Trojan

What is “Trojan:Win32/Redline.GJX!MTB”?

Malware Removal

The Trojan:Win32/Redline.GJX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.GJX!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Redline.GJX!MTB?


File Info:

name: C4C3FD2EE829367C26B6.mlw
path: /opt/CAPEv2/storage/binaries/aeec8780bdade38ebb5c4c328d20c0efe9f9791682b9c14ff0d233b860f9b312
crc32: B6439FE1
md5: c4c3fd2ee829367c26b6480de480b9dd
sha1: 99a499b57b7e73d609ee58797beaf1409a9db8a7
sha256: aeec8780bdade38ebb5c4c328d20c0efe9f9791682b9c14ff0d233b860f9b312
sha512: a279a22fe7e5758f49c1235900d095dcc13e3280c4350625586d66cfe9e6f9ac5ddf5e28625f4142e67b62a7a4ed2c977d296e410c8e870b8ccb2c2b391999ff
ssdeep: 1536:BSOCUYh3YGZ2fqUkYwY216TuClydopoTX7qQwH7Pxs:UZUMoU2CM+EuCly6oTXejxs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10F939D233990D072D857C870A4B48AE1AFBDF1521BA641873B5DE27F1F263D113BB299
sha3_384: cc27c5fd2df9e84252e61fc2a816aae85649460e26a790a8dc73fcb52d5c53081c89b6365803487d0bc8bc972fadf1ea
ep_bytes: e8173c0000e9a4feffff3b0d2c4d4100
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: Wissol Petreleum Georgia
FileDescription: Wissol Petreleum Georgia Product
FileVersion: 877
InternalName: RP8fe8cSwLZr
LegalCopyright: © Wissol Petreleum Georgia All rights reserved.
LegalTrademarks: © Wissol Petreleum Georgia Trademarks
OriginalFilename: e0K1FNp8.exe
ProductName: GLl8Lox6pF
ProductVersion: 877
Translation: 0x0407 0x04b0

Trojan:Win32/Redline.GJX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.635FDBB5.A.41B17A91
ClamAVWin.Packed.Dacic-10006147-0
FireEyeGeneric.Dacic.635FDBB5.A.41B17A91
CAT-QuickHealTrojan.GenericPMF.S30400730
SkyhighGenericRXWF-QV!C4C3FD2EE829
ALYacGeneric.Dacic.635FDBB5.A.41B17A91
MalwarebytesTrojan.MalPack
VIPREGeneric.Dacic.635FDBB5.A.41B17A91
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a75f91 )
AlibabaTrojan:Win32/Injurer.0853001c
K7GWTrojan ( 005a75f91 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTVT
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderGeneric.Dacic.635FDBB5.A.41B17A91
AvastWin32:PWSX-gen [Trj]
TencentTrojan-Spy.Win32.Stealer.haaq
EmsisoftGeneric.Dacic.635FDBB5.A.41B17A91 (B)
F-SecureTrojan.TR/Crypt.Agent.pxqxv
DrWebTrojan.PWS.RedLineNET.7
ZillyaTrojan.Injurer.Win32.5311
TrendMicroTROJ_GEN.R002C0DG723
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.15XMIPU
JiangminTrojan.PSW.Reline.aep
GoogleDetected
AviraTR/Crypt.Agent.pxqxv
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Trojan.Injurer.gen
ArcabitGeneric.Dacic.635FDBB5.A.41B17A91
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.pef
MicrosoftTrojan:Win32/Redline.GJX!MTB
VaristW32/Kryptik.KDL.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R590027
McAfeeGenericRXWF-QV!C4C3FD2EE829
MAXmalware (ai score=82)
VBA32BScope.TrojanPSW.RedLine
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DG723
RisingBackdoor.Agent!8.C5D (TFE:5:vkYRWNsvAhN)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/Kryptik.HUIM!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redline.GJX!MTB?

Trojan:Win32/Redline.GJX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment