Trojan

How to remove “Trojan:Win32/Redline.GFV!MTB”?

Malware Removal

The Trojan:Win32/Redline.GFV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.GFV!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the RedLine malware family
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.GFV!MTB?


File Info:

name: 42D8D60FCC396927B91B.mlw
path: /opt/CAPEv2/storage/binaries/790dca1792f05311c08c283279d3a9f424f44db35d8eb2c13defc5123260b8b9
crc32: 5A16E888
md5: 42d8d60fcc396927b91bec01f2df475a
sha1: b11434e583b06e2a4a1e2f3970597dc87f6d5166
sha256: 790dca1792f05311c08c283279d3a9f424f44db35d8eb2c13defc5123260b8b9
sha512: 36a76f2b1a6ac050e399f6f31e64d0feca1545f4a5977f138d15a7cd6bd69e0f243caffa962c88950f8e20458c5cca7a91b024182643b15f72e8885f4616b60e
ssdeep: 24576:it0mgo7IYRQq6madDc0MFjRGSucplKTg4s5mCN0TU8/ByKJh0otC:i1T7I5fAXjRGStlKFss1Tj/Byqh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F451303A691B8E2FB6741354F1ED598BA6FB5318E4C9643331C6A3F19B02F2C2A7315
sha3_384: 18675db168c5d79778c481fb2b873cdab2da61ef346d5ab0fbf48ba25231dcb00d0b2e295ffe421cfcf2a42225b1a182
ep_bytes: e8893d0000e979feffffcccccccccccc
timestamp: 2021-12-26 09:47:32

Version Info:

FilesVersion: 15.15.66.51
InternalNamy: GoalHard
LegalasCopyright: Copyright (C) 2023, shmaer
ProductNames: SmothPath
Translation: 0x04fe 0x03ff

Trojan:Win32/Redline.GFV!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
tehtrisGeneric.Malware
DrWebTrojan.PWS.Stealer.35775
MicroWorld-eScanTrojan.GenericFCA.Agent.78256
FireEyeGeneric.mg.42d8d60fcc396927
McAfeePacked-GEE15!42D8D60FCC39
Cylanceunsafe
ZillyaTrojan.Stealer.Win32.41458
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericFCA.Agent.78256
K7GWTrojan ( 005a14b01 )
K7AntiVirusTrojan ( 005a14b01 )
ArcabitTrojan.GenericFCA.Agent.D131B0
VirITTrojan.Win32.Genus.OWO
CyrenW32/Kryptik.JGU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTCP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packer.pkr_ce1a-9980177-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
AlibabaTrojanSpy:Win32/Stealer.d6cc5073
NANO-AntivirusTrojan.Win32.Upatre.jvibuo
ViRobotTrojan.Win.Z.Stealer.1164800.N
RisingTrojan.Kryptik!1.E3DA (CLASSIC)
SophosTroj/Krypt-VZ
F-SecureHeuristic.HEUR/AGEN.1316578
VIPRETrojan.GenericFCA.Agent.78256
TrendMicroTROJ_GEN.R002C0DCN23
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericFCA.Agent.78256 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.PSW.Rhadamanthus.al
AviraHEUR/AGEN.1316578
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Sabsik
MicrosoftTrojan:Win32/Redline.GFV!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.pef
GDataTrojan.GenericFCA.Agent.78256
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R565073
Acronissuspicious
ALYacTrojan.GenericFCA.Agent.78256
TACHYONTrojan-Spy/W32.InfoStealer.1164800.C
DeepInstinctMALICIOUS
VBA32BScope.Trojan-Banker.UrSnif
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DCN23
TencentTrojan.Win32.Obfuscated.gen
YandexTrojan.Kryptik!BDmhBcImoq8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/GenKryptik.GHYM!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.583b06
AvastWin32:CrypterX-gen [Trj]

How to remove Trojan:Win32/Redline.GFV!MTB?

Trojan:Win32/Redline.GFV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment