Trojan

Trojan:Win32/RedLineStealer!pz removal

Malware Removal

The Trojan:Win32/RedLineStealer!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLineStealer!pz virus can do?

  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the CookieStealer malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Uses XCOPY for copying files
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/RedLineStealer!pz?


File Info:

name: 494F25F1D93D818D75D9.mlw
path: /opt/CAPEv2/storage/binaries/7b869018d90be43a61f0e9e8fee2013509759e9c8337db288b5d2a7d512dcc42
crc32: B6E26826
md5: 494f25f1d93d818d75d95c58f5724529
sha1: 45466c31ea1114b2aac2316c0395c8f5c984eb94
sha256: 7b869018d90be43a61f0e9e8fee2013509759e9c8337db288b5d2a7d512dcc42
sha512: 4c8a42403dedd8ba803e7a6542a1d2e1b56a78e9379f98fbc05986d4d7bf9984a224038035e4e03a215125bc44ae9ea84adb10d30148dde1c55a3d72ed59da83
ssdeep: 24576:UIVFA1pqtg/TnMbX0lwyh0FVmEBy/1kwFYyOsbM5cPtSixxeQiYfmh:1FA1pvTMbOwa0TmzSMYE4ePtSi+QiYOh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126659F21F6829036EDE300B286FE477F8D68BA21071454D7E3C42D699A719E27B3B717
sha3_384: 2b021b4382a816f3c814df7192c3c0be3e1cf6516f20de8761eabd33f5ca90ebb9d9fa12e8c36a5d98e24c71c35e4aa9
ep_bytes: e8f5040000e974feffff558bec56ff75
timestamp: 2021-09-14 02:08:46

Version Info:

FileVersion: 1.0.0.1
LegalCopyright: Copyright (C) 2019
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Trojan:Win32/RedLineStealer!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Socelars.4!c
CynetMalicious (score: 100)
CAT-QuickHealTrojan.DisbukRI.S19305183
SkyhighBehavesLike.Win32.Generic.th
ALYacGen:Variant.Zusy.371633
Cylanceunsafe
VIPREGen:Variant.Zusy.371633
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 005690661 )
BitDefenderGen:Variant.Zusy.371633
K7GWSpyware ( 005690661 )
VirITTrojan.Win32.PSWStealer.DAO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PYV
APEXMalicious
KasperskyHEUR:Trojan.Script.Generic
AlibabaTrojanSpy:Win32/Socelars.0955d0d7
NANO-AntivirusTrojan.Script.Stealer.jvhbnw
ViRobotTrojan.Win32.Z.Socelars.1448448.AO
MicroWorld-eScanGen:Variant.Zusy.371633
AvastJS:ScriptXE-inf [Trj]
RisingStealer.FBAdsCard!1.CE03 (CLASSIC)
TACHYONTrojan/W32.Agent.1448448.AA
EmsisoftTrojan-Spy.Socelars (A)
F-SecureHeuristic.HEUR/AGEN.1307841
DrWebTrojan.Siggen13.57604
ZillyaTrojan.Disbuk.Win32.207
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.494f25f1d93d818d
SophosTroj/Agent-BGVO
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Disbuk.da
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1307841
Antiy-AVLTrojan[Spy]/Win32.Socelars
Kingsoftmalware.kb.a.947
MicrosoftTrojan:Win32/RedLineStealer!pz
XcitiumMalware@#3c3isgadd6acp
ArcabitTrojan.Zusy.D5ABB1
SUPERAntiSpywareTrojan.Agent/Gen-SpySocelars
ZoneAlarmHEUR:Trojan.Script.Generic
GDataGen:Variant.Zusy.371633
VaristW32/Socelars.G.gen!Eldorado
AhnLab-V3Infostealer/Win.Socelars.R372531
McAfeeGenericRXLT-RQ!494F25F1D93D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agentb
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10bd3db1
YandexTrojanSpy.Socelars!ODWU1aL7btk
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.74142850.susgen
FortinetW32/Socelars.S!tr.spy
BitDefenderThetaGen:NN.ZexaF.36744.y10@au6YVxlj
AVGJS:ScriptXE-inf [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLineStealer!pz?

Trojan:Win32/RedLineStealer!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment