Trojan

Trojan:Win32/Redline.MYV!MTB malicious file

Malware Removal

The Trojan:Win32/Redline.MYV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.MYV!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.MYV!MTB?


File Info:

name: D34FCB73718373F843D2.mlw
path: /opt/CAPEv2/storage/binaries/7e0645b4a775ba4aec2ac02c9e7f6e5d809dd41a4248c447e0a7250dfdb9a091
crc32: 2B689475
md5: d34fcb73718373f843d285c8296e2315
sha1: 5c08e0863b3ca9a2d1c1e0fb6be1374d7f6ff965
sha256: 7e0645b4a775ba4aec2ac02c9e7f6e5d809dd41a4248c447e0a7250dfdb9a091
sha512: 38235c52fb8cccb2496299078d17c987b92a51be614d9e000fb9f1bd24481e0f2f0abd1fe73fccce36ddddb306a582ed6e370fcc419f607c494675416658ce8d
ssdeep: 6144:K9y+bnr+wp0yN90QEO2WmriIgatfvhnWqbUR2dE3PIECsvzMqAd+poEzU:/Mrgy90ng6fvhnWqY4E3GGM5+poEg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5940107A7E98032F5B5577018FB02C30A36BD605B78435B678EAE5918B26B4F27077B
sha3_384: e0f118e7a38e5e9e7f62dc40dfa3d3d88c6248b9eb089a1ddd9317ad5d6ad844f59e2a772101f2630e5ec3c753b4b776
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Самоизвлечение CAB-файлов Win32
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0419 0x04b0

Trojan:Win32/Redline.MYV!MTB also known as:

LionicTrojan.Win32.Stealer.12!c
FireEyeGeneric.mg.d34fcb73718373f8
McAfeeArtemis!D34FCB737183
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3259154
SangforTrojan.Win32.Agent.Vutr
K7AntiVirusTrojan ( 0059e3df1 )
AlibabaTrojanSpy:Win32/Stealer.65d2a72a
K7GWTrojan ( 0059e3df1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/KillAV.KMEF-6536
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Disabler-9987080-0
KasperskyUDS:Trojan.MSIL.Agent.gen
NANO-AntivirusTrojan.Win32.Stealer.juyrng
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.MSIL.Agent.hg
DrWebTrojan.Siggen19.32857
VIPRETrojan.GenericKD.65331035
TrendMicroTROJ_GEN.R002C0PBS23
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
IkarusTrojan.MSIL.Disabler
GDataWin32.Trojan-Stealer.Cordimik.A4MD3R
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Sabsik
MicrosoftTrojan:Win32/Redline.MYV!MTB
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.65716475
MalwarebytesGeneric.Trojan.Injector.DDS
RisingTrojan.Kryptik!1.E2E3 (CLASSIC:bWQ1Og1hFSx6Nlh97w)
YandexTrojan.Disabler!G6z7qDxyklM
SentinelOneStatic AI – Suspicious SFX
FortinetMSIL/Disabler.DR!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.371837
PandaTrj/Chgt.AD

How to remove Trojan:Win32/Redline.MYV!MTB?

Trojan:Win32/Redline.MYV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment