Trojan

How to remove “Trojan:Win32/Redline.GNR!MTB”?

Malware Removal

The Trojan:Win32/Redline.GNR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.GNR!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.GNR!MTB?


File Info:

name: 7F71554759F26C929118.mlw
path: /opt/CAPEv2/storage/binaries/6afa6a2fa247b5687f5d1f73147e27f804cc5ede8b80cd84a73d299d4f47fc53
crc32: 504F6325
md5: 7f71554759f26c92911833d6475ee79b
sha1: 13ea59a4735b00274a6bd96543877153dd8e3e79
sha256: 6afa6a2fa247b5687f5d1f73147e27f804cc5ede8b80cd84a73d299d4f47fc53
sha512: ca79923fa197db8ab9846e4cb10ce793c58d1bbc6600a3a70ae3c102b0e4f57b63f022759148fa49fcf82aa11ffb757c70b2a808c0c36b22a1d30f2344ea0f0c
ssdeep: 12288:hbcqJI2dAClBItf+BVPf7qlHYBP3lq7bmxoRj3ccZRrpu9cdTxtH1/3EtlZ:6qe2dACotf+BVnT8IoRj3ccfT53I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189459D1079D24022DFFA2571B7ACB979269FD07037181ACB15D897FEE7A69C06F32482
sha3_384: 4bc9e3fdc94f595a40203fc48ed55edd4616dbde1721c7c931b02bd83a7bced88c86a84921b65cc733b954844682658c
ep_bytes: e9ea280400e97b270700e95daf0400e9
timestamp: 2023-11-02 02:41:45

Version Info:

0: [No Data]

Trojan:Win32/Redline.GNR!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.RedLine.l!c
DrWebTrojan.PWS.Stealer.38044
MicroWorld-eScanGen:Variant.Ser.Zusy.4711
FireEyeGen:Variant.Ser.Zusy.4711
SkyhighBehavesLike.Win32.Sabsik.th
ALYacGen:Variant.Ser.Zusy.4711
MalwarebytesTrojan.MalPack.RND.Generic
VIPREGen:Variant.Ser.Zusy.4711
SangforTrojan.Win32.Agent.Vhxm
K7AntiVirusTrojan ( 005ac80f1 )
BitDefenderGen:Variant.Ser.Zusy.4711
K7GWTrojan ( 005ac80f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.kDW@aC6ontd
VirITTrojan.Win32.GenusT.DTKV
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUYH
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
AlibabaTrojanSpy:Win32/Stealer.15fc0ed2
NANO-AntivirusTrojan.Win32.Inject4.kczvob
RisingBackdoor.Agent!8.C5D (TFE:1:6GqAaQTPo2I)
EmsisoftGen:Variant.Ser.Zusy.4711 (B)
F-SecureTrojan.TR/AD.RedLineSteal.fhcjn
TrendMicroTrojanSpy.Win32.REDLINE.YXDKBZ
SophosTroj/Krypt-ABY
MAXmalware (ai score=85)
GoogleDetected
AviraTR/AD.RedLineSteal.fhcjn
VaristW32/Kryptik.KNN.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Redline.GNR!MTB
ArcabitTrojan.Ser.Zusy.D1267
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.PSE.12W6N6R
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLine.C5535794
McAfeeArtemis!7F71554759F2
TACHYONTrojan-Spy/W32.InfoStealer.1213440
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDKBZ
IkarusTrojan.Win32.Redline
FortinetW32/Injector.ETFD!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Trojan:Win32/Redline.GNR!MTB?

Trojan:Win32/Redline.GNR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment