP+19P2yLnafTR93YBgobwN+5AxtyTCjzVm8NsCuFaJ0hH:wIS0Gne883YdbY+5QyTE1kFa+l
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 2005-2015
InternalName:
FileVersion: 1.0.0.634
CompanyName: IObit
LegalTrademarks: IObit
Comments:
ProductName: Display
ProductVersion: 2.0.0.0
FileDescription: Advanced SystemCare Display
OriginalFilename:
Translation: 0x0409 0x04e4

Trojan:Win32/Dridex.VSF!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.735
MicroWorld-eScanTrojan.GenericKD.35346825
FireEyeGeneric.mg.429d63af6c900c0c
CAT-QuickHealTrojan.Multi
McAfeeDrixed-FJW!429D63AF6C90
MalwarebytesPUP.Optional.AdvancedSystemCare
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.35346825
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZedlaF.34634.Ky8@auFKQXnj
CyrenW32/Agent.CBF.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Downloader.Win32.Cridex.hbl
AlibabaTrojanDownloader:Win32/Dridex.9f26eb65
ViRobotTrojan.Win32.Z.Ursnif.604672
AegisLabHacktool.Win32.Krap.lKMc
Ad-AwareTrojan.GenericKD.35346825
SophosMal/Generic-R + Mal/EncPk-APV
ComodoMalware@#3gfutsm3j7gj3
F-SecureTrojan.TR/Ursnif.skhwh
TrendMicroTROJ_FRS.VSNTKK20
McAfee-GW-EditionDrixed-FJW!429D63AF6C90
EmsisoftTrojan.Cridex (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Ursnif.skhwh
Antiy-AVLGrayWare/Win32.Kryptik.ehls
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Dridex.VSF!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D21B5989
SUPERAntiSpywarePUP.LoadMoney/Variant
ZoneAlarmTrojan-Downloader.Win32.Cridex.hbl
GDataTrojan.GenericKD.35346825
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4229007
VBA32BScope.Trojan.Wacatac
PandaTrj/GdSda.A
ESET-NOD32Win32/Dridex.DD
TrendMicro-HouseCallTROJ_FRS.VSNTKK20
RisingRansom.Shade!8.12CC (TFE:2:k40YZbWyNNL)
IkarusTrojan.Win32.Ursnif
eGambitUnsafe.AI_Score_99%
FortinetW32/Cridex.HBM!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.63F6.Malware.Gen

How to remove Trojan:Win32/Dridex.VSF!MTB?

Trojan:Win32/Dridex.VSF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment