Trojan

About “Trojan:Win32/Redline.CCER!MTB” infection

Malware Removal

The Trojan:Win32/Redline.CCER!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.CCER!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Redline.CCER!MTB?


File Info:

name: 34136DE1723BCF4EEFB5.mlw
path: /opt/CAPEv2/storage/binaries/f1eee33c1f9ecf9480ca073f68b30c610d26a47cf5e48c087e275cc957e2cbc1
crc32: 90582E1D
md5: 34136de1723bcf4eefb5d3e6a05a304d
sha1: 48fffa2325c66329c8f32554434cbce387cd2faf
sha256: f1eee33c1f9ecf9480ca073f68b30c610d26a47cf5e48c087e275cc957e2cbc1
sha512: b50c785ed587e2eb7294ee76bf10826f53125069ab6da3a81caad7a2902f70ebb5272a1cf47b5c3782327e3a1844d8c917dd4d18e005db733309bf78458d7e1c
ssdeep: 12288:Em4zcDZfXgoHnmfBnqB/nWgWhCNzwsGQjY25/paucNJXNuiDwyAkxEjN0lktFDAM:m4ZfZHnmfBqB/nWgWgNzGxE/pudxEBt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3359E217DC582B2EDF210B783EDF66A82BDE4B0072542DF12D857EED7106C16B36296
sha3_384: 17951c956715fe8e1eb2009aa1f562ff93dd3315aa134c3111dcccaa6b5bfd0b9909f8f00693ebcf0f008a1103c1116b
ep_bytes: e9b01a0400e939690600e92ba10400e9
timestamp: 2023-10-26 16:07:24

Version Info:

0: [No Data]

Trojan:Win32/Redline.CCER!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.514822
ClamAVWin.Packed.Pwsx-10012424-0
FireEyeGen:Variant.Zusy.514822
SkyhighBehavesLike.Win32.Sabsik.th
ALYacGen:Variant.Zusy.514822
Cylanceunsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Redline.305f2e99
K7GWTrojan ( 005aa09f1 )
K7AntiVirusTrojan ( 005add031 )
ArcabitTrojan.Zusy.D7DB06
BitDefenderThetaGen:NN.ZexaF.36744.ezW@aeb2cZj
VirITTrojan.Win32.Genus.TWC
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVLV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderGen:Variant.Zusy.514822
NANO-AntivirusTrojan.Win32.Convagent.kcstbv
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Injurer.hg
TACHYONTrojan/W32.Injurer.1118208
SophosTroj/Krypt-ABY
F-SecureTrojan.TR/AD.Nekark.xaqro
DrWebTrojan.Inject4.63403
VIPREGen:Variant.Zusy.514822
TrendMicroTROJ_GEN.R002C0DK123
EmsisoftGen:Variant.Zusy.514822 (B)
IkarusTrojan.Win32.Redline
JiangminTrojan.Injurer.t
GoogleDetected
AviraTR/AD.Nekark.xaqro
Antiy-AVLTrojan/Win32.Kryptik.huyh
MicrosoftTrojan:Win32/Redline.CCER!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.pef
GDataWin32.Trojan.PSE.IMBV54
VaristW32/Kryptik.KNN.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5532119
McAfeeGenericRXAA-AA!34136DE1723B
MAXmalware (ai score=84)
VBA32BScope.TrojanPSW.RedLine
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DK123
RisingBackdoor.Convagent!8.123DC (TFE:5:fvDR64zeDjF)
YandexTrojan.Injector!qmUDtMuzpXE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.ETFD!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Redline.CCER!MTB?

Trojan:Win32/Redline.CCER!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment