Trojan

Should I remove “Trojan:Win32/RedlineStealer.XS!MTB”?

Malware Removal

The Trojan:Win32/RedlineStealer.XS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedlineStealer.XS!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedlineStealer.XS!MTB?


File Info:

name: 2777A7F891C8E9DA3F58.mlw
path: /opt/CAPEv2/storage/binaries/23f39d677902923a0cd7edf3b444e8e770106cabc7f7842f59dc35e6ebf113f4
crc32: B1C30D40
md5: 2777a7f891c8e9da3f588b7660a1bcbc
sha1: a9f80412d1bdbcc6a25dab059c26a2de0d723078
sha256: 23f39d677902923a0cd7edf3b444e8e770106cabc7f7842f59dc35e6ebf113f4
sha512: 54ac4e45515475185438154e6751d82176472a38a02b14beb9dd4cd6a6c6cb73d8dab6fcc4d4fe35b227aeaa95737322a4ebc4b843940776b68b1be64c60e9a5
ssdeep: 12288:VS7+D/uaVaKNB5b8NFhAE6eqa4Q4PwgOC0yxJuPYH5SECku+nNTO2qiwDB5XHqQ:VS7U/unKNB5b8NTyxJuPSSECOObpK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C159E6138CC8571DDF620B982ECBB25C1BDE0B10B2746CB5AC856FED620AC56F35987
sha3_384: d60fcf56866ec4a1f8a8a58199e938e8cdc3af88b66aafc202fd99cbe9e198bf6257341b7268e00aaaebcbb9b48992ae
ep_bytes: e93d580300e987b00800e968a30600e9
timestamp: 2022-06-17 17:02:57

Version Info:

0: [No Data]

Trojan:Win32/RedlineStealer.XS!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.50471509
FireEyeGeneric.mg.2777a7f891c8e9da
ALYacTrojan.GenericKD.50471509
CylanceUnsafe
SangforInfostealer.Win32.Kryptik.Vcsn
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Stealer.37771388
K7GWTrojan ( 005947a11 )
K7AntiVirusTrojan ( 005947a11 )
CyrenW32/Sabsik.AK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FWFX
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.ccgd
BitDefenderTrojan.GenericKD.50471509
NANO-AntivirusTrojan.Win32.Stealer.jpivvl
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.10d07dae
Ad-AwareTrojan.GenericKD.50471509
SophosMal/Generic-S + Troj/Krypt-NG
DrWebTrojan.PWS.Stealer.32450
ZillyaTrojan.GenKryptik.Win32.145933
TrendMicroTROJ_GEN.R002C0WFJ22
McAfee-GW-EditionGenericRXTJ-PF!2777A7F891C8
EmsisoftTrojan.GenericKD.50471509 (B)
IkarusTrojan.Win32.Krypt
GDataWin32.Trojan.PSE.FRYKYB
JiangminTrojanSpy.Stealer.xtd
AviraTR/Kryptik.ixagj
ArcabitTrojan.Generic.D3022255
ViRobotTrojan.Win32.Z.Genkryptik.919552.A
MicrosoftTrojan:Win32/RedlineStealer.XS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5174454
McAfeeGenericRXTJ-PF!2777A7F891C8
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1645987792
TrendMicro-HouseCallTROJ_GEN.R002C0WFJ22
RisingTrojan.Generic@AI.97 (RDML:BbHb6hq0LM/hHWZ2FIClAw)
MaxSecureTrojan.Malware.184629152.susgen
FortinetW32/GenKryptik.FWDP!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Chgt.AB

How to remove Trojan:Win32/RedlineStealer.XS!MTB?

Trojan:Win32/RedlineStealer.XS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment