Trojan

Should I remove “Trojan:Win32/Redline.ASBG!MTB”?

Malware Removal

The Trojan:Win32/Redline.ASBG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.ASBG!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.ASBG!MTB?


File Info:

name: 0629E92D916D7310C80A.mlw
path: /opt/CAPEv2/storage/binaries/a05d785c04bec88bb68f6d01375867d81644ce524fcb8a9a95b823758f01a8af
crc32: 0C5E2931
md5: 0629e92d916d7310c80a43981d03e6fe
sha1: fc4fab4460f0c0471762d9ca33c052f896504960
sha256: a05d785c04bec88bb68f6d01375867d81644ce524fcb8a9a95b823758f01a8af
sha512: 6d19af2752c5c7e7ab7e0aa91844cfdea8f7f392f9684237e5f01e344af78613b4b9c4a10fe8718ecce72b69b110a63bb3244fad3a0f68357c254c9305aab3bd
ssdeep: 12288:fC9oudYAEg29AzB87kHCYbAVnReEbUjHpkpuWSeNJQ4peapdy87Cr2KK:flKYM29Ad87kHCwWRewu0dym
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF259E1139C08075EEF320B7A6EDBA6E42EDD864075916DF06DC5BEED7606C13E32682
sha3_384: 85721219851766f9f7d49f5b5611729913740f9357b584bff6ef1ed9b6b53b33d72f21eb9a159a2f799000164ce089e0
ep_bytes: e9d40a0400e97c790500e945910400e9
timestamp: 2023-10-28 10:25:18

Version Info:

0: [No Data]

Trojan:Win32/Redline.ASBG!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.103861
FireEyeTrojan.GenericKDZ.103861
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXAA-AA!0629E92D916D
MalwarebytesTrojan.MalPack.RND
BitDefenderTrojan.GenericKDZ.103861
CrowdStrikewin/malicious_confidence_70% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUYH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Backdoor.Win32.Mokes.gen
NANO-AntivirusTrojan.Win32.Injuke.kcvpbg
RisingBackdoor.Convagent!8.123DC (TFE:1:yKg2Il94czN)
F-SecureTrojan.TR/AD.RedLineSteal.atbul
VIPRETrojan.GenericKDZ.103861
EmsisoftTrojan.GenericKDZ.103861 (B)
IkarusTrojan.Win32.Agent
VaristW32/Kryptik.KNN.gen!Eldorado
AviraTR/AD.RedLineSteal.atbul
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Redline.ASBG!MTB
ArcabitTrojan.Generic.D195B5
ZoneAlarmHEUR:Backdoor.Win32.Mokes.gen
GDataTrojan.GenericKDZ.103861
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36792.aDW@aKPzkTh
ALYacTrojan.GenericKDZ.103861
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
VBA32Backdoor.Mokes
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/Redline.ASBG!MTB?

Trojan:Win32/Redline.ASBG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment