Trojan

About “Trojan:Win64/Dridex.EF!MTB” infection

Malware Removal

The Trojan:Win64/Dridex.EF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Dridex.EF!MTB virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan:Win64/Dridex.EF!MTB?


File Info:

crc32: 66161C27
md5: 43d74d2dda79c4106ad4e03c41104625
name: 43D74D2DDA79C4106AD4E03C41104625.mlw
sha1: 703e7f07dd89be4ae200baa9d02d764fea03846d
sha256: 1724ff9ba5628de250ba08b8aa9e22f2d8dd1ef1202db2aa431092830b9096cd
sha512: a91c7d3cab697a12b364355e1ff5c3b87dff515bc81ae5101d191bd472840c3bf71b7ae3b42a119adcf9b7f61b68c525ab36b207634af16f2d4ad3d329cac30e
ssdeep: 12288:ndMIwS97wJs6tSKDXEabXaC+jhc1S8XXk7CZzHsZH9dq0T:dMIJxSDX3bqjhcfHk7MzH6z
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005 - 2009 Nir Sofer
InternalName: TeltwFoo
FileVersion: 9.74
CompanyName: NirSoft
ProductName: TeltwFoo
ProductVersion: 9.74
FileDescription: ProduKey
OriginalFilename: TeltwFoo.exe
Translation: 0x0409 0x04b0

Trojan:Win64/Dridex.EF!MTB also known as:

Elasticmalicious (high confidence)
ClamAVWin.Dropper.Dridex-9875456-0
CAT-QuickHealTrojan.Win64RI.S20908814
ALYacTrojan.GenericKDZ.75562
ZillyaTrojan.Injexa.Win64.129
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW64/MSIL_Kryptik.ELJ.gen!Eldorado
ESET-NOD32a variant of Win64/Kryptik.CJV
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin64:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win64.Injexa.pef
BitDefenderTrojan.GenericKDZ.75562
MicroWorld-eScanTrojan.GenericKDZ.75562
TencentMalware.Win32.Gencirc.10ce569e
Ad-AwareTrojan.GenericKDZ.75562
SophosML/PE-A + Troj/Dridex-ABY
McAfee-GW-EditionDrixed-FJX!43D74D2DDA79
FireEyeGeneric.mg.43d74d2dda79c410
EmsisoftTrojan.GenericKDZ.75562 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injexa.hs
AviraHEUR/AGEN.1143679
Antiy-AVLTrojan/Generic.ASMalwS.3333576
MicrosoftTrojan:Win64/Dridex.EF!MTB
GridinsoftTrojan.Win64.Kryptik.oa!s1
ZoneAlarmHEUR:Trojan.Win64.Injexa.pef
GDataTrojan.GenericKDZ.75562
AhnLab-V3Trojan/Win.Generic.R426521
McAfeeDrixed-FJX!43D74D2DDA79
MAXmalware (ai score=86)
VBA32Trojan.Win64.Dridex
MalwarebytesMalware.AI.1884556628
IkarusTrojan.Win64.Dridex
MaxSecureBanker.Win64.Emotet.sb
FortinetW64/Kryptik.CJV!tr
AVGWin64:BankerX-gen [Trj]

How to remove Trojan:Win64/Dridex.EF!MTB?

Trojan:Win64/Dridex.EF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment