Trojan

About “Trojan:Win32/Dridex.VSI!MTB” infection

Malware Removal

The Trojan:Win32/Dridex.VSI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dridex.VSI!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Dridex.VSI!MTB?


File Info:

crc32: B63000ED
md5: e0c054b049cf0bae1bb797674fb3eb17
name: E0C054B049CF0BAE1BB797674FB3EB17.mlw
sha1: 0afc1cc68df5c5ba28261b4a97c1e858d66d585a
sha256: eb3154fc479e6ec838bffbf7cb1f4247c4286625e2311bf6ba50abf7a48044a1
sha512: 844b562e37ba8f1e58c5292df4764581e919cd620fbc15502a711cc4f2e9732e9d131b9bddfa0c14ffe31c02717a9c2b5eb8f307455f2fdae0837fa04286269b
ssdeep: 3072:ZFsIcCVMdHhbwlilXv+/dw7NN24M/1Z/NHPp6Yyb5RmShVo2D:ZF32hXYd6rrM9BNCNYS
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2002-2008 Safer Networking Limited. All rights reserved.
InternalName:
FileVersion: 1, 0, 0, 8
CompanyName: Safer Networking Limited
Comments: Dummy associated to files that should not be opened.
ProductName: Spybot - Search & Destroy
ProductVersion: 1, 6, 0, 0
FileDescription: Dummy
OriginalFilename: blindman.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Dridex.VSI!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45011867
FireEyeGeneric.mg.e0c054b049cf0bae
Qihoo-360Generic/HEUR/QVM40.1.EFBF.Malware.Gen
McAfeeRDN/Dridex
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 00574b581 )
BitDefenderTrojan.GenericKD.45011867
K7GWTrojan ( 00574b581 )
CrowdStrikewin/malicious_confidence_80% (D)
ArcabitTrojan.Generic.D2AED39B
CyrenW32/Trojan.QETP-8525
SymantecTrojan.Gen.2
TrendMicro-HouseCallTrojanSpy.Win32.DRIDEX.THLAEBO
AvastWin32:Trojan-gen
ClamAVWin.Malware.Generic-9809335-0
ViRobotTrojan.Win32.Z.Undef.204800
Ad-AwareTrojan.GenericKD.45011867
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.yommf
TrendMicroTrojanSpy.Win32.DRIDEX.THLAEBO
McAfee-GW-EditionBehavesLike.Win32.Drixed.dh
EmsisoftTrojan.Crypt (A)
AviraTR/Crypt.Agent.yommf
MAXmalware (ai score=87)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Dridex.VSI!MTB
GDataTrojan.GenericKD.45011867
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34700.mu8@aiEZHHCi
ALYacTrojan.GenericKD.45011867
TACHYONTrojan/W32.Agent.204800.BKT
VBA32BScope.Trojan.Agentb
MalwarebytesTrojan.MalPack.RND
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIFY
RisingTrojan.Generic@ML.85 (RDML:MX8JbaVP2PRwpxwv7gbTIA)
YandexTrojan.Kryptik!f+ZcgtOkZ60
IkarusTrojan.Win32.Crypt
FortinetPossibleThreat.PALLAS.H
AVGWin32:Trojan-gen

How to remove Trojan:Win32/Dridex.VSI!MTB?

Trojan:Win32/Dridex.VSI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment