Trojan

What is “Trojan:Win32/RedLine.MBCQ!MTB”?

Malware Removal

The Trojan:Win32/RedLine.MBCQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.MBCQ!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.MBCQ!MTB?


File Info:

name: 6DADE374F6ADF45383D8.mlw
path: /opt/CAPEv2/storage/binaries/9c8a7f8664913927e276132a6a602ff4d452cf322f2d4f4032a61a5be9cda339
crc32: 4A8665AC
md5: 6dade374f6adf45383d88138325a6ba2
sha1: 9436b44b1ebd30fa9721e84a9e0201a46f519a9a
sha256: 9c8a7f8664913927e276132a6a602ff4d452cf322f2d4f4032a61a5be9cda339
sha512: 6403251de5a8e5f67289e4674746048c5f7580a638aa79784b7dad3d7c5a6e2322cf933a929d3cc749b595b3c45ac378cce8660841246a256eb108417757d8c3
ssdeep: 6144:qJieERFHqXwvTygXUNVS4MGh1aBFrvz1xcxcVtiP:qJYR7yR1aBFrvz1xcxyiP
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17A64590372C68C7DF8AA073E61D48F2DD877ED60064458FB37A49A654FE021394AB5BE
sha3_384: 1ab4b0daa20817e89bb81ff5deaa79929f4beb2c9389fde251a34bdc477bff3170590fb6977149b854cdeb02e9b21625
ep_bytes: e8f5020000e974feffff836104008bc1
timestamp: 2023-06-08 15:05:43

Version Info:

0: [No Data]

Trojan:Win32/RedLine.MBCQ!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tedy.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.6dade374f6adf453
McAfeeArtemis!6DADE374F6AD
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a6c241 )
K7GWTrojan ( 005a6c241 )
BitDefenderThetaGen:NN.ZexaF.36250.tuY@a4@K6li
VirITTrojan.Win32.GenusT.DMQK
CyrenW32/Agent.GJN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTTW
APEXMalicious
ClamAVWin.Malware.Tedy-10003982-0
KasperskyUDS:Trojan-Spy.Win32.Stealer
BitDefenderGen:Variant.Lazy.350509
MicroWorld-eScanGen:Variant.Lazy.350509
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Backdoor.Agent.Rnkl
SophosMal/Generic-S
F-SecureTrojan.TR/AD.RedLineSteal.kuqzd
DrWebTrojan.Inject4.58183
VIPREGen:Variant.Lazy.350509
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Lazy.350509 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.350509
AviraTR/AD.RedLineSteal.kuqzd
Antiy-AVLTrojan[Backdoor]/Win32.Convagent
ArcabitTrojan.Lazy.D5592D
ZoneAlarmUDS:Trojan-Spy.Win32.Stealer
MicrosoftTrojan:Win32/RedLine.MBCQ!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R585702
ALYacGen:Variant.Tedy.379608
MAXmalware (ai score=87)
MalwarebytesTrojan.Crypt.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CF823
RisingTrojan.Kryptik!8.8 (TFE:1:cMcbqn3OwsH)
IkarusTrojan-Spy.Agent
FortinetW32/GenKryptik.GKNM!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLine.MBCQ!MTB?

Trojan:Win32/RedLine.MBCQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment