Trojan

Should I remove “Trojan:Win32/RedLine.MT!MTB”?

Malware Removal

The Trojan:Win32/RedLine.MT!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.MT!MTB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan:Win32/RedLine.MT!MTB?


File Info:

name: 01156A12CABE39E63CF9.mlw
path: /opt/CAPEv2/storage/binaries/e3f7e1e012cea9fb6483924e7625c577e4d185686b8cf05a725415b87697ffbe
crc32: 61537215
md5: 01156a12cabe39e63cf988453ce75726
sha1: 0e37ad046263223d7f50d3ec253ed38f039490d1
sha256: e3f7e1e012cea9fb6483924e7625c577e4d185686b8cf05a725415b87697ffbe
sha512: c8bdf5ec809611581aac2fad51335e6a649f120d856e8c020df9ad3adb0b5ab3ee4da745e6ad4a0d23690c8ef4f31f5c6a93ae4f96db6c6937cbc0cbca00576d
ssdeep: 3072:Ygdgqv8IvN4rday74dcRUtI0bdk2w2UpKckQmG8XM4i9UcQriQf5n6x2ZgSjyIdi:YgvNQHR/0kkXhi9UcQr9tZgSjyIdDRB6
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C34AE13BF60D120C679E1B374A10A94B12D4A21EBDC6D47672C8ABA1FF37D1723A45E
sha3_384: a946c3778db78b7f72084a54b1eb2b9d61e7e19e75024f0e04ced14a16e4d48f0684c575671e8610ca50785135849cc3
ep_bytes: e8f13d0000e9a4feffff8b4c2404f7c1
timestamp: 2022-11-15 15:33:41

Version Info:

0: [No Data]

Trojan:Win32/RedLine.MT!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.12!c
DrWebTrojan.Inject4.47114
MicroWorld-eScanTrojan.GenericKD.63673349
FireEyeTrojan.GenericKD.63673349
ALYacTrojan.GenericKD.63673349
MalwarebytesSpyware.PasswordStealer
VIPRETrojan.GenericKD.63673349
SangforInfostealer.Win32.Agent.V89k
K7AntiVirusTrojan ( 0059b25b1 )
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 0059b25b1 )
BitDefenderThetaGen:NN.ZexaF.34796.omW@aerM2W
CyrenW32/Stealer.CC.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HRPK
APEXMalicious
ClamAVWin.Ransomware.Redline-9978672-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderTrojan.GenericKD.63673349
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan-Spy.Stealer.Psmw
Ad-AwareTrojan.GenericKD.63673349
SophosMal/Generic-S
TrendMicroTrojanSpy.Win32.REDLINE.YXCKPZ
McAfee-GW-EditionRDN/Generic PWS.y
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.63673349 (B)
GDataWin32.Trojan.PSE.1U5K1HQ
GoogleDetected
AviraTR/AD.RedLineSteal.gtssx
Antiy-AVLTrojan/Win32.Sabsik
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D3CB9405
ViRobotTrojan.Win32.Z.Stealer.237056
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.pef
MicrosoftTrojan:Win32/RedLine.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLine.R534925
McAfeeArtemis!01156A12CABE
MAXmalware (ai score=84)
VBA32BScope.TrojanPSW.RedLine
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCKPZ
RisingTrojan.Generic@AI.100 (RDML:w+D7K9nLzdzde6Fu+7lj8w)
FortinetW32/GenKryptik.GCKR!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Trojan:Win32/RedLine.MT!MTB?

Trojan:Win32/RedLine.MT!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment