Trojan

Trojan:Win32/Redline.YY!MTB removal guide

Malware Removal

The Trojan:Win32/Redline.YY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.YY!MTB virus can do?

  • Authenticode signature is invalid

How to determine Trojan:Win32/Redline.YY!MTB?


File Info:

name: 4938386CBB40C65ED8A8.mlw
path: /opt/CAPEv2/storage/binaries/512d9068db6324b8ba1ec64805451932a942eecfd6c35f3bd6ab1c7e22cca5b3
crc32: 350A7955
md5: 4938386cbb40c65ed8a8d0ff64db7650
sha1: d4db2c83af4ec660ac736b1fcd05f1f17696326c
sha256: 512d9068db6324b8ba1ec64805451932a942eecfd6c35f3bd6ab1c7e22cca5b3
sha512: f6ddb62682cc25f61543a6cd34625ecd2f396a83f11ab60c08f21c5713d90f3dc0a0dc12e716a31a4937575478ecbb3b14a39ba6fef4805199895398b345ab53
ssdeep: 6144:1E+YIrl/qvnb8w8wLPcYnOf121MQI/s5MoyAO/6VKnGR:BZlivnb8wtT35qoVEGR
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AF946B073567C0F7D566C2B01D2ECBBD493989249D220DAF63C42EBE99F5A413E27839
sha3_384: 9d32e00f274166d5af5381e46b331cd76e9d7ef8c219c0dc5484ab42f85d55527c14d14a1bbc6cbda03ec1f6a25ea05a
ep_bytes: e8c8040000e974feffff836104008bc1
timestamp: 2022-09-07 13:07:40

Version Info:

0: [No Data]

Trojan:Win32/Redline.YY!MTB also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Lazy.241246
ClamAVWin.Malware.Exploitx-9967939-0
FireEyeGen:Variant.Lazy.241246
McAfeeGenericRXUC-YG!4938386CBB40
CyrenW32/Kryptik.HLV.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HQRH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Exploit.Win32.Agent.gen
BitDefenderGen:Variant.Lazy.241246
AvastWin32:ExploitX-gen [Expl]
Ad-AwareGen:Variant.Lazy.241246
EmsisoftGen:Variant.Lazy.241246 (B)
VIPREGen:Variant.Lazy.241246
McAfee-GW-EditionGenericRXUC-YG!4938386CBB40
SophosMal/EncPk-ZC
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.241246
JiangminExploit.Agent.zt
Antiy-AVLTrojan/Generic.ASMalwS.50E8
MicrosoftTrojan:Win32/Redline.YY!MTB
GoogleDetected
AhnLab-V3Malware/Win.ExploitX-gen.R514207
MAXmalware (ai score=88)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesTrojan.Crypt
RisingExploit.Agent!8.1B (TFE:5:knwmf844xYF)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/DotNetPacker.B!tr
AVGWin32:ExploitX-gen [Expl]

How to remove Trojan:Win32/Redline.YY!MTB?

Trojan:Win32/Redline.YY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment