Spy

Spyware.RedLineStealer.Drop removal instruction

Malware Removal

The Spyware.RedLineStealer.Drop is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.RedLineStealer.Drop virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Spyware.RedLineStealer.Drop?


File Info:

name: F12F1035317627F5382D.mlw
path: /opt/CAPEv2/storage/binaries/1c7912da99477b5d5fc713d74f2c268b95d6dec76c3bfd794e4e7f5d5d21dec7
crc32: CF950F69
md5: f12f1035317627f5382d55182cfe8473
sha1: e36be5b7c32a793514e8734d70171ab5178b47b7
sha256: 1c7912da99477b5d5fc713d74f2c268b95d6dec76c3bfd794e4e7f5d5d21dec7
sha512: dfb2f5434b59b5989ad8c3bf1adfca69d096d81b064d8144777646d6c715251729fc9b1379e7a84dea6c348b171342683e7d71be743b4b1b37429538799aa6fe
ssdeep: 6144:xdRVzSkGTxSLD8uq5CaOPs47bhqUdJcdfkjD31l4mQ9xA:xhqxSLo5C1Ps4XhHcd8X31XQrA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F74D003F9C58872D5221A311A39B751693EB9201F188ADFB3E84D6DEB351E17335AB3
sha3_384: d32e65b1196006e21f7dc15d657e35b64f46f023429e0b8fdf7d565906a2c7ea9a29f6a5ba8748bfea64664f7f502b35
ep_bytes: e884040000e988feffff3b0d68d64300
timestamp: 2020-06-25 10:38:24

Version Info:

0: [No Data]

Spyware.RedLineStealer.Drop also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.453341
FireEyeGen:Variant.Bulz.453341
McAfeeArtemis!F12F10353176
CylanceUnsafe
SangforTrojan.MSIL.Dropper.Gen2
K7AntiVirusTrojan-Downloader ( 0057c3731 )
AlibabaRansom:MSIL/Blocker.6b68453b
K7GWTrojan-Downloader ( 0057c3731 )
BitDefenderThetaGen:NN.ZemsilF.34062.im1@a8FBUne
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HWQ
TrendMicro-HouseCallRansom_Blocker.R011C0WDU21
Paloaltogeneric.ml
KasperskyUDS:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Variant.Bulz.453341
NANO-AntivirusTrojan.Win32.Ransom.iuzxtl
AvastWin32:DangerousSig [Trj]
TencentWin32.Trojan.Falsesign.Dzjj
SophosMal/Generic-S
TrendMicroRansom_Blocker.R011C0WDU21
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Bulz.453341 (B)
IkarusTrojan-Dropper.MSIL.Agent
GDataGen:Variant.Bulz.453341
AviraTR/Dropper.MSIL.Gen2
Antiy-AVLTrojan[Downloader]/MSIL.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.453341
MAXmalware (ai score=89)
MalwarebytesSpyware.RedLineStealer.Drop
APEXMalicious
YandexTrojan.DR.MSIL!Wt3Yd9ux+M4
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.R011C0WDU21!tr
AVGWin32:DangerousSig [Trj]
PandaTrj/Genetic.gen

How to remove Spyware.RedLineStealer.Drop?

Spyware.RedLineStealer.Drop removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment