Malware

Win64/Dridex.BA removal

Malware Removal

The Win64/Dridex.BA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Dridex.BA virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win64/Dridex.BA?


File Info:

crc32: 7CA5F90B
md5: e35c61ebe91c031d45c2ae5fee1ce298
name: upload_file
sha1: 18f2b3c265c8cb3dfc839e276c8b991e2dc03eaf
sha256: 6da8b8e1b1f1db5c5497500cc342b5778541c2d6584a958ce64ae77c09895ecc
sha512: 9b29a54deec72ef1e8c713da7659299df77a842e4543b2cf2d09dcea30cc68e87fff71e629acbf76feaada6a6019ac79c9ea438c3dc3d00d44f731bc767e620d
ssdeep: 24576:hhLBOY3Zch8R9trbCPQFaD0JAc8V7M/GGS069NmgsSF:pTFJawGGj6fmg
type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Apple Inc. 1989-2016
InternalName: LswdDualo
FileVersion: 7.8.7
CompanyName: Apple Computer, Inc.
ProductName: LswddUalo
ProductVersion: QuickTime 0.0.0
FileDescription: CoreVideo
OriginalFilename: LswdDualo.qtx
Translation: 0x0410 0x04b0

Win64/Dridex.BA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34594787
McAfeeDrixed-FJI!E35C61EBE91C
CylanceUnsafe
AegisLabTrojan.Win64.Injexa.4!c
K7AntiVirusTrojan ( 0056cab71 )
BitDefenderTrojan.GenericKD.34594787
K7GWTrojan ( 0056cab71 )
CrowdStrikewin/malicious_confidence_80% (D)
ArcabitTrojan.Generic.D20FDFE3
TrendMicroTROJ_FRS.VSNTIP20
SymantecW64.Cridex
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win64.Injexa.vho
AlibabaTrojan:Application/Kryptik.56fd3256
TencentMalware.Win32.Gencirc.11af9236
Ad-AwareTrojan.GenericKD.34594787
EmsisoftTrojan.GenericKD.34594787 (B)
ComodoMalware@#2m0diwv6qtqut
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.Siggen10.28215
InvinceaMal/Generic-S + Troj/Dridex-ABY
McAfee-GW-EditionBehavesLike.Win64.Drixed.dc
FireEyeGeneric.mg.e35c61ebe91c031d
SophosTroj/Dridex-ABY
IkarusTrojan-Banker.Dridex
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Win64.Injexa
MicrosoftTrojan:Win64/Dridex.RAX!MTB
ViRobotTrojan.Win32.Z.Kryptik.1009152.K
ZoneAlarmHEUR:Trojan.Win64.Injexa.vho
GDataTrojan.GenericKD.34594787
CynetMalicious (score: 90)
ALYacSpyware.Banker.Dridex
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.RND
PandaTrj/CI.A
ESET-NOD32Win64/Dridex.BA
TrendMicro-HouseCallTROJ_FRS.VSNTIP20
RisingTrojan.Kryptik!8.8 (TFE:2:Dn04PTKgeCC)
SentinelOneDFI – Suspicious PE
FortinetW64/Kryptik.BZO!tr
AVGWin64:BankerX-gen [Trj]
AvastWin64:BankerX-gen [Trj]
Qihoo-360Win64/Trojan.4a4

How to remove Win64/Dridex.BA?

Win64/Dridex.BA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment