Trojan

How to remove “Trojan:Win32/RedLine.BD!MTB”?

Malware Removal

The Trojan:Win32/RedLine.BD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.BD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/RedLine.BD!MTB?


File Info:

name: 3A11C5557CF099750857.mlw
path: /opt/CAPEv2/storage/binaries/4751d2c0e00c7dbfda3c85e4a4e1a65437f05714605b76d14c2796435f67938d
crc32: EC5CE4B9
md5: 3a11c5557cf09975085718d26eb081df
sha1: a145bf9386b3e9c480e0d49a621acbe028cd90e5
sha256: 4751d2c0e00c7dbfda3c85e4a4e1a65437f05714605b76d14c2796435f67938d
sha512: e634ee2f415b311722ac01b571997e3fb3b14d1fa86c23c2be62784eb508f2aa0c29d4f98fb3bfbaf34e4e46adfd426216f35227139a5b8be59ea2c50ffe6586
ssdeep: 6144:NxbsyfrmiWMGrbzG7wgpMxBGS6hF6CjqKwmENXDSYVM6V2o:NZ7KiWMGrO7wgpMxBGvhMC2/leYVM0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A64F1327A909471D4A35A3014B8D7A55F7BF8431A74484B3BA8277A5FA13D0AF3C36B
sha3_384: 0017bd28bb143e4160158fa3b4526f40e74a642996aee4d6f5e8d6b2f0e3f0b1dedbe564268d906810b578fc2a41413f
ep_bytes: e87f400000e989feffff8bff558bec83
timestamp: 2022-07-26 02:43:23

Version Info:

CompanyName: PakistanFoods
FileDescription: Bluetooth
FileVersions: 37.23.85.90
InternalName: splash.exe
LegalCopyright: Naughtly reason inc.
ProdName: SilverVision
Translation: 0x4049 0x0566

Trojan:Win32/RedLine.BD!MTB also known as:

LionicTrojan.Win32.Denes.4!c
MicroWorld-eScanTrojan.GenericKD.65609990
FireEyeGeneric.mg.3a11c5557cf09975
CAT-QuickHealTrojan.Redline
ALYacTrojan.GenericKD.65609990
MalwarebytesTrojan.MalPack.GS
VIPRETrojan.GenericKD.65609990
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059f5141 )
AlibabaTrojan:Win32/Denes.10f75b62
K7GWTrojan ( 0059f5141 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/ABRisk.SGKP-2767
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HSUF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Denes.pef
BitDefenderTrojan.GenericKD.65609990
AvastWin32:PWSX-gen [Trj]
TencentTrojan-Ransom.Win32.Stop.gen
EmsisoftTrojan.GenericKD.65609990 (B)
DrWebTrojan.DownLoader45.45076
ZillyaTrojan.Denes.Win32.1052
TrendMicroTrojanSpy.Win32.REDLINE.YXDBUZ
McAfee-GW-EditionPacked-GEE10!3A11C5557CF0
Trapminemalicious.high.ml.score
SophosTroj/Krypt-VE
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.1YUIOLR
JiangminBackdoor.Mokes.hkq
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.ytlur
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
ArcabitTrojan.Generic.D3E92106
ViRobotTrojan.Win.Z.Pe_A.312760
MicrosoftTrojan:Win32/RedLine.BD!MTB
GoogleDetected
AhnLab-V3Trojan/Win.PWSX-gen.R559499
McAfeeArtemis!3A11C5557CF0
VBA32Malware-Cryptor.2LA.gen
Cylanceunsafe
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDBUZ
RisingTrojan.Kryptik!1.E2CC (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.ZDS
AVGWin32:PWSX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Trojan:Win32/RedLine.BD!MTB?

Trojan:Win32/RedLine.BD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment