Backdoor

Backdoor:Win32/RemoteManipulator!rfn information

Malware Removal

The Backdoor:Win32/RemoteManipulator!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/RemoteManipulator!rfn virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Backdoor:Win32/RemoteManipulator!rfn?


File Info:

crc32: C4214609
md5: 1999896087f7edc2d521787131d08fba
name: aaaaaaaa.exe
sha1: 927a3a6874004049e0d6400eb218a6f377d67afb
sha256: 3d72d9ba9f710fc9b83fe7ae88a0ba6fa84e4bf9e2a9b67b020aac73ea2f256a
sha512: a16768a8fef18561f054b1846074feeaac4b77b60897bafca853b7641d7c06fac533b6d1f74342d068959264d4ff065bca4436742c18ec796f7fea1d4a2a9c15
ssdeep: 196608:OPfaBYMRlp30bgwOGcjwppBR5dgI8H++H:OK2MRlN0bgXGGwpj5gI8e
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/RemoteManipulator!rfn also known as:

MicroWorld-eScanGen:Variant.Zusy.153837
CAT-QuickHealTrojan.Dynamer.S239831
McAfeeGenericRXBV-FW!1999896087F7
MalwarebytesTrojan.Banload
ZillyaTrojan.RA.Win32.52
K7GWTrojan ( 004c3fe61 )
K7AntiVirusTrojan ( 004c3fe61 )
ArcabitTrojan.Zusy.D258ED
TrendMicroTROJ_GEN.R01FC0CIF18
CyrenW32/Trojan.FASM-5282
SymantecSMG.Heur!gen
TrendMicro-HouseCallTROJ_GEN.R01FC0CIF18
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Zusy.153837
NANO-AntivirusTrojan.Win32.Reconyc.ejtcsm
Paloaltogeneric.ml
Ad-AwareGen:Variant.Zusy.153837
EmsisoftGen:Variant.Zusy.153837 (B)
ComodoUnclassifiedMalware
F-SecureGen:Variant.Zusy.153837
DrWebTrojan.Siggen6.60941
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1005908
Antiy-AVLTrojan/Win32.Scar
MicrosoftBackdoor:Win32/RemoteManipulator!rfn
Endgamemalicious (high confidence)
ViRobotTrojan.Win32.Z.Zusy.6541824
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataGen:Variant.Zusy.153837
AhnLab-V3Trojan/Win32.Fuerboos.R232927
ALYacGen:Variant.Zusy.153837
AVwareTrojan.Win32.Generic!BT
VBA32TScope.Trojan.Delf
CylanceUnsafe
ESET-NOD32a variant of Win32/RA-based.NCG
IkarusTrojan.Win32.ChePro
FortinetW32/RABased.RFCL!tr
AVGWin32:Malware-gen
Cybereasonmalicious.087f7e
PandaTrj/Genetic.gen
CrowdStrikemalicious_confidence_90% (D)
Qihoo-360Win32/Backdoor.d55

How to remove Backdoor:Win32/RemoteManipulator!rfn?

Backdoor:Win32/RemoteManipulator!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment