Trojan

What is “Trojan:Win32/RedLine.RPX!MTB”?

Malware Removal

The Trojan:Win32/RedLine.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.RPX!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.RPX!MTB?


File Info:

name: E86D9D80956CBA628FC8.mlw
path: /opt/CAPEv2/storage/binaries/9cc9623cd4f59c2f240a69c68080e09c2ca845bd9dc5f6a775d5d7726dda3b26
crc32: B623F7D3
md5: e86d9d80956cba628fc8ac4f988a1c36
sha1: 6eb566a12e8c7ddce899d8b45d44625ad563f46f
sha256: 9cc9623cd4f59c2f240a69c68080e09c2ca845bd9dc5f6a775d5d7726dda3b26
sha512: d40b973eaeb1f9690c9ad0c1a666c8209b1ccefb3e07b84d966b711314641e45be9bd88bf2f2d46ae6938a7510f26d66639828bbcad58b85f3c712f79cfbf4df
ssdeep: 6144:Yp5w3TtBWzookICyTDlXFOvK7QAOe6+bRa9ss:YpCBWzookIw7+49ss
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T160258F11B5D1C072D873253209E4DBBA5A3DB9300B6199EF67E40F7E8F306C19672AA7
sha3_384: 1461eaf2f734ca47f9e398c886dc8f8b592ccb10d8e484704e7f4f8e44dc2358df89e9461b4f8878e92548c21ba8a0c1
ep_bytes: e8ca070000e974feffff558bec8b4508
timestamp: 2023-05-24 08:58:29

Version Info:

0: [No Data]

Trojan:Win32/RedLine.RPX!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.469415
ClamAVWin.Trojan.Pwsx-10002387-0
FireEyeGeneric.mg.e86d9d80956cba62
ALYacGen:Variant.Zusy.469415
MalwarebytesTrojan.Injector
VIPREGen:Variant.Zusy.469415
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a5b311 )
AlibabaTrojan:Win32/Injector.933d0ef5
K7GWTrojan ( 005a5b311 )
Cybereasonmalicious.12e8c7
CyrenW32/Kryptik.IXI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ESYR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.469415
AvastWin32:PWSX-gen [Trj]
EmsisoftGen:Variant.Zusy.469415 (B)
F-SecureTrojan.TR/AD.Nekark.kquvb
McAfee-GW-EditionBehavesLike.Win32.Generic.fz
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataGen:Variant.Zusy.469415
JiangminTrojanSpy.Stealer.agrz
AviraTR/AD.Nekark.kquvb
ArcabitTrojan.Zusy.D729A7
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/RedLine.RPX!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5369784
Acronissuspicious
McAfeeArtemis!E86D9D80956C
MAXmalware (ai score=89)
VBA32Malware-Cryptor.Inject.gen
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CEO23
RisingBackdoor.Agent!8.C5D (TFE:5:kXxJGmNMLUE)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HSKS!tr
BitDefenderThetaGen:NN.ZexaF.36196.@uX@aC1F6Qe
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLine.RPX!MTB?

Trojan:Win32/RedLine.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment