Malware

Exploit:Win32/RpcDcom!rfn removal guide

Malware Removal

The Exploit:Win32/RpcDcom!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit:Win32/RpcDcom!rfn virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Exploit:Win32/RpcDcom!rfn?


File Info:

crc32: FE696773
md5: 99cd5125197d84ea398c9f38e5b4be35
name: 99CD5125197D84EA398C9F38E5B4BE35.mlw
sha1: 7d39cb033ad0536ed1cd64c5e8458db6d4768689
sha256: f89c8f3a6caeb19ad7a6ef77c1222dd9fe37e097529b33c2d6644884bd477b5f
sha512: f7fd62ffc81ed8de13b60b03fd23b4c3d68c17b73e71f9fd318c4e64c6b273ce1e36ee057990191973bfc87f6f02e1e9ef0a7d55cd61c188bee7b116ee099561
ssdeep: 49152:UHO/4MnYYJ2ZhqSGLHkJEMk+V8tgJd8Wic8YcM4R81qkqd6:4IDQk+Cga3c85f81qfd6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2002-2003 Microsoft Corporation. All rights reserved.
InternalName: dwtrig20.exe
FileVersion: 11.0.8160
CompanyName: Microsoft Corporation
LegalTrademarks1: Microsoftxae is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windowsxae is a registered trademark of Microsoft Corporation.
ProductName: Watson Subscriber for SENS Network Notifications
ProductVersion: 11.0.8160
FileDescription: Watson Subscriber for SENS Network Notifications
OriginalFilename: dwtrig20.exe
Translation: 0x0000 0x04e4

Exploit:Win32/RpcDcom!rfn also known as:

BkavW32.AIDetectVM.malware2
FireEyeGeneric.mg.99cd5125197d84ea
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
CyrenW32/Ursu.DK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:GenMalicious-IER [Trj]
ClamAVWin.Malware.Kolab-6803326-0
RisingExploit.RpcDcom!8.60D (CLOUD)
F-SecureTrojan.TR/Trash.Gen2
McAfee-GW-EditionBehavesLike.Win32.Valla.wh
SophosML/PE-A
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_100%
AviraTR/Trash.Gen2
MicrosoftExploit:Win32/RpcDcom!rfn
GDataWin32.Trojan-Dropper.Rbot.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Facelabc.Gen
McAfeeTrojan-FDXG!99CD5125197D
MAXmalware (ai score=99)
PandaTrj/CI.A
TencentVirus.Win32.Kolabc.aad
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SuspectCRC.0B1D!tr
AVGWin32:GenMalicious-IER [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.fe8

How to remove Exploit:Win32/RpcDcom!rfn?

Exploit:Win32/RpcDcom!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment