Gridinsoft Logo

Launcher.exe Malware RedLine Analysis

Malware RedLine
Updated on 2024-07-09 (3 months ago)
Checked by Online Virus Scanner
Online Virus Checker v.1.0.181.174
DB Version: 2024-07-09 05:00:26

Malware.Win32.RedLine.tr

RedLine Stealer is a malicious program designed to exfiltrate users’ confidential data from browsers, systems, and installed software. It is often delivered through email attachments or compromised websites. RedLine not only steals sensitive information but also poses a significant threat by introducing other malware into the victim's operating system. This two-pronged attack approach makes RedLine a potent and dangerous cyber threat.

File Launcher.exe
Checked 2024-07-09 02:44:32
MD5 027bb5827e250671ebaee0200df3eaf4
SHA1 73329c59bc6cc585ec1c18e216da1c65b5518c62
SHA256 80f306d656669534f8996c5b83c6b0c1aa87e0097bac53b79d8ec30550ea5e44
SHA512 49f5ce1731b941854566037a5bf1495b1151e5b770a482677d86ac3ab1dc8dd0f3269f90a054d8d828560767d4098850f819a144f14fd62314326d2b15a9b6d9
Imphash f34d5f2d4577ed6d9ceec516c1f5a744
File Size 2159616 bytes

Malware.Win32.RedLine.tr Removal

Malware.Win32.RedLine.tr Removal

Gridinsoft has the capability to identify and eliminate Malware.Win32.RedLine.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation 0x0000 0x04b0
Comments
CompanyName master131
FileDescription Extreme Injector
FileVersion 3.7.3.0
InternalName Extreme Injector.exe
LegalCopyright Copyright © 2017
LegalTrademarks master131
OriginalFilename Extreme Injector.exe
ProductName Extreme Injector
ProductVersion 3.7.3.0
Assembly Version 3.7.3.0

Portable Executable Info

Image Base: 0x00400000
Entry Point: 0x0043029e
Compilation: 2081-09-23 12:17:32
Checksum: 0x0007efad (Actual: 0x0021a7e0)
OS Version: 4.0
PEiD: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Sign: The PE file does not contain a certificate table.
Sections: 3
Imports: mscoree,
Exports: 0
Resources: 1

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x0002e2a4 0x0002e400 e69e8c750faf07194f66a310f5e3b5f3 6.19
.rsrc 0x00032000 0x000003d4 0x00000400 a9162519b21cee786e392f7c2edfae41 3.48
.reloc 0x00034000 0x0000000c 0x00000200 ad0a6b4525092f96ee7808055cdae654 0.08

Leave a comment *

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware