Trojan

Trojan:Win32/Reline.RA!MTB removal instruction

Malware Removal

The Trojan:Win32/Reline.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Reline.RA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Anomalous binary characteristics

How to determine Trojan:Win32/Reline.RA!MTB?


File Info:

name: 2F453310F098F258077F.mlw
path: /opt/CAPEv2/storage/binaries/c85fbe74e732833f2bb0db33c577c2eb06166fab9b7d0f7e45744a811e4aee5a
crc32: F9CBACA4
md5: 2f453310f098f258077f7040f340eb9e
sha1: 0c76bb155f8b0a107f1cb3bb8d7d343ae40386a3
sha256: c85fbe74e732833f2bb0db33c577c2eb06166fab9b7d0f7e45744a811e4aee5a
sha512: f88808e237d35ee2dc7dbbc419d71d5265ecc3f8666ce9118cdf52d69c60391ff9c57c7a16ae753f838a7da3d046ee9ebc0424075e809c1be5fb3ba2185c007d
ssdeep: 98304:pbKU2g1jp4O5zBeE35PC8Tcw8MQAkq7LH+CU21p3a1eM9pgjSgR:p+kDNBpVHHnLHGsp3a1eUM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11316333E3061191DC015F6B5AD7F7D27CACD4B7C10BE4626726F0E00AA9ECD09A8EB65
sha3_384: 555c3329d582990cf95145150dc0a84fb1f97a5bc55292d0e1233569126cea2ba7e9f2ae6384f0e5a94c96aea0cf1e94
ep_bytes: 6801708700e801000000c3c334e70278
timestamp: 2021-12-16 16:09:30

Version Info:

0: [No Data]

Trojan:Win32/Reline.RA!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.81830
FireEyeGeneric.mg.2f453310f098f258
ALYacTrojan.GenericKDZ.81830
CylanceUnsafe
ZillyaTrojan.Asprotect.Win32.34
K7AntiVirusTrojan ( 0058bf581 )
AlibabaPacked:Win32/Asprotect.4b5f9d69
K7GWTrojan ( 0058bf581 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.KU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Fragtor-9916737-0
KasperskyHEUR:Trojan-PSW.Win32.Agent.gen
BitDefenderTrojan.GenericKDZ.81830
NANO-AntivirusTrojan.Win32.Stealer.jjowot
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKDZ.81830
SophosMal/Generic-S
DrWebTrojan.PWS.Stealer.31811
TrendMicroTROJ_FRS.0NA104LL21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftTrojan.GenericKDZ.81830 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.T64CN8
JiangminTrojan.PSW.Agent.cur
KingsoftWin32.PSWTroj.Undef.(kcloud)
GridinsoftTrojan.Heur!.032160A1
ViRobotTrojan.Win32.Z.Asprotect.4386816.A
MicrosoftTrojan:Win32/Reline.RA!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R459608
McAfeeGenericRXRE-TU!2F453310F098
MAXmalware (ai score=80)
VBA32BScope.Trojan.Fabookie
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_FRS.0NA104LL21
YandexTrojan.Asprotect!UJcQc0BB5XU
IkarusTrojan.Win32.ASProtect
MaxSecureTrojan.Malware.12570143.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34114.@NWaaGgzj4pi
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Reline.RA!MTB?

Trojan:Win32/Reline.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment