Trojan

Trojan:Win32/RedLine.SPDX!MTB removal

Malware Removal

The Trojan:Win32/RedLine.SPDX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.SPDX!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.SPDX!MTB?


File Info:

name: CBD57FDD6D2FE86ED8E4.mlw
path: /opt/CAPEv2/storage/binaries/afb863861712dd517cbb119b78f4ed35ae1724890402fea3076f51fcbbcfc835
crc32: 35499A4B
md5: cbd57fdd6d2fe86ed8e410955be7efcb
sha1: 72afed4b0eef5dd5a753720d507c2a7fd12e3a99
sha256: afb863861712dd517cbb119b78f4ed35ae1724890402fea3076f51fcbbcfc835
sha512: d0242c068049dd3bb6fcf04aae002b093906bd11ed9bd6cc735388eb249f742ffa71466af6ee3f575fa4f280fb77220f51d7e3b5212dc78d107b687a67eaac36
ssdeep: 24576:U+t/MpDDk1mPxLfPwVO8cclC+YEzn6RzrpcHXf:f/z1mPxL9zQoESzrpc3f
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T168266B213EA28231DFA223750DAC7422B15DB4A7072D70FF759A2BFD9B12DF12A76051
sha3_384: a81877c843084c73db449bb62d42a3d1bd6c902e491dbb92387fab3a7911a79c68f6a77e2719a84de9f0937a6a405db8
ep_bytes: e943430400e908a60500e9cd570100e9
timestamp: 2023-09-23 10:35:30

Version Info:

0: [No Data]

Trojan:Win32/RedLine.SPDX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.RedLine.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Babar.66758
SkyhighGenericRXWK-GL!CBD57FDD6D2F
McAfeeGenericRXWK-GL!CBD57FDD6D2F
MalwarebytesTrojan.Crypt
VIPREGen:Variant.Babar.66758
SangforInfostealer.Win32.Kryptik.Vi13
K7AntiVirusTrojan ( 005aaa221 )
BitDefenderGen:Variant.Babar.66758
K7GWTrojan ( 005aaa221 )
BitDefenderThetaGen:NN.ZexaE.36792.@RZ@aCnIzpoi
VirITTrojan.Win32.Genus.TGU
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVAC
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-10008461-0
KasperskyTrojan.Win32.Injuke.iuer
AlibabaTrojan:Win32/Injuke.153a64e3
NANO-AntivirusTrojan.Win32.Stealer.kbcpwj
ViRobotTrojan.Win.Z.Redline.4439552
RisingBackdoor.Agent!8.C5D (TFE:1:GRn6PQFyOMS)
SophosMal/Generic-S
DrWebTrojan.PWS.RedLineNET.6
ZillyaBackdoor.Pandora.Win32.186
TrendMicroTrojanSpy.Win32.REDLINE.YXDKJZ
FireEyeGeneric.mg.cbd57fdd6d2fe86e
EmsisoftGen:Variant.Babar.66758 (B)
IkarusTrojan.Win32.Redline
JiangminTrojan.Extgen.p
VaristW32/Agent.GTL.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/RedLine.SPDX!MTB
ArcabitTrojan.Babar.D104C6
ZoneAlarmTrojan.Win32.Injuke.iuer
GDataGen:Variant.Babar.66758
GoogleDetected
AhnLab-V3Infostealer/Win.Injection.C5479143
VBA32BScope.TrojanPSW.RedLine
ALYacGen:Variant.Babar.66758
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDKJZ
TencentMalware.Win32.Gencirc.10bf2c11
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.218956198.susgen
FortinetW32/Kryptik.HUBU!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLine.SPDX!MTB?

Trojan:Win32/RedLine.SPDX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment