Trojan

Trojan:Win32/Redline!pz malicious file

Malware Removal

The Trojan:Win32/Redline!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline!pz virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Redline!pz?


File Info:

name: 6F17D270BBE9FA219444.mlw
path: /opt/CAPEv2/storage/binaries/d55baae6e7fc365863c5c03c98fc65407eb562b57619c18ccee310b518e4e5e1
crc32: 55915746
md5: 6f17d270bbe9fa219444d39f1ca69e01
sha1: c116ebe277a4b92223f350f4c140dd01eb3c0107
sha256: d55baae6e7fc365863c5c03c98fc65407eb562b57619c18ccee310b518e4e5e1
sha512: 0dff72f6a5f64c95362b73ff9b2885e64d0422665a6aa065061e31ed76230dfb8f3b0b95f6617bc051e4e3aefc659b37c35bee68a1e3fb36da09639cfe3e8eb1
ssdeep: 12288:L7EW34JVXdcfoDm4gVidIoE2U+W9ZXU24:L7EeaWh+W9Z4
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FC94E12B77D84057F793E57012F62D22067D303A2ECF88CAD379F80605979E59ABD60A
sha3_384: c10a47f6c823ad07d5f798dd4b8b3788db9b15da7ee58f683d6a4a94fc4d59b6d53003684e8923cf751dcf3cb3b4c5a6
ep_bytes: e8a6210000e9a4feffff8bff558bec8b
timestamp: 2023-02-18 14:57:51

Version Info:

Comments: Scrupulous unvalued attractions modernise skylines
CompanyName: Mantids remove
FileDescription: Sportsmen quasi kinetics potsherds
FileVersion: 7.224.8.0
InternalName: Including pricier
LegalCopyright: Copyright © Inauspicious scroll melodiously supplicating
LegalTrademarks: Planners deviated influenced
OriginalFilename: Simpleton rustics
ProductName: Angels cranks
ProductVersion: 7.224.8.0
Translation: 0x081a 0x081a

Trojan:Win32/Redline!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.450845
FireEyeGeneric.mg.6f17d270bbe9fa21
CAT-QuickHealTrojan.GenericRI.S30089819
SkyhighGenericRXVN-FO!6F17D270BBE9
McAfeeGenericRXVN-FO!6F17D270BBE9
Cylanceunsafe
ZillyaTrojan.Stealer.Win32.47685
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Redline.a4d7e810
K7GWTrojan ( 0059ef771 )
K7AntiVirusTrojan ( 0059ef771 )
BitDefenderThetaGen:NN.ZexaE.36744.zq2@aeXEI0pi
VirITTrojan.Win32.GenusT.EFPU
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HSDM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.450845
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.13bb5d41
EmsisoftGen:Variant.Zusy.450845 (B)
F-SecureHeuristic.HEUR/AGEN.1364952
DrWebTrojan.PWS.Siggen3.26446
VIPREGen:Variant.Zusy.450845
Trapminemalicious.high.ml.score
SophosTroj/Steal-DID
IkarusTrojan.Win32.Redline
GDataGen:Variant.Zusy.450845
JiangminTrojanSpy.Stealer.agip
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1364952
Antiy-AVLTrojan/Win32.Kryptik
XcitiumMalware@#3bzruij48hrpf
ArcabitTrojan.Zusy.D6E11D
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Redline!pz
VaristW32/Kryptik.JCA.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R559323
Acronissuspicious
VBA32BScope.Trojan.Khalesi
ALYacGen:Variant.Zusy.450845
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Agent!8.C5D (TFE:5:UAVXpJIkJgH)
YandexTrojan.Kryptik!NIuJEBZD5+4
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HSEV!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Redline!pz?

Trojan:Win32/Redline!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment