Trojan

How to remove “Trojan:Win32/Redline.GNQ!MTB”?

Malware Removal

The Trojan:Win32/Redline.GNQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.GNQ!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Redline.GNQ!MTB?


File Info:

name: A7368E6CE5673B471F52.mlw
path: /opt/CAPEv2/storage/binaries/68fb61943d60b561c175e64bc751ddea7bffe8fc051da76fc0a5cf8e46a14c38
crc32: 130FF27B
md5: a7368e6ce5673b471f52a910fd73efd5
sha1: 7a81f5df8bf932ea69a607e18a1361e04e40e829
sha256: 68fb61943d60b561c175e64bc751ddea7bffe8fc051da76fc0a5cf8e46a14c38
sha512: 0464cee42d119006a4ab49380208672fb18dfa1e8665c1b2ac5e19ee7a713b9ca298f9d726aba6bf3bf4f5d9332996d8c863582563fa52742f48ded8fc68709a
ssdeep: 12288:7q8mqYOR2nmfCMLug57SZbc2ElO+MZKqNMbczulyxySbDhlrEuoZ9s:LoDnmfCMLug52ZbVZKqN5bFuzZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B135AE2279C1D47AEEE710B682ECF675827DE0B4072915CB02D807EEDB536C16F32696
sha3_384: 8050f2b5d4c2237e8570c214a2927fd85006179a5cc449235ff33521bd9dc493d0b4d8c4c38f6b38dda93d8130a88cce
ep_bytes: e966e80300e9be2d0600e9f06e0400e9
timestamp: 2023-11-01 04:10:38

Version Info:

0: [No Data]

Trojan:Win32/Redline.GNQ!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.517442
FireEyeGen:Variant.Zusy.517442
SkyhighBehavesLike.Win32.Generic.th
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.517442
BitDefenderGen:Variant.Zusy.517442
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HUYH
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.gen
RisingBackdoor.Agent!8.C5D (TFE:5:fKpFrkIy1XD)
SophosTroj/Krypt-ABY
DrWebTrojan.Inject4.63603
EmsisoftGen:Variant.Zusy.517442 (B)
IkarusTrojan.Win32.Redline
GoogleDetected
VaristW32/Kryptik.KYF.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Redline.GNQ!MTB
ArcabitTrojan.Zusy.D7E542
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.gen
GDataGen:Variant.Zusy.517442
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLine.R619460
McAfeeArtemis!A7368E6CE567
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
PandaTrj/Genetic.gen
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HUYH!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/Redline.GNQ!MTB?

Trojan:Win32/Redline.GNQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment