Trojan

Trojan:Win32/RedLine.DB!MTB removal tips

Malware Removal

The Trojan:Win32/RedLine.DB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.DB!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.DB!MTB?


File Info:

name: A4F805726DC131854717.mlw
path: /opt/CAPEv2/storage/binaries/757af145de8dafd8839c575137a8a771425a7e52284c51a155d656a5dbb8ef2e
crc32: 0CF71930
md5: a4f805726dc1318547173f521d50ce79
sha1: 1b2ccddeaea2e78ec665fea26fee5461811a6470
sha256: 757af145de8dafd8839c575137a8a771425a7e52284c51a155d656a5dbb8ef2e
sha512: 8a5f1bea5442451c9600b48064df40c454fd920b9d825a84635a1322db4d6ddbe342b5273af159c38e6f4506c1ce2f86611896769057c6db0404cd23f19fdf50
ssdeep: 12288:FqEmWjVR2nmfCMLug57y5Dc+8dO+8ZKqNMDc7ulyoyVVxhoNbwXBaV:FbynmfCMLug5GJ7FZKqN5cwRa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11535AF21BAF180B6EDE320B7C6FCF93146AFE0B0071549CB069957EED6145C1AF32686
sha3_384: 241048a38de6641282bcdfb74fd5dc25f7ead30cc0c9cab665ec6d5381d54ddcd0e0f185e9da727333153d8a2f7972e7
ep_bytes: e966e80300e9be2d0600e9f06e0400e9
timestamp: 2023-10-31 23:03:24

Version Info:

0: [No Data]

Trojan:Win32/RedLine.DB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Redline.i!c
Elasticmalicious (high confidence)
DrWebTrojan.AntiAVNET.3
MicroWorld-eScanGen:Variant.Zusy.517442
FireEyeGen:Variant.Zusy.517442
SkyhighBehavesLike.Win32.Sabsik.th
ALYacGen:Variant.Zusy.517442
Cylanceunsafe
VIPREGen:Variant.Zusy.517442
SangforInfostealer.Win32.Redline.Vn7x
K7AntiVirusTrojan ( 005ac7d11 )
BitDefenderGen:Variant.Zusy.517442
K7GWTrojan ( 005ac7d11 )
VirITTrojan.Win32.Genus.TZZ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HUYH
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
AlibabaTrojanPSW:Win32/RedLine.970e950d
NANO-AntivirusTrojan.Win32.Stealerc.kcyktw
RisingBackdoor.Agent!8.C5D (TFE:5:fKpFrkIy1XD)
SophosTroj/Krypt-ABY
F-SecureTrojan.TR/AD.Nekark.fjjoh
TrendMicroTROJ_GEN.R002C0DK123
EmsisoftGen:Variant.Zusy.517442 (B)
IkarusTrojan.Win32.Redline
MAXmalware (ai score=83)
JiangminTrojan.PSW.Stealerc.lw
GoogleDetected
AviraTR/AD.Nekark.fjjoh
VaristW32/Kryptik.KYF.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/RedLine.DB!MTB
ArcabitTrojan.Zusy.D7E542
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.1J5FZX9
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLine.R619460
McAfeeGenericRXAA-AA!A4F805726DC1
TACHYONTrojan-PWS/W32.Stealerc.1100288.B
DeepInstinctMALICIOUS
VBA32BScope.TrojanPSW.RedLine
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK123
TencentMalware.Win32.Gencirc.10bf3fbd
YandexTrojan.Kryptik!c+XFin20OPE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLine.DB!MTB?

Trojan:Win32/RedLine.DB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment