Ransom

Ransom:Win32/Rantest!rfn removal tips

Malware Removal

The Ransom:Win32/Rantest!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Rantest!rfn virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ransom:Win32/Rantest!rfn?


File Info:

crc32: BBE095D9
md5: c13794036129e9e6d1e3070802802731
name: C13794036129E9E6D1E3070802802731.mlw
sha1: 1eb70e4a157efad2cfaa8380e8ea609c71252416
sha256: 4e187b9531d5f4b986f66c2e2c31526adcdcb8478370539a03afdd679967510a
sha512: 364a3f02f99c09956f705f63cef687d7d8a8115866f2c4810fe5fe5c7d0c296e04d64d52ce5b3db48a90eda5abbfe1bb0a4537b33f18a74cbf77115d3f59ef23
ssdeep: 6144:umYXefGbpma6dhJ/2u/d6AjWcPyC4koXAXUd2CCkm/taEFl3g6RswD1f6Wp5V:uz9mldhJ/2u/d6AjWcfHEhm/XFl3fRR
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.1.0.76
InternalName: WeakCryptor.exe
FileVersion: 1.1.0.76
ProductVersion: 1.1.0.76
FileDescription:
OriginalFilename: WeakCryptor.exe

Ransom:Win32/Rantest!rfn also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanApplication.RanSim.D
FireEyeGeneric.mg.c13794036129e9e6
McAfeeGenericRXCZ-GH!C13794036129
MalwarebytesBladabindi.Backdoor.Njrat.DDS
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005159961 )
BitDefenderApplication.RanSim.D
K7GWTrojan ( 005159961 )
Cybereasonmalicious.36129e
CyrenW32/S-704b571d!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Generic-6268112-0
KasperskyHEUR:Trojan-Ransom.Win32.Fasem.a
NANO-AntivirusTrojan.Win32.StartPage.ezgaba
Ad-AwareApplication.RanSim.D
EmsisoftTrojan.Ransom (A)
F-SecureHeuristic.HEUR/AGEN.1127299
DrWebTrojan.MulDrop7.48244
ZillyaTool.RanSim.Win32.82
McAfee-GW-EditionGenericRXCZ-GH!C13794036129
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataApplication.RanSim.D
JiangminTrojan.Generic.blxmo
WebrootW32.Ransomsimulation
AviraHEUR/AGEN.1127299
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitApplication.RanSim.D
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Fasem.d
MicrosoftRansom:Win32/Rantest!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Miner.C2265471
BitDefenderThetaGen:NN.ZemsilF.34590.xm0@aO5JZSo
ALYacApplication.RanSim.D
VBA32Trojan.MSIL.Miner
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Riskware.KnownBe4.A
TencentMalware.Win32.Gencirc.10b531d3
YandexTrojan.StartPage!lYqrblf0HfQ
MAXmalware (ai score=99)
FortinetMSIL/Fasem.A!tr.ransom
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.1b4

How to remove Ransom:Win32/Rantest!rfn?

Ransom:Win32/Rantest!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment