Threat Database Trojans Trojan.Dridex.G

Trojan.Dridex.G

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,215
Threat Level: 80 % (High)
Infected Computers: 149
First Seen: January 7, 2013
Last Seen: July 12, 2026
OS(es) Affected: Windows

The detection of Trojan.Dridex.G on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the issue and guide you through the removal process. It's essential to approach this situation with caution and follow the recommended steps to ensure the complete elimination of the threat.

What Is Trojan.Dridex.G?

Trojan.Dridex.G is a type of malicious software that can compromise the security and integrity of your computer system. The name suggests it may be related to the Dridex malware family, known for its banking Trojan capabilities. However, without specific details, it's crucial to focus on the general characteristics of Trojan-type threats. These malware types are designed to disguise themselves as legitimate software, making them difficult to detect. Once inside your system, they can cause a variety of problems, including data theft, unauthorized access, and system instability.

How Trojan.Dridex.G Operates

Trojan-type malware, like Trojan.Dridex.G, typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can create backdoors for remote access, allowing attackers to control your system, steal sensitive information, or use your computer as part of a botnet for malicious activities. The operation of such malware can be sophisticated, involving encryption and communication with command and control servers to receive updates or send stolen data.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, there are several symptoms that may indicate your system is compromised. These include unusual system behavior, such as unexpected crashes, slower performance, or unfamiliar programs running in the background. You might also notice changes in your browser settings or the appearance of unwanted toolbars and extensions. Additionally, if you're experiencing frequent pop-ups, redirects to suspicious websites, or finding unfamiliar files and folders on your computer, it could be a sign of a Trojan infection.

How to Remove Trojan.Dridex.G

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download necessary tools while minimizing system activity.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that you don't recognize or that were installed around the time you noticed the infection symptoms. Be cautious and only remove programs you're sure are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This step can help remove any malicious extensions or settings changes made by the Trojan. Note that this will also remove any saved passwords and custom settings, so you may want to export your bookmarks and settings before resetting.
  5. After completing the above steps, reboot your computer and perform another full scan to ensure no remnants of the malware remain. This final scan is crucial to confirm the removal of Trojan.Dridex.G and to check for any other potential threats.

Conclusion

Removing Trojan.Dridex.G requires careful and systematic steps to ensure the malware is completely eradicated from your system. It's also important to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading files from the internet. By following the guidance provided and maintaining good cybersecurity practices, you can protect your system and personal data from similar threats in the future.

Analysis Report

General information

Family Name: Trojan.Dridex.G
Signature status: No Signature

Known Samples

MD5: 757d06b3a08f350715293e06ea13ff78
SHA1: 8c5c483e45418343839bcf4aa7d38481779b71e4
SHA256: F4A246F81DD18E0BCD977CCE37E712C4C714D41F51E69D5599DAFBEBA615EAD5
File Size: 391.68 KB, 391680 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Acala Software.
File Description Acala Auto ipdate
File Version 2.0.0.1
Internal Name Autoipdate.exe

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 4
Whitelisted Blocks: 2
Unknown Blocks: 4

Visual Map

x ? ? x 0 ? ? 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • VirtualAllocEx
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...