Trojan

Trojan:Win32/Redline!pz information

Malware Removal

The Trojan:Win32/Redline!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the MetaStealer malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Redline!pz?


File Info:

name: AA7DCE9AF2E2A4E853EF.mlw
path: /opt/CAPEv2/storage/binaries/d5448a46db863a1a80ca9e14d835daa8d25acf74ff27dfb940c415a41be52563
crc32: 6FA41D11
md5: aa7dce9af2e2a4e853ef433cafa00f20
sha1: 4fbd7b79900bf9c35bc27fb6a87f6bbe862e4518
sha256: d5448a46db863a1a80ca9e14d835daa8d25acf74ff27dfb940c415a41be52563
sha512: 876e6276ad693cb66835c200241bc2a44406a179dc9ee1daf8a305332791cd4bb3bd949ebbbaf05320527a2d244e3f9c7050ab09aff8abc21a3575637dd8a136
ssdeep: 6144:HZ8oJE7XiIwsyvBImtq26FrR0Jnep4HzTVN:58EiXiBumg26FrR0Jnep4XV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T156B68E1575098F7FE3D3097CDACA92B98B28B2653F5364CB2BD00B964F697C1A93050E
sha3_384: 9cfa24599eef8b79bbaa741c5783b3e71bbb3d2214506203b762c9c0181c2216ab65495ae220c48742743d2c8ca6a9aa
ep_bytes: e802750000e9a4feffff3b0d907a4400
timestamp: 2023-10-22 12:02:22

Version Info:

0: [No Data]

Trojan:Win32/Redline!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Redline.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103700
FireEyeGeneric.mg.aa7dce9af2e2a4e8
SkyhighBehavesLike.Win32.Trojan.vz
McAfeeArtemis!AA7DCE9AF2E2
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4556808
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ace5d1 )
AlibabaTrojanSpy:Win32/Redline.ccb36bd0
K7GWTrojan ( 005ace5d1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Genus.TSS
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVCX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKDZ.103700
NANO-AntivirusTrojan.Win32.Stealer.kctyjw
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.11b9d01f
EmsisoftTrojan.GenericKDZ.103700 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.PWS.RedLineNET.6
VIPRETrojan.GenericKDZ.103700
TrendMicroTROJ_GEN.R002C0DBF24
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ACN
IkarusTrojan.Win32.Redline
GDataWin32.Trojan.PSE.11AU12L
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.GenKryptik.gphv
KingsoftWin32.Hack.Convagent.gen
XcitiumMalware@#2cc080sdcchrg
ArcabitTrojan.Generic.D19514
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Redline!pz
VaristW32/Stealer.GB.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R616884
VBA32BScope.Backdoor.Agent
ALYacTrojan.GenericKDZ.103700
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DBF24
RisingTrojan.Kryptik!1.F127 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/GenKryptik.GPHV!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.af2e2a
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Stealer.gen

How to remove Trojan:Win32/Redline!pz?

Trojan:Win32/Redline!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment