Trojan

What is “Trojan:Win32/Redline.GMX!MTB”?

Malware Removal

The Trojan:Win32/Redline.GMX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.GMX!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Redline.GMX!MTB?


File Info:

name: 4C8A8FA085BD09A3FCFA.mlw
path: /opt/CAPEv2/storage/binaries/ab7ec0387c051d1e75eb4a921ac523f1802663a09c099271026929f91a951701
crc32: F7D87300
md5: 4c8a8fa085bd09a3fcfa92829bfecc75
sha1: a745696fd948b87c4698a20012623aa6c8d96ea1
sha256: ab7ec0387c051d1e75eb4a921ac523f1802663a09c099271026929f91a951701
sha512: cbecd993b3b5950d0908bf6f6f088ced2a017e1dcad53440c8e9f8deff67f50e94cda3494225e60be4669d9d94ba04fc4a3f9496f9029d57137ebbc0f924923a
ssdeep: 12288:lQ8Uddcc/z+LlkDTZetL7/SWwyI/QJB1hl+eKuBkOp12HzU/ferLk0dmoZl/Vzmu:iddf/z+LlkDTZeoJBYJB15x5pq9fkw
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19475BF3038A088A2DFA219BF46FDB7D675AD91B407369CC7139439EFA7046C16E37582
sha3_384: 1df32b2bcb31a07f84761230051163659c6a50055f74b0113eca8fe8b46f803890dd994ea77d5b201a7436ec3350ff4a
ep_bytes: e9c5b70100e9e91a0700e93bfd0400e9
timestamp: 2023-11-25 16:41:04

Version Info:

0: [No Data]

Trojan:Win32/Redline.GMX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Kysler.1
FireEyeGen:Heur.Kysler.1
SkyhighBehavesLike.Win32.Generic.th
McAfeeArtemis!4C8A8FA085BD
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4377916
K7AntiVirusTrojan ( 005add031 )
AlibabaTrojanSpy:Win32/Redline.fcd33615
K7GWTrojan ( 005add031 )
ArcabitTrojan.Kysler.1
VirITTrojan.Win32.GenusT.DTXP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVNG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Heur.Kysler.1
NANO-AntivirusTrojan.Win32.Kryptik.kenmyo
AvastWin32:PWSX-gen [Trj]
TencentTrojan-Spy.Win32.Stealer.kaa
EmsisoftGen:Heur.Kysler.1 (B)
F-SecureTrojan.TR/AD.Nekark.hmyan
DrWebTrojan.DownLoader46.36269
VIPREGen:Heur.Kysler.1
TrendMicroTrojanSpy.Win32.LUMMASTEALER.YXDK4Z
SophosMal/Generic-S
IkarusTrojan.Win32.Redline
JiangminTrojanSpy.Stealer.ajkc
VaristW32/Kryptik.KYF.gen!Eldorado
AviraTR/AD.Nekark.hmyan
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Redline.GMX!MTB
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.PSE.17WEUN3
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5553599
VBA32BScope.Backdoor.Agent
ALYacGen:Heur.Kysler.1
MAXmalware (ai score=86)
MalwarebytesTrojan.Injector
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.LUMMASTEALER.YXDK4Z
RisingBackdoor.Agent!8.C5D (TFE:5:FI2gQdvqmYP)
YandexTrojan.Kryptik!OwwoFj5Zet4
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redline.GMX!MTB?

Trojan:Win32/Redline.GMX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment