Trojan

Trojan:MSIL/RedLineStealer.KAI!MTB removal

Malware Removal

The Trojan:MSIL/RedLineStealer.KAI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/RedLineStealer.KAI!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/RedLineStealer.KAI!MTB?


File Info:

name: 58B5E1651F22758360E2.mlw
path: /opt/CAPEv2/storage/binaries/338a9ed485b7c08b597c939fe179b45da817e793fe2114be6250f33c58efc6e8
crc32: F673EC01
md5: 58b5e1651f22758360e232c203161384
sha1: 9117da79734dd03a122b99c18f9fc9ce4c1b337b
sha256: 338a9ed485b7c08b597c939fe179b45da817e793fe2114be6250f33c58efc6e8
sha512: 6be1ca77ba3d802e463b4d0272256b40e0b306e2c9ee3b51841194cd2a58edfd19683acf2ae558d0445ae3c351a96162cc8f5ecd1ab1774f1632771da07e4fab
ssdeep: 6144:paNimhRi9vYZ4uCm7KkjnI0jiYMN4x3zzGwJCil/6tuOO1jjkgXhzJU:E/hw9vYZ4eW85jiYM+RzLCixcuB1nkg4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AB7423ACEA132811CC0E18B17585D8212BF093C4D6DBD46AF2D5A854AF263CF7FA438D
sha3_384: e0ef15c6f380c23d1ae8b18e45ff4a0c78c40091aa32e061c2049dd4f8e337bd4c1274c3e63107fcd679cd6114464689
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-02-25 11:51:27

Version Info:

Translation: 0x0000 0x04b0
Comments: Ionosondes Defensemen Wrenchingly
CompanyName: Entertainment Network
FileDescription: Permittee
FileVersion: 1.0.0.0
InternalName: Displacement.exe
LegalCopyright: Copyright 2023
OriginalFilename: Displacement.exe
ProductName: Troubling Ultravacuum Legitimator
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/RedLineStealer.KAI!MTB also known as:

BkavW32.AIDetectMalware.CS
AVGWin32:PWSX-gen [Trj]
DrWebTrojan.Inject5.2873
MicroWorld-eScanGen:Variant.Ser.Zusy.4899
FireEyeGeneric.mg.58b5e1651f227583
SkyhighArtemis!Trojan
McAfeeArtemis!58B5E1651F22
MalwarebytesTrojan.Crypt.MSIL
SangforTrojan.Msil.Kryptik.Vwkl
K7AntiVirusTrojan ( 005b21931 )
AlibabaTrojan:MSIL/RedLineStealer.2488514c
K7GWTrojan ( 005b21931 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36802.vm2@aKzudCj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.ALAE
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Injuke.gen
BitDefenderGen:Variant.Ser.Zusy.4899
NANO-AntivirusTrojan.Win32.Injuke.kkalim
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:Z4nzjYtmw2fCE5AObRhxPQ)
SophosTroj/Steal-DVK
F-SecureTrojan.TR/AD.RedLineSteal.wojyt
ZillyaTrojan.GenKryptik.Win32.494486
TrendMicroTrojanSpy.Win32.REDLINE.YXEBZZ
EmsisoftGen:Variant.Ser.Zusy.4899 (B)
IkarusTrojan.MSIL.Krypt
GoogleDetected
AviraTR/AD.RedLineSteal.wojyt
Kingsoftmalware.kb.c.929
MicrosoftTrojan:MSIL/RedLineStealer.KAI!MTB
ArcabitTrojan.Ser.Zusy.D1323
ZoneAlarmHEUR:Trojan.MSIL.Injuke.gen
GDataGen:Variant.Ser.Zusy.4899
VaristW32/MSIL_Agent.HQD.gen!Eldorado
AhnLab-V3Trojan/Win.PWSX-gen.C5593732
ALYacGen:Variant.Ser.Zusy.4899
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXEBZZ
TencentMalware.Win32.Gencirc.11bcd61f
MAXmalware (ai score=83)
MaxSecureTrojan.Malware.74181957.susgen
FortinetMSIL/GenKryptk.GUGT!tr
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/RedLineStealer.KAI!MTB?

Trojan:MSIL/RedLineStealer.KAI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment