Trojan

TrojanDownloader:Win32/Dalexis!rfn!rfn removal tips

Malware Removal

The TrojanDownloader:Win32/Dalexis!rfn!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Dalexis!rfn!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a known Maktub ransomware decryption instruction / key file.
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Dalexis!rfn!rfn?


File Info:

crc32: 3E161F04
md5: bb8cd5df2be7e8bcc5be439675b3d0a2
name: BB8CD5DF2BE7E8BCC5BE439675B3D0A2.mlw
sha1: 627ac60f64974d5caaf81c2de8ca0977c91f4219
sha256: d351ac17dc0d9476ef029484a165f99e258f546bba2d619b1c6485cb8875ac7a
sha512: 57031eb7d7b2c27d7ecacdc085d07065ced46a742128f9818f62c9fe6633c31aa8eb20ffc52c8415613787946060f5a6b5adf8b977d5ca4fed9656233ebd9cfa
ssdeep: 6144:tnzQnu/cmM1oSigOQT2F8U92Iu7DMVQZhWLvLRXdYX9ji+uhi2PsrhY:hzQnkM1oSiBGI8bxn5m6i+uo20tY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Dalexis!rfn!rfn also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
ClamAVWin.Malware.Cabby-6803812-0
FireEyeGeneric.mg.bb8cd5df2be7e8bc
McAfeeGenericRXAR-RE!BB8CD5DF2BE7
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e3ef1 )
BitDefenderTrojan.Agent.CCGV
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.f2be7e
BaiduWin32.Trojan.Agent.awh
CyrenW32/Trojan.RLTC-3878
APEXMalicious
AvastWin32:Filecoder-AD [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Cabby.zipxi
NANO-AntivirusTrojan.Win32.Cabby.ejsael
MicroWorld-eScanTrojan.Agent.CCGV
RisingRansom.MaktubLocker!1.B2ED (CLASSIC)
Ad-AwareTrojan.Agent.CCGV
SophosMal/Generic-S
ComodoTrojWare.Win32.Cabby.SA@6twhrl
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.Encoder.7386
ZillyaDownloader.Cabby.Win32.1866
TrendMicroRansom.Win32.MATUBLOCKER.SMTH
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
EmsisoftTrojan.Agent.CCGV (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Cabby.coy
AviraTR/Crypt.ZPACK.Gen7
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Win32.Cabby
MicrosoftTrojanDownloader:Win32/Dalexis!rfn!rfn
GridinsoftTrojan.Win32.Downloader.sb!s1
ArcabitTrojan.Agent.CCGV
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
ZoneAlarmTrojan-Downloader.Win32.Cabby.zipxi
GDataTrojan.Agent.CCGV
AhnLab-V3Trojan/Win32.Locky.R192278
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.xqW@aiUK6jbi
ALYacTrojan.Agent.CCGV
TACHYONTrojan-Downloader/W32.Cabby.379904
VBA32BScope.TrojanDownloader.Gootkit
MalwarebytesRansom.MaktubLocker
PandaTrj/Genetic.gen
ESET-NOD32Win32/Filecoder.MaktubLocker.B
TrendMicro-HouseCallRansom.Win32.MATUBLOCKER.SMTH
TencentMalware.Win32.Gencirc.10b27092
YandexTrojan.GenAsa!jIt9QWjtyVA
IkarusTrojan.FileCryptor
eGambitUnsafe.AI_Score_99%
FortinetW32/MaktubLocker.B!tr
AVGWin32:Filecoder-AD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.C3DB.Malware.Gen

How to remove TrojanDownloader:Win32/Dalexis!rfn!rfn?

TrojanDownloader:Win32/Dalexis!rfn!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment