Trojan

Trojan:Win32/Drokbk.C!dha removal guide

Malware Removal

The Trojan:Win32/Drokbk.C!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Drokbk.C!dha virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Drokbk.C!dha?


File Info:

name: E26A66BFE0DA89405E25.mlw
path: /opt/CAPEv2/storage/binaries/64f39b858c1d784df1ca8eb895ac7eaf47bf39acf008ed4ae27a796ac90f841b
crc32: AD089FC8
md5: e26a66bfe0da89405e25a66baad95b05
sha1: 4eb5c832ce940739d6c0eb1b4fc7a78def1dd15e
sha256: 64f39b858c1d784df1ca8eb895ac7eaf47bf39acf008ed4ae27a796ac90f841b
sha512: 2b24ae439a012e0dd8c0cf2669909d9e4b3ffa937dd856dd149db72ca231d749d63e7e960d41e57649b72b17f35f8b030d34f12e33aef6d4451e000ea4a2eb78
ssdeep: 6144:DDKW1Lgbdl0TBBvjc/h6iNYKfER27VcHmb7epjV5khYVyewqF:Xh1Lk70Tnvjc5zfEcapjVBNF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14164E02131C1C1B3D4B7153444E5CA7A9E3975621B6A96D7BB8C1BBA2F203E4E3362CD
sha3_384: a4d5f3dd13ad401eb0064b72e5b8ea17d260ed571f2aeaedc735146207580319d38e62dc49f3cebda0783c9a337b3149
ep_bytes: e8e15c0000e9a4feffff8bff558bec83
timestamp: 2012-07-13 22:47:16

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Drokbk
FileVersion: 1.0.0.0
InternalName: Drokbk.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Drokbk.exe
ProductName: Drokbk
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/Drokbk.C!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.39978557
FireEyeGeneric.mg.e26a66bfe0da8940
McAfeeGeneric .qh
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Generic.Win32.1657245
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059b6d11 )
AlibabaTrojan:Win32/Generic.d54293bd
K7GWTrojan ( 0059b6d11 )
CyrenW32/ABRisk.MBAM-1449
SymantecBackdoor.Drokbk
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FRS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.39978557
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13ace246
EmsisoftTrojan.GenericKD.39978557 (B)
F-SecureTrojan.TR/RedLineSteal.EP
DrWebTrojan.MulDrop20.37863
VIPRETrojan.GenericKD.39978557
TrendMicroTROJ_GEN.R002C0PGS22
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Spy
GDataTrojan.GenericKD.39978557
WebrootW32.Trojan.Drokbk
AviraTR/RedLineSteal.EP
Antiy-AVLTrojan[APT]/Win32.Apt35
ArcabitTrojan.Generic.D262063D
ViRobotTrojan.Win32.Z.Sabsik.320512
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Drokbk.C!dha
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5269389
BitDefenderThetaGen:NN.ZexaF.36722.tq0@aq20C1e
ALYacTrojan.Agent.Drokbk
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PGS22
RisingTrojan.Generic@AI.100 (RDML:N0/oG/JpFnMPhxVp+5xI2g)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Drokbk.C!dha?

Trojan:Win32/Drokbk.C!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment