Trojan

Trojan:Win32/RedLine.DB!MTB malicious file

Malware Removal

The Trojan:Win32/RedLine.DB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.DB!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.DB!MTB?


File Info:

name: C05262D8F76B40DC7435.mlw
path: /opt/CAPEv2/storage/binaries/d0a2b8d80b4cdbf68d9becc7f3018dc81a0d1342b89e1ff3cedd2d6a027f0b97
crc32: 2F0098AB
md5: c05262d8f76b40dc7435b885a37881ad
sha1: beb09da855466814f88ead4f121afa77d466c77d
sha256: d0a2b8d80b4cdbf68d9becc7f3018dc81a0d1342b89e1ff3cedd2d6a027f0b97
sha512: 9aa9f884038e156de6ae089e22bac57eccf82b9f6c7e2600e4636eac7ef9133fe3d70842d2ca36504d1bdf13b33d640026d30e76e5dd4cba243f615c04f239bb
ssdeep: 24576:MlyQC29Ad87kHCQWRegu26oR5W7jZy+1:Mot87kHC4gP697jZy+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15535AF22398590B1EEE220F742ECB66E466ED0B4075456DF06E56AEFC7603C17B3368D
sha3_384: 0e65178fe9bc8302030b3b076498217dddb0b63d07dd560cb1b750846f9a19f5945e99c6c638f9b4c82948eb636a6029
ep_bytes: e9d40a0400e97c790500e945910400e9
timestamp: 2023-10-29 06:35:42

Version Info:

0: [No Data]

Trojan:Win32/RedLine.DB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mokes.4!c
MicroWorld-eScanTrojan.Agent.GHOJ
FireEyeTrojan.Agent.GHOJ
CAT-QuickHealTrojan.StealercPMF.S31323732
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXWL-YO!C05262D8F76B
Cylanceunsafe
VIPRETrojan.Agent.GHOJ
K7AntiVirusTrojan ( 005ac80f1 )
BitDefenderTrojan.Agent.GHOJ
K7GWTrojan ( 005ac80f1 )
ArcabitTrojan.Agent.GHOJ
BitDefenderThetaGen:NN.ZexaF.36744.dDW@a8Siowm
VirITTrojan.Win32.Genus.TXA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HVLV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
AlibabaTrojanPSW:Win32/RedLine.ebaa2e7b
NANO-AntivirusTrojan.Win32.Injuke.kcvpbg
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Kryptik.kbbq
EmsisoftTrojan.Agent.GHOJ (B)
F-SecureTrojan.TR/AD.Nekark.xeiwk
DrWebTrojan.DownLoader46.28389
ZillyaTrojan.Kryptik.Win32.4349182
TrendMicroTROJ_GEN.R002C0DK423
SophosTroj/Krypt-ABY
IkarusTrojan.Win32.Agent
JiangminBackdoor.Mokes.hsj
VaristW32/Kryptik.KNN.gen!Eldorado
AviraTR/AD.Nekark.xeiwk
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Kryptik.huyh
KingsoftWin32.Hack.Mokes.gen
MicrosoftTrojan:Win32/RedLine.DB!MTB
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.1JK18K6
GoogleDetected
AhnLab-V3Trojan/Win.Stealerc.R618806
VBA32Backdoor.Mokes
ALYacTrojan.Agent.GHOJ
TACHYONBackdoor/W32.Mokes.1109504
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DK423
RisingBackdoor.Convagent!8.123DC (TFE:5:QN8nk0L4j1E)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLine.DB!MTB?

Trojan:Win32/RedLine.DB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment