Categories: Backdoor

About “Backdoor:Win32/Simda!rfn” infection

The Backdoor:Win32/Simda!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Simda!rfn virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Simda!rfn?


File Info:

crc32: 52B1A45Bmd5: 0000b8a0eb87a843cae1d9c5b8b635f1name: 0000b8a0eb87a843cae1d9c5b8b635f1.exesha1: 67a9a9d70a5f6248067390255b7ab55c539592ccsha256: 1e00e0e9cea37bd275a69b141ec32ea05eac2796ad2e0390c8d8f443dc9ea895sha512: 93dd6d57ab55e833afdc31b22c781fa928409f56c13a3d56d44cc027067166ec3ded5d7f04495109fb2b180f1a7a87981b8a9df0d7b19e867989a6bb6e27a36bssdeep: 3072:/W/Qc+sSxnTrGadgsFqZeo4pwkhUmZr3hPsOraS:/W/2sSxTrGvsFUejWyZr3hPswatype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Simda!rfn also known as:

Bkav W32.DropperMultiA.Trojan
MicroWorld-eScan Gen:Trojan.Heur.kqW@Xc62oad
CAT-QuickHeal Trojan.Mauvaise.SL1
McAfee Trojan-Shifu!0000B8A0EB87
Malwarebytes Spyware.Shiz
BitDefender Gen:Trojan.Heur.kqW@Xc62oad
K7GW Spyware ( 004ce3951 )
K7AntiVirus Spyware ( 004ce3951 )
TheHacker Trojan/Spy.Shiz.ncr
TrendMicro TSPY_SHIZ.SMCP
NANO-Antivirus Trojan.Win32.Shiz.dvsrfy
F-Prot W32/Shifu.A.gen!Eldorado
Symantec SMG.Heur!gen
TrendMicro-HouseCall TSPY_SHIZ.SMCP
Paloalto generic.ml
ClamAV Win.Trojan.Shifu-6330434-1
GData Win32.Trojan-Spy.Shiz.D
Kaspersky Trojan-Banker.Win32.Shifu.eph
ViRobot Trojan.Win32.Agent.168448.U
Tencent Win32.Trojan-banker.Shifu.A
Ad-Aware Gen:Trojan.Heur.kqW@Xc62oad
Sophos Troj/Shiz-BO
Comodo TrojWare.Win32.Shifu.AK@5v0un7
F-Secure Gen:Trojan.Heur.kqW@Xc62oad
DrWeb Trojan.MulDrop7.20629
Zillya Trojan.Shiz.Win32.2662
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.TrojanShifu.ch
Trapmine malicious.high.ml.score
Emsisoft Gen:Trojan.Heur.kqW@Xc62oad (B)
Ikarus Trojan-Banker.ShiFu
Cyren W32/Shifu.A.gen!Eldorado
Webroot W32.Trojan.Gen
Avira TR/Dropper.Gen
MAX malware (ai score=100)
Antiy-AVL Trojan/Win32.TSGeneric
Microsoft Backdoor:Win32/Simda!rfn
Endgame malicious (high confidence)
SUPERAntiSpyware Spyware.Agent/Gen-Shiz
ZoneAlarm Trojan-Banker.Win32.Shifu.eph
AhnLab-V3 Trojan/Win32.Shifu.R164118
VBA32 BScope.TrojanBanker.Shifu
TACHYON Trojan/W32.Agent.168448.TE
Cylance Unsafe
Panda Trj/Genetic.gen
Arcabit Trojan.Heur.EA7D88
ESET-NOD32 Win32/Spy.Shiz.NCR
Rising Trojan.Shiz!1.A8EF (CLASSIC)
Yandex Trojan.PWS.Shifu!
SentinelOne static engine – malicious
Fortinet W32/Shiz.NCR!tr.spy
AVG Win32:Shifu-B [Trj]
Cybereason malicious.0eb87a
Avast Win32:Shifu-B [Trj]
CrowdStrike malicious_confidence_100% (D)
Qihoo-360 Win32/Trojan.b83

How to remove Backdoor:Win32/Simda!rfn?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Generic.Dacic.C6835568.A.9C2F4F0E information

The Generic.Dacic.C6835568.A.9C2F4F0E is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

How to remove “Fragtor.545276”?

The Fragtor.545276 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.4236857157 removal tips

The Malware.AI.4236857157 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

How to remove “Win32/AutoRun.VB.ALG”?

The Win32/AutoRun.VB.ALG is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Win32/Spy.Virkonni.F removal instruction

The Win32/Spy.Virkonni.F is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “Backdoor.Farfli.AH”?

The Backdoor.Farfli.AH is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago