Trojan

Trojan:Win64/Dridex.EF!MTB information

Malware Removal

The Trojan:Win64/Dridex.EF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Dridex.EF!MTB virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Trojan:Win64/Dridex.EF!MTB?


File Info:

crc32: FEB9AFD0
md5: 3d987c559fee6dc8d39a0428f77b39b1
name: 3D987C559FEE6DC8D39A0428F77B39B1.mlw
sha1: 698b12b088ffa55f47a0ea5a4504276941d7cb31
sha256: 3bd1435d754a8c551c78784e9c8a52f04f9e2c8837b3ce23f85905ac0b1be8a4
sha512: 40d97176d656353c1415734f5f56bf94c61693ecfb2f0b53e600cf550739a64e6b2e7cd33cb21cdf52d810a8494292ef4338fa716885eef73be046905319923c
ssdeep: 12288:NdMIwS97wJs6tSKDXEabXaC+jhc1S8XXk7CZzHsZH9dq0Ta:jMIJxSDX3bqjhcfHk7MzH6zW
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005 - 2009 Nir Sofer
InternalName: TeltwFoo
FileVersion: 9.74
CompanyName: NirSoft
ProductName: TeltwFoo
ProductVersion: 9.74
FileDescription: ProduKey
OriginalFilename: TeltwFoo.exe
Translation: 0x0409 0x04b0

Trojan:Win64/Dridex.EF!MTB also known as:

Elasticmalicious (high confidence)
ClamAVWin.Dropper.Dridex-9875456-0
CAT-QuickHealTrojan.Win64RI.S20908814
ALYacTrojan.GenericKDZ.75562
ZillyaTrojan.Injexa.Win64.129
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW64/MSIL_Kryptik.ELJ.gen!Eldorado
ESET-NOD32a variant of Win64/Kryptik.CJV
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin64:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win64.Injexa.pef
BitDefenderTrojan.GenericKDZ.75562
MicroWorld-eScanTrojan.GenericKDZ.75562
TencentMalware.Win32.Gencirc.10ce569e
Ad-AwareTrojan.GenericKDZ.75562
SophosML/PE-A + Troj/Dridex-ABY
McAfee-GW-EditionDrixed-FJX!3D987C559FEE
FireEyeGeneric.mg.3d987c559fee6dc8
EmsisoftTrojan.GenericKDZ.75562 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Injexa.hs
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3333576
MicrosoftTrojan:Win64/Dridex.EF!MTB
GridinsoftTrojan.Win64.Kryptik.oa!s1
ArcabitTrojan.Generic.D1272A
ZoneAlarmHEUR:Trojan.Win64.Injexa.pef
GDataTrojan.GenericKDZ.75562
AhnLab-V3Trojan/Win.Generic.R426521
McAfeeDrixed-FJX!3D987C559FEE
MAXmalware (ai score=83)
VBA32Trojan.Win64.Dridex
MalwarebytesMalware.AI.1884556628
IkarusTrojan.Win64.Dridex
MaxSecureBanker.Win64.Emotet.sb
FortinetW64/Kryptik.CJV!tr
AVGWin64:BankerX-gen [Trj]

How to remove Trojan:Win64/Dridex.EF!MTB?

Trojan:Win64/Dridex.EF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment