Trojan

Trojan:Win32/Redosdru.W removal instruction

Malware Removal

The Trojan:Win32/Redosdru.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redosdru.W virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup

Related domains:

remote.dxcqsa.xyz
remote.securityterm.xyz
remote.d1x2c3q4s5.xyz
remote.aoldpanther.xyz

How to determine Trojan:Win32/Redosdru.W?


File Info:

crc32: 213F792A
md5: 12d41d7037252a3a63628d81e79c6aee
name: dbackup.exe
sha1: e838c063b61885166685b8b288e9d2f663b0bcfc
sha256: 943cab049b78ebf7f210191447ba0332737824e19cac2a1ca8e09298263512ef
sha512: ec8f6d7f8217eb96b206003c752d69a8c535b5c059b5301ad2b1ac36f4aa43d2a3cf5a6200baccd8c5c8b1f69a7d5343bf304d2a15d79d57f8c74b1569075091
ssdeep: 24576:YNKMJ4T7f9HVHFeUxkLym+B450zHuZTu:YNRM7fxXe7ybB4Tu
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Redosdru.W also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.DownLoader33.28141
MicroWorld-eScanGen:Variant.Graftor.717052
FireEyeGeneric.mg.12d41d7037252a3a
Qihoo-360Generic/HEUR/QVM07.1.6417.Malware.Gen
ALYacGen:Variant.Graftor.717052
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Dapato.b!c
K7AntiVirusTrojan ( 005640191 )
BitDefenderGen:Variant.Graftor.717052
K7GWTrojan ( 005640191 )
Cybereasonmalicious.037252
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.717052
KasperskyTrojan-Dropper.Win32.Dapato.qezk
AlibabaTrojanDropper:Win32/Dapato.6e42eeae
TencentWin32.Trojan-dropper.Dapato.Dyqm
Ad-AwareGen:Variant.Graftor.717052
SophosMal/Generic-S
ComodoTrojWare.Win32.BlackMoon.R@8c1vff
F-SecureTrojan.TR/Drop.Dapato.vpxku
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.717052 (B)
AviraTR/Drop.Dapato.vpxku
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.DAF0FC
ZoneAlarmTrojan-Dropper.Win32.Dapato.qezk
MicrosoftTrojan:Win32/Redosdru.W
Acronissuspicious
McAfeeArtemis!12D41D703725
MAXmalware (ai score=82)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Dropper
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.JDYDRFX
TrendMicro-HouseCallTROJ_GEN.R002H0CD620
RisingTrojan.Injector!1.A1C3 (CLOUD)
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AP.2BFAFC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redosdru.W?

Trojan:Win32/Redosdru.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment