Trojan

Trojan.Downloader.rnKfaqMBMyhj (file analysis)

Malware Removal

The Trojan.Downloader.rnKfaqMBMyhj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.rnKfaqMBMyhj virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Anomalous binary characteristics

Related domains:

133uc.com

How to determine Trojan.Downloader.rnKfaqMBMyhj?


File Info:

crc32: 22EED35D
md5: 81a92af647b032187bf4dd818b048f5a
name: 81A92AF647B032187BF4DD818B048F5A.mlw
sha1: 482f9080bda588d73ff9f67bdf4ac8ae6bbd461c
sha256: 213902c53c44a56464821675ee015fc6dcf0d636d34c9ac75c1ab817f263ce67
sha512: 6b7dc22c83ddf1519922ae860e91a60bd7151ceff1933f69fc943b7c1b82049ef5ba11096127c5c31a468b30b9517a0ad1a5a277a634358be2d6c58c4b529c81
ssdeep: 24576:mknenoECqhLtFIVy36HQNUPUJeHQXky4Fr8ymDaMxs731Xr1OI/onlp7kog6rJg:m0enrhxFIc344UPUJeHQX4Fr9mDMrxr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.4.0
CompanyName: x4e50x5929x767bx9646x5668
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.4.0
FileDescription:
OriginalFilename:
Translation: 0x0804 0x03a8

Trojan.Downloader.rnKfaqMBMyhj also known as:

K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Multi.Generic.4!c
ClamAVWin.Trojan.Downloader-46660
ALYacGen:Trojan.Downloader.rnKfaqMBMyhj
BitDefenderGen:Trojan.Downloader.rnKfaqMBMyhj
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.647b03
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojanDownloader:Win32/BackDr.86f2d709
NANO-AntivirusTrojan.Win32.FlyStudio.pmato
MicroWorld-eScanGen:Trojan.Downloader.rnKfaqMBMyhj
TencentWin32.Trojan.Mir2.Dztp
Ad-AwareGen:Trojan.Downloader.rnKfaqMBMyhj
SophosMal/BackDr-X
ComodoMalware@#2dwm18schgwg4
BitDefenderThetaAI:Packer.9ABA49D120
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.81a92af647b03218
EmsisoftGen:Trojan.Downloader.rnKfaqMBMyhj (B)
WebrootW32.InfoStealerPrast
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan/Generic.ASCommon.FB
MicrosoftTrojan:Win32/Occamy.C21
GDataGen:Trojan.Downloader.rnKfaqMBMyhj
McAfeeArtemis!81A92AF647B0
MAXmalware (ai score=100)
PandaTrj/CI.A
YandexTrojan.GenAsa!jn7cN+QNheg
IkarusTrojan-GameThief.Win32.Lmir
FortinetW32/Genome.PWFS!tr
Paloaltogeneric.ml

How to remove Trojan.Downloader.rnKfaqMBMyhj?

Trojan.Downloader.rnKfaqMBMyhj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment