Trojan

Trojan:Win32/Redline.CBEB!MTB removal

Malware Removal

The Trojan:Win32/Redline.CBEB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.CBEB!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.CBEB!MTB?


File Info:

name: FF7B345435C3DD03167E.mlw
path: /opt/CAPEv2/storage/binaries/9c497c8a4f6545448ab0fe418747425b9cc55c447fb21723b36a17e176bd35bd
crc32: A387FA38
md5: ff7b345435c3dd03167eb132cc1d3e50
sha1: 6325e258679183caf98bdd5795df091e8995c4fa
sha256: 9c497c8a4f6545448ab0fe418747425b9cc55c447fb21723b36a17e176bd35bd
sha512: 916d7d73155504611554d35ca5f3ae49d6eaafe7860f2f45dbbd6c9db569a01be35921c62b9814940c336056cf62dde54df5ddb6ece94385ba6d0928b1161f44
ssdeep: 24576:NBWxgHnG6Zw1lLHeryR2P7ZZJ4Ldu4YrLa6NThfYtMExML:NTG6Zw1lL+OR2F4dulLa63fYtMExM
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A5653E1132F94769F6F3CF785A76A6B14A7ABC69DD10C29E1251D80ECD31B90C860B3B
sha3_384: 3dc5c5d9b8e56392f47ebc702f5d179a89bab9ce870122ecd92d1590323bdbd39499735706a50ec31cfcf74d59e2b7cd
ep_bytes: e8430d0000e929feffff8b4df464890d
timestamp: 2023-08-24 23:43:12

Version Info:

0: [No Data]

Trojan:Win32/Redline.CBEB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader46.1295
MicroWorld-eScanGen:Variant.Lazy.381463
ClamAVWin.Malware.Exploitx-9967939-0
FireEyeGen:Variant.Lazy.381463
McAfeeArtemis!FF7B345435C3
Cylanceunsafe
SangforInfostealer.Win32.Redline.V33k
AlibabaTrojanSpy:Win32/Stealer.83d7241f
BitDefenderThetaGen:NN.ZexaF.36662.CzW@aSIr3Qji
VirITTrojan.Win32.GenusT.DQCU
CyrenW32/ABRisk.LVZO-1778
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GNEK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Lazy.381463
NANO-AntivirusTrojan.Win32.Stealer.jywszg
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.11b5b3bb
SophosMal/Generic-S
F-SecureTrojan.TR/Injector_AGen.cxweb
VIPREGen:Variant.Lazy.381463
TrendMicroTrojanSpy.Win32.REDLINE.YXDHZZ
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Lazy.381463 (B)
GDataGen:Variant.Lazy.381463
JiangminTrojanSpy.Stealer.aiic
AviraTR/Injector_AGen.cxweb
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Lazy.D5D217
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Redline.CBEB!MTB
GoogleDetected
VBA32BScope.TrojanPSW.RedLine
ALYacGen:Variant.Lazy.381463
MAXmalware (ai score=86)
MalwarebytesMalware.AI.3588093746
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDHZZ
RisingBackdoor.Agent!8.C5D (TFE:5:pkqPjMAU9tR)
YandexTrojan.GenKryptik!x5hn5GMRGYg
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ETBS!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redline.CBEB!MTB?

Trojan:Win32/Redline.CBEB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment