Trojan

Trojan:Win32/Redline.MKLK!MTB removal guide

Malware Removal

The Trojan:Win32/Redline.MKLK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.MKLK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan:Win32/Redline.MKLK!MTB?


File Info:

name: 70380EB7D994BBD7C52E.mlw
path: /opt/CAPEv2/storage/binaries/f16d88efa0664a9949495473cd62e51b5b2031492c916ce3b4c0133b56874df2
crc32: E472294E
md5: 70380eb7d994bbd7c52e37ea776e6f24
sha1: 7579d6b56d9dcf3777263df0ab8120834c92a456
sha256: f16d88efa0664a9949495473cd62e51b5b2031492c916ce3b4c0133b56874df2
sha512: 64bb949541861a9f71f5dcdacb7643fb4d72f3e14dd619b7009ff37c5c52ab00e265b420e3f170645c1064717131b3ccec9c3e2f4c03e1a812d32d8a2a0730bb
ssdeep: 6144:4+Z2NHewQvD9Jm8+sjQVyiwNZh3LB/PWpsRv3JyVWzXc:12EwQvZkfsjQVyiwNZb/PWux34N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196548E00BB90D039F5BB52F44979837CB93A7EB14B2554CB62D41AEE5A396E0EC7034B
sha3_384: 34f680590b8c691468301a9abcaddcba78c003e21028431626d8bfae7bc02120f617046eb429006e306e92c2dd064c47
ep_bytes: 8bff558bece836760000e8110000005d
timestamp: 2022-01-09 02:13:25

Version Info:

Translations: 0x0136 0x00aa

Trojan:Win32/Redline.MKLK!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.Y!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.61805902
FireEyeGeneric.mg.70380eb7d994bbd7
McAfeeRDN/Smoke Loader
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Redline.1b1bfd71
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.HLA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQRG
Paloaltogeneric.ml
ClamAVWin.Packed.Pwsx-9965190-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.61805902
CynetMalicious (score: 100)
APEXMalicious
Ad-AwareTrojan.GenericKD.61805902
EmsisoftTrojan.GenericKD.61805902 (B)
DrWebTrojan.PWS.Stealer.33898
TrendMicroRansom.Win32.STOP.SMYXBFX.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Raccrypt
AviraTR/AD.MalwareCrypter.ssbao
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASCommon.2BA
MicrosoftTrojan:Win32/Redline.MKLK!MTB
GDataTrojan.GenericKD.61805902
GoogleDetected
AhnLab-V3Malware/Win.Generic.R514003
VBA32TrojanPSW.RedLine
MalwarebytesTrojan.MalPack.GS
AvastWin32:DropperX-gen [Drp]
RisingTrojan.Generic@AI.100 (RDML:+8vHYqN6RmBhFI+Lbg1xMQ)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.56d9dc
PandaTrj/GdSda.A

How to remove Trojan:Win32/Redline.MKLK!MTB?

Trojan:Win32/Redline.MKLK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment