Trojan

Should I remove “Trojan:Win32/Redline.MYV!MTB”?

Malware Removal

The Trojan:Win32/Redline.MYV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.MYV!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.MYV!MTB?


File Info:

name: 1FE42EB1A3B8E83776B3.mlw
path: /opt/CAPEv2/storage/binaries/c5a6c1ca96ab656e39bc4d1ca30657f76369796e703defbc410b95a40ceecd8a
crc32: 061B8019
md5: 1fe42eb1a3b8e83776b32e5144c9004f
sha1: 74dd55b0f51bff999b6ef956baa4a9d85ae96e16
sha256: c5a6c1ca96ab656e39bc4d1ca30657f76369796e703defbc410b95a40ceecd8a
sha512: 0a1f20b61e2dccf46a0b1289dbd4772437d95d896de58d0d285c5598a064d8b11454ea3be5a8401bcb9f04f8cbd2925ed577700e653ccfdeb3badf7b23cc11c7
ssdeep: 12288:SMrwy90IDo0HZ8uB5ndEYdE3QQo305dB:OyVT8YGQLuz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F94010BABE88572E4B4577018F602C31B32BD515B38879B678FAE591873670F67132B
sha3_384: d578800cef6e86905696b28667a32be1eb03413d477517776293cd89efb72b36e7cd0d11d11a2a7c6a8b8a607ffe0177
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

Trojan:Win32/Redline.MYV!MTB also known as:

LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen19.32857
FireEyeGeneric.mg.1fe42eb1a3b8e837
CAT-QuickHealTrojan.MSIL
McAfeeArtemis!1FE42EB1A3B8
MalwarebytesGeneric.Trojan.Injector.DDS
ZillyaTrojan.Agent.Win32.3257025
SangforTrojan.Win32.Agent.Vq3j
K7AntiVirusTrojan ( 0059e3df1 )
AlibabaTrojanSpy:Win32/Stealer.38d9f39a
K7GWTrojan ( 0059e3df1 )
Cybereasonmalicious.1a3b8e
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Disabler-9987080-0
KasperskyUDS:Trojan.MSIL.Agent.gen
NANO-AntivirusTrojan.Win32.Disabler.juzaun
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.hg
VIPRETrojan.GenericKD.65331035
TrendMicroTROJ_GEN.R002C0PBS23
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Suspicious SFX
GDataWin32.Trojan-Stealer.Cordimik.BKQW13
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Sabsik
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:Win32/Redline.MYV!MTB
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.65716475
Cylanceunsafe
RisingTrojan.Kryptik!1.E2E3 (CLASSIC:bWQ1Og1hFSx6Nlh97w)
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan.MSIL.Disabler
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Trojan:Win32/Redline.MYV!MTB?

Trojan:Win32/Redline.MYV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment