Trojan

Trojan:Win32/Redline!pz information

Malware Removal

The Trojan:Win32/Redline!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline!pz virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the MetaStealer malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline!pz?


File Info:

name: 9B1949E5B189D1BFD92F.mlw
path: /opt/CAPEv2/storage/binaries/3673290d4843b51c1ee7a618792924de6a1bcebfe402d2bbcde5f8746028797d
crc32: 67E61B8A
md5: 9b1949e5b189d1bfd92f966f70f9754d
sha1: e1c0178966e7c00fb423f0384d65afb3445cb5c5
sha256: 3673290d4843b51c1ee7a618792924de6a1bcebfe402d2bbcde5f8746028797d
sha512: c954685db3ab965379615fde3251033e9041139aeb4fd81aae7d2d3c8bb3ea405363fa5241159ae1b292614b2a8c2a0b682d2339a9c895fef928d04888960ecc
ssdeep: 24576:znC0rGWoHIsS8PjwxC+p6B6a9Dhvh6AbyCWQsP2SzY:z5oHIsS8b+sB6a3vDKP2B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD953C1176F94B59F6F30EB86ABAA612087ABC69DF11C6DF1250904E0831BD48970F7B
sha3_384: 75ae47db75338a5fd2be16a47d3273bc842484bcb103c65987ac1e13669c1e5c0cb642a6ea30e0d2f101ccb3307fcaea
ep_bytes: e908f20400e9036c0600e9be680100e9
timestamp: 2023-11-03 16:24:34

Version Info:

0: [No Data]

Trojan:Win32/Redline!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mokes.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Dropper.ZXC
SkyhighBehavesLike.Win32.Obfuscated.tm
McAfeeGenericRXWM-NP!9B1949E5B189
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Dropper.ZXC
K7AntiVirusTrojan ( 005add031 )
BitDefenderTrojan.Dropper.ZXC
K7GWTrojan ( 005add031 )
ArcabitTrojan.Dropper.ZXC
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVLV
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
AlibabaTrojanPSW:Win32/RedLine.db9ded6a
NANO-AntivirusTrojan.Win32.Mokes.kdevzn
AvastWin32:TrojanX-gen [Trj]
RisingBackdoor.Mokes!8.619 (TFE:1:7KD0hlTOYCM)
EmsisoftTrojan.Dropper.ZXC (B)
F-SecureTrojan.TR/AD.RedLineSteal.cyvip
DrWebTrojan.SmokeLoader.41
ZillyaTrojan.GenKryptik.Win32.278541
TrendMicroTROJ_GEN.R002C0DKA23
FireEyeTrojan.Dropper.ZXC
SophosTroj/Krypt-ABY
IkarusTrojan.Win32.Crypt
MAXmalware (ai score=84)
JiangminBackdoor.Mokes.hsr
GoogleDetected
AviraTR/AD.RedLineSteal.cyvip
VaristW32/Kryptik.KZZ.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik.gptp
KingsoftWin32.Hack.Mokes.gen
MicrosoftTrojan:Win32/Redline!pz
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.1XSTV4D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.R620583
VBA32Backdoor.Mokes
ALYacTrojan.Dropper.ZXC
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKA23
TencentTrojan-PSW.Win32.Stealerc.hat
YandexTrojan.GenKryptik!1ETBBomOtxI
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.GPTP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redline!pz?

Trojan:Win32/Redline!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment