Trojan

Trojan:Win32/RedlineStealer.CM!MTB removal tips

Malware Removal

The Trojan:Win32/RedlineStealer.CM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedlineStealer.CM!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/RedlineStealer.CM!MTB?


File Info:

name: 38A66C563D03AF797F97.mlw
path: /opt/CAPEv2/storage/binaries/1a13bea22835c2e8a879cb244365bdf1d13665a88e3db87c00f9ef62196a98ac
crc32: 16B6F6EC
md5: 38a66c563d03af797f972ccb8add8978
sha1: 25dfc16336b91ceddf6196adac09163379ae1515
sha256: 1a13bea22835c2e8a879cb244365bdf1d13665a88e3db87c00f9ef62196a98ac
sha512: 9606f119f36c16b53a5806793da686ca21a38fc9c05a7c5732955103326efaccaae3e9ae18b43e7f4863adb6565f0e02a85d5864059b0cb3171a5363c8a7cd48
ssdeep: 24576:X51CYLYb61XlNMHg1l3tEOP4eLKFpuJJd41TwboOM4Lp+0E1QUl3RuQ55313T:X55K+LiEJk1UboOM41+3l3N
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T130B50A036ACB0E75DDD23BB461CB533AA734FE30CA2A9B7FB608C53559532D4681A742
sha3_384: e08806a30a733ad0c86656144f9611ae8730955f366e32a5affb66cda597d3c7f1c80ae71d82e5fc535728be938f8a47
ep_bytes: 83ec0cc705b873500000000000e8aecc
timestamp: 2022-06-30 12:39:43

Version Info:

0: [No Data]

Trojan:Win32/RedlineStealer.CM!MTB also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanGen:Variant.Fragtor.109248
FireEyeGen:Variant.Fragtor.109248
CAT-QuickHealTrojan.ConvagenPMF.S28352518
ALYacGen:Variant.Fragtor.109248
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3812036
K7AntiVirusTrojan ( 0059501a1 )
AlibabaTrojan:Win32/RedlineStealer.e7b4fad7
K7GWTrojan ( 0059501a1 )
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPZW
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCGAZ
Paloaltogeneric.ml
ClamAVWin.Packed.Fragtor-9954665-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Fragtor.109248
NANO-AntivirusTrojan.Win32.Kryptik.jpstvi
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.zaa
Ad-AwareGen:Variant.Fragtor.109248
EmsisoftGen:Variant.Fragtor.109248 (B)
ComodoMalware@#3ur82khieofr
DrWebTrojan.Inject4.36802
VIPREGen:Variant.Fragtor.109248
TrendMicroTrojanSpy.Win32.REDLINE.YXCGAZ
McAfee-GW-EditionGenericRXTN-UO!38A66C563D03
SentinelOneStatic AI – Suspicious PE
SophosMal/Generic-S + Troj/Steal-CTS
WebrootW32.Trojan.Gen
AviraTR/Kryptik.uihvj
Antiy-AVLTrojan/Generic.ASMalwS.6C82
KingsoftWin32.Troj.Generic.jm.(kcloud)
MicrosoftTrojan:Win32/RedlineStealer.CM!MTB
GDataWin32.Trojan.PSE.17P1R11
GoogleDetected
AhnLab-V3Trojan/Win.RedlineStealer.R502307
McAfeeGenericRXTN-UO!38A66C563D03
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.RedLine
MalwarebytesTrojan.Crypt
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.Win32.RedlineStealer
MaxSecureTrojan.Malware.1728101.susgen
FortinetPossibleThreat.MU
AVGWin32:Evo-gen [Trj]
PandaTrj/Chgt.AA

How to remove Trojan:Win32/RedlineStealer.CM!MTB?

Trojan:Win32/RedlineStealer.CM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment