Threat Database Trojans Trojan.MSIL.Redline.D

Trojan.MSIL.Redline.D

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 393
First Seen: February 19, 2022
Last Seen: February 17, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Redline.D on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malware that could compromise your computer's security and privacy. It is essential to understand the nature of this threat and take appropriate steps to remove it and protect your system.

What Is Trojan.MSIL.Redline.D?

Trojan.MSIL.Redline.D is a type of malware that can infect your computer and potentially cause harm. The term "Trojan" refers to a broad category of malware that disguises itself as legitimate software, allowing it to bypass security measures and gain unauthorized access to your system. The specifics of Trojan.MSIL.Redline.D, such as its exact behaviors and targets, can vary, but its classification as a Trojan indicates it is designed to deceive and exploit vulnerabilities.

How Trojan.MSIL.Redline.D Operates

Malware like Trojan.MSIL.Redline.D typically operates by exploiting weaknesses in software or human behavior to gain access to a computer system. Once inside, it can perform a variety of malicious actions, including stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system. The exact mechanisms and goals of Trojan.MSIL.Redline.D can depend on its specific design and the intentions of its creators.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Redline.D infection can vary widely, depending on the malware's specific behaviors and the system it has infected. Common signs of malware infection include unexpected changes to system settings, unfamiliar programs or icons, slow system performance, frequent crashes, or pop-ups and other unwanted advertisements. However, some malware is designed to operate stealthily, making it difficult to detect without specific security tools.

How to Remove Trojan.MSIL.Redline.D

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode. This will help prevent the malware from loading and give you a cleaner environment to work in. Ensure you have an internet connection to download and update security software.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help detect and remove Trojan.MSIL.Redline.D and any other malware that may be present.
  3. Uninstall Suspicious Programs: Check your installed programs for anything suspicious or unfamiliar and uninstall it. Be cautious and ensure you are not removing legitimate software.
  4. Reset Your Browser: If you use Chrome, Firefox, or Edge, consider resetting your browser to its default settings. This can help remove any malware-related extensions or settings changes.
  5. Reboot and Re-scan: After taking the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Redline.D requires a systematic approach to ensure your system is thoroughly cleaned and protected. By understanding the nature of this threat and following the steps outlined above, you can help protect your computer and personal data from potential harm. Remember, prevention is key; keeping your operating system, software, and security tools up to date, along with practicing safe computing habits, can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.MSIL.Redline.D
Signature status: No Signature

Known Samples

MD5: 573e8767d71036ef33bc1c96d8d4ae54
SHA1: 4c417af15c976e235c5fcfcccb94c0556c0caaba
SHA256: C78F7787ABD622282C8EF1A07C99616330905A9E154723DE815E5DDFEE05B2E4
File Size: 774.66 KB, 774656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 4.3.106.0
Comments Devart dbForge Data Compare Console for SQL Server
Company Name Devart
File Description Devart dbForge Data Compare Console for SQL Server
File Version 4.3.106.0
Internal Name datacomparecmd.exe
Legal Copyright © Devart. All rights reserved.
Original Filename datacomparecmd.exe
Product Version 4.3.106.0

File Traits

  • .NET
  • .sdata
  • Reactor
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 1,323
Potentially Malicious Blocks: 15
Whitelisted Blocks: 1,098
Unknown Blocks: 210

Visual Map

0 0 0 0 0 0 0 0 0 x 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 ? ? 0 0 0 ? ? ? ? ? 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? 0 ? ? 0 ? x 0 ? ? 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? x x x 0 0 ? ? ? 0 0 0 0 x 0 0 ? x ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? x ? 0 ? ? ? x x ? 0 ? ? 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 ? x 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? x ? 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 x ? ? ? ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\programdata\isolated storage\1ae7c1ba\59fd041e Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\cid\{b1159e65-821c3-21c5-ce21-34a484d54444}\1ae7c1ba::0 Aw �'$�tq7�(� 2Q� RegNtPreCreateKey
HKCU\cid\{b1159e65-821c3-21c5-ce21-34a484d54444}\1ae7c1ba::1 Aw �'$�tq7�(� 2Q� RegNtPreCreateKey
HKCU\cid\{b1159e65-821c3-21c5-ce21-34a484d54444}\1ae7c1ba::3 $`� b`r�SQH�U! � RegNtPreCreateKey
HKCU\cid\{e4580f81}\1ae7c1ba::0 Aw �'$�tq7�(� 2Q� RegNtPreCreateKey
HKCU\cid\{e4580f81}\1ae7c1ba::1 Aw �'$�tq7�(� 2Q� RegNtPreCreateKey
HKCU\cid\{e4580f81}\1ae7c1ba::3 $`� b`r�SQH�U! � RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
Show More
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Info Queried
  • GetAdaptersInfo

Related Posts

Trending

Most Viewed

Loading...