Spy

MonitoringTool:Win32/SpyRecon!rfn removal guide

Malware Removal

The MonitoringTool:Win32/SpyRecon!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MonitoringTool:Win32/SpyRecon!rfn virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MonitoringTool:Win32/SpyRecon!rfn?


File Info:

name: 5A05020CC834C6D21DF4.mlw
path: /opt/CAPEv2/storage/binaries/ef9fee35ca031e6b7f52af39b653e908021a781964558ea714fc9a6ab284cd32
crc32: D0B9BBEA
md5: 5a05020cc834c6d21df4773293bc3c05
sha1: 10c54437bd080185eae5b7cac9f8005e28ccf39d
sha256: ef9fee35ca031e6b7f52af39b653e908021a781964558ea714fc9a6ab284cd32
sha512: 6a3b8ff281fed92bef0ccb9c44c0f931920596a1e850dce5a1f7fdb79fb7dfa8e1620bb152c42a4a660bc36397e82546eda50d0a7a5986cc4c11ea4832a855b4
ssdeep: 12288:5y0c86jMoBYckWsNSwghuEwmAtH1R8yyTK2+fX7BUIQTE:o0c87oBYckWsNSwXEwmuyTK2+fX7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193A4238EBF5A41A0F38090706BCECF28999C858EED17373318A9D51A74737E16B85D49
sha3_384: 63b6ba53d2c53763e8584ef3d71c281a1fd3a5a1f33c10d99c91e96e3f8b0dd55e6ef49552718c2022049f64851d2272
ep_bytes: 60be00304f008dbe00e0f0ffc787f448
timestamp: 2008-01-23 10:51:12

Version Info:

0: [No Data]

MonitoringTool:Win32/SpyRecon!rfn also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.46633250
FireEyeTrojan.GenericKD.46633250
McAfeeSpyRecon.a
MalwarebytesMalware.Heuristic.1003
ZillyaTrojan.Spyrecon.Win32.11
SangforTrojan.Win32.Spyrecon.AA
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/Spyrecon.5d1cdd56
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.cc834c
VirITTrojan.Win32.Generic.AR
SymantecSpyware.Recon
ESET-NOD32a variant of Win32/Spy.Spyrecon.AA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
BitDefenderTrojan.GenericKD.46633250
NANO-AntivirusTrojan.Win32.Spyrecon.dcbpv
TencentWin32.Trojan.Spy.Gwnw
F-SecureTrojan.TR/Spy.Spyrecon.I.1
VIPRETrojan.GenericKD.46633250
TrendMicroTROJ_NEWHEUR.EQ
McAfee-GW-EditionSpyRecon.a
EmsisoftTrojan.GenericKD.46633250 (B)
IkarusVirus.Win32.Spyreacon
GDataTrojan.GenericKD.46633250
WebrootW32.Malware.Gen
AviraTR/Spy.Spyrecon.I.1
MAXmalware (ai score=99)
Antiy-AVLTrojan[Spy]/Win32.Spyrecon
XcitiumMalware@#2e8cuoi4j9hhz
ArcabitTrojan.Generic.D2C79122
MicrosoftMonitoringTool:Win32/SpyRecon!rfn
GoogleDetected
VBA32TrojanSpy.Skeeyah
ALYacTrojan.GenericKD.46633250
Cylanceunsafe
TrendMicro-HouseCallTROJ_NEWHEUR.EQ
RisingSpyware.Spyrecon!8.5601 (CLOUD)
YandexTrojanSpy.Spyrecon!xJI89PITAy8
MaxSecureTrojan.Malware.2203360.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZexaF.36196.DmGfaSvMEPhc
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MonitoringTool:Win32/SpyRecon!rfn?

MonitoringTool:Win32/SpyRecon!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment