Trojan

Trojan:Win32/RedLine.DB!MTB information

Malware Removal

The Trojan:Win32/RedLine.DB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.DB!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.DB!MTB?


File Info:

name: 21DC2EC7A73AC01CE4F3.mlw
path: /opt/CAPEv2/storage/binaries/213ab89a5f2fd9198cce6ea36d651df5d2447740493e4ab092481b19a976d02f
crc32: 32F91D26
md5: 21dc2ec7a73ac01ce4f3f9aec348c8d0
sha1: 4811880671112ba22721b26c971d3246aaa31f55
sha256: 213ab89a5f2fd9198cce6ea36d651df5d2447740493e4ab092481b19a976d02f
sha512: 1e786849600a4aee6d17c60b23b7e0bd11999666987947d15e01990b7e030bcba668729843e41e8c0cbda4216a7951a092614cc027335ee9288fdda67947957d
ssdeep: 12288:oC9QYpUdkM29AFD87kHC8D/hRR2CbUjGLkUuWSO6RKK:ot8Uj29AZ87kHCAfR2uur
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5158D2139C081B2EEF320B747ECBA6683ADD4B4071516DF06D85BEED7606C17B36686
sha3_384: 9b52cb09ba292da1e05c941c428410a23105b72457a35eab93fedc58d5a48ebecc69181aca184400b52faf7f083e99d5
ep_bytes: e9d40a0400e97c790500e945910400e9
timestamp: 2023-10-29 04:25:50

Version Info:

0: [No Data]

Trojan:Win32/RedLine.DB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader46.28389
ClamAVWin.Packed.Pwsx-10012424-0
SkyhighBehavesLike.Win32.Smokeloader.dm
ALYacTrojan.GenericKDZ.103861
MalwarebytesTrojan.Crypt
VIPRETrojan.GenericKDZ.103861
K7AntiVirusTrojan ( 005ac7d11 )
BitDefenderTrojan.GenericKDZ.103861
K7GWTrojan ( 005ac7d11 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.4CW@aOdscAh
VirITTrojan.Win32.Genus.TXA
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HUYH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
NANO-AntivirusTrojan.Win32.Injuke.kcvpbg
ViRobotTrojan.Win.Z.Kryptik.921600.Y
MicroWorld-eScanTrojan.GenericKDZ.103861
RisingBackdoor.Convagent!8.123DC (TFE:5:QN8nk0L4j1E)
EmsisoftTrojan.GenericKDZ.103861 (B)
F-SecureTrojan.TR/AD.SmokeLoader.dhgip
ZillyaTrojan.Kryptik.Win32.4349182
TrendMicroTROJ_GEN.R002C0DK423
FireEyeTrojan.GenericKDZ.103861
SophosTroj/Krypt-ABY
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1JK18K6
VaristW32/Kryptik.KNN.gen!Eldorado
AviraTR/AD.SmokeLoader.dhgip
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Kryptik
GridinsoftTrojan.Win32.Amadey.bot
ArcabitTrojan.Generic.D195B5
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
MicrosoftTrojan:Win32/RedLine.DB!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R618872
McAfeeGenericRXAA-AA!21DC2EC7A73A
TACHYONBackdoor/W32.Mokes.921600
DeepInstinctMALICIOUS
VBA32Backdoor.Mokes
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK423
TencentTrojan.Win32.Kryptik.kbbq
YandexTrojan.Kryptik!UVTmIzY8udM
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/RedLine.DB!MTB?

Trojan:Win32/RedLine.DB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment