Trojan

Should I remove “Trojan-PSW.Win32.Reline.us”?

Malware Removal

The Trojan-PSW.Win32.Reline.us is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Reline.us virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-PSW.Win32.Reline.us?


File Info:

name: 4CB1BD6C9C4AE855DB0F.mlw
path: /opt/CAPEv2/storage/binaries/46ac20a6cb7d8111b8ca8e96d5c377833f3d7c663d48912c17584c7f5d3ca12e
crc32: D5D06331
md5: 4cb1bd6c9c4ae855db0f42acde4deb64
sha1: ccfcae1b80168a20f24c6b69092ae7d297dafcf8
sha256: 46ac20a6cb7d8111b8ca8e96d5c377833f3d7c663d48912c17584c7f5d3ca12e
sha512: 8d337e5f24273207b4408aa3511daef9830abb2ddc61f791529a3e86c45543600c2daae6b0db5ddc7a608733e7a2df3afd083ab0130af0083094751b91b5399f
ssdeep: 6144:SznwwwVeujkN+kSfbQf14XZEs3ZCbgfBr8ELlZzCNGqJAXhDcmnIaps6SFMIznoH:zeVskSfbQt42spZBr8ErHPnthoMIz8QE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102A4D1A17D320883D43B8BBDC421A78A88B8D05E711725BF71A876242C1E9DD9F4F57E
sha3_384: 4d121dac3b0826fb16c4b033108a80941e22559ec109001d91b59bc6ebdf5d36804f2b1fbd8a487296b99c94f74dfd1f
ep_bytes: eb05f70c63d5ce50eb058ff5093ae2e8
timestamp: 2068-02-11 04:57:50

Version Info:

FileDescription: AdGuard Web Installer
LegalCopyright: (C) 2009-2018 Adguard Software Ltd
ProductName: AdGuard Web Installer
ProductVersion: 1.0
CompanyName: Adguard Software Ltd
Translation: 0x0409 0x04b0

Trojan-PSW.Win32.Reline.us also known as:

LionicTrojan.Win32.Reline.i!c
DrWebTrojan.PWS.Stealer.31805
MicroWorld-eScanTrojan.GenericKD.47612444
FireEyeGeneric.mg.4cb1bd6c9c4ae855
CAT-QuickHealTrojanpws.Reline
ALYacTrojan.GenericKD.47612444
CylanceUnsafe
ZillyaTrojan.Reline.Win32.6144
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Reline.537c24e0
K7GWTrojan ( 0058b8b41 )
K7AntiVirusTrojan ( 0058b8b41 )
BitDefenderThetaGen:NN.ZexaF.34084.Dq3@a4P2hDni
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.BIR
TrendMicro-HouseCallTROJ_FRS.0NA103L921
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Reline.us
BitDefenderTrojan.GenericKD.47612444
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.47612444
EmsisoftTrojan.Agent (A)
ComodoTrojWare.Win32.UMal.fpwhb@0
TrendMicroTROJ_FRS.0NA103L921
McAfee-GW-EditionRDN/GenericAC
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataWin32.Trojan-Stealer.CredStealer.P1SKSE
JiangminTrojan.PSW.Reline.my
WebrootW32.Trojan.Gen
AviraTR/PSW.Reline.A
Antiy-AVLTrojan/Generic.ASMalwS.34EB96B
KingsoftWin32.PSWTroj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.vb
ViRobotTrojan.Win32.Z.Sabsik.485968
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
Acronissuspicious
McAfeeRDN/GenericAC
VBA32TScope.Malware-Cryptor.SB
MalwarebytesSpyware.RedLineStealer
APEXMalicious
RisingTrojan.Generic@ML.88 (RDMK:AvWGN6WovRVTlAqmCXJUog)
YandexTrojan.PWS.Reline!JPf81KgP1V0
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan-PSW.Win32.Reline.us?

Trojan-PSW.Win32.Reline.us removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment