Trojan

What is “TrojanDownloader:Win32/Contaskitar!rfn”?

Malware Removal

The TrojanDownloader:Win32/Contaskitar!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Contaskitar!rfn virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Contaskitar!rfn?


File Info:

name: 55D0AD86D14FC43D9BFC.mlw
path: /opt/CAPEv2/storage/binaries/42391b8666d5b281b8d2398abbd1352821956843fb6c5d2905fd55c76b374528
crc32: 8A7FAED6
md5: 55d0ad86d14fc43d9bfcacd1c0fca5d8
sha1: af4cfb337032985fd30a67fedd4de0cc7da87c63
sha256: 42391b8666d5b281b8d2398abbd1352821956843fb6c5d2905fd55c76b374528
sha512: 8f7f4e3844479db9321640abd4846ba3dc088d8cc781229b2ddb63f600fecdf39cf6ad7ce096f3f6a7ac9aee40e9daab071bd5b69b4ea0152fdb6b451a5c06ad
ssdeep: 24576:wlw9dyvXtGK0rRQodA4xO6VM0adPrkFaGu:SMSmAqO4M0aB1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE558D26E212C436D5A7A8308C1745B89431FF526D7AA97E37F87E2DCF327C36825252
sha3_384: dafa8c57a9f0bf9871b4ee7964272ce6007145509e37ba29bd10028a3f76e36fe159c253fba27313f721f9e3016cff44
ep_bytes: 558bec83c4f053b8609c4a00e8b3c6f5
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Arquivo Solicitado
FileDescription: Arquivo Solicitado
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Arquivo Solicitado
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0416 0x04e4

TrojanDownloader:Win32/Contaskitar!rfn also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Lohmys.myeZ
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Graftor.150937
FireEyeGeneric.mg.55d0ad86d14fc43d
SkyhighBehavesLike.Win32.ObfuscatedPoly.th
ALYacGen:Variant.Adware.Graftor.150937
MalwarebytesKraddare.Adware.Advertising.DDS
VIPREGen:Variant.Adware.Graftor.150937
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004d9cab1 )
BitDefenderGen:Variant.Adware.Graftor.150937
CrowdStrikewin/grayware_confidence_90% (D)
VirITTrojan.Win32.Fraudster.BOM
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Adware.Midia.C
APEXMalicious
ClamAVWin.Downloader.Midia-9985779-0
KasperskyTrojan-Banker.Win32.Lohmys.a
AlibabaTrojanBanker:Win32/Lohmys.691ee6bd
NANO-AntivirusTrojan.Win32.Lohmys.dvstgg
RisingDownloader.Contaskitar!8.4C9 (TFE:5:tu15fycoqZE)
EmsisoftGen:Variant.Adware.Graftor.150937 (B)
F-SecureTrojan.TR/Rogue.qpeipum
DrWebTrojan.Fraudster.2213
ZillyaTrojan.Lohmys.Win32.252
Trapminemalicious.high.ml.score
SophosPCMega (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Banker.Lohmys.am
GoogleDetected
AviraTR/Rogue.qpeipum
VaristW32/A-753fb810!Eldorado
Antiy-AVLTrojan[Banker]/Win32.Agent
KingsoftWin32.Troj.Banker.a
MicrosoftTrojanDownloader:Win32/Contaskitar!rfn
XcitiumApplication.Win32.Midia.SK@59q394
ArcabitTrojan.Adware.Graftor.D24D99
ZoneAlarmTrojan-Banker.Win32.Lohmys.a
GDataWin32.Trojan-Downloader.Agent.BP
CynetMalicious (score: 100)
McAfeePUP-FJK
MAXmalware (ai score=99)
DeepInstinctMALICIOUS
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Lohmys.16000426
YandexTrojan.PWS.Lohmys!FBnKrv9l/J8
IkarusPUA.Midia
MaxSecureTrojan.Banker.Lohmys.a
FortinetW32/Fraudster.AB!tr
BitDefenderThetaAI:Packer.436C3E5E19
AVGWin32:Adware-BJA [PUP]
Cybereasonmalicious.370329
AvastWin32:Adware-BJA [PUP]

How to remove TrojanDownloader:Win32/Contaskitar!rfn?

TrojanDownloader:Win32/Contaskitar!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment