Trojan

About “TrojanDownloader:Win32/Wintrim!rfn” infection

Malware Removal

The TrojanDownloader:Win32/Wintrim!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Wintrim!rfn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Wintrim!rfn?


File Info:

name: 8D69C461087B463EE738.mlw
path: /opt/CAPEv2/storage/binaries/c072158efb03891b88e0187922fb58f0fedadab1bb91ed8f9147fe9a67862cf5
crc32: DCB1B03E
md5: 8d69c461087b463ee7384f77bd141e29
sha1: 8e563f24edb9e5b00b1796972993f7796a4db891
sha256: c072158efb03891b88e0187922fb58f0fedadab1bb91ed8f9147fe9a67862cf5
sha512: 56badab7f50c220b911c54d1110c35c4bdc1e68ba90647eaf45eaaf614027244c6896f10886834253abf0b56b6cb53eb1c8c48718fe17f404b216a2fba9ff9e1
ssdeep: 12288:nTNso7AZgcADT8dP+wumdvSsbn1KuknKxJVnYUbL37ct8erGbwgzEbudvtxt+5d1:nTNmAmr1dvTcPK1YGrM2BvMd1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146351244C4EED07FFC1C61B0AACF6875E8A58E9D237E12097A91FE325217921F91B0B5
sha3_384: 9a5e12b7a1e52b7eced4e7e6e70ed3b4ec4e43a0157de00c44035076e2ec2ed2573b205b93571870f800c997878547f5
ep_bytes: 81ec780500005355565733ff8d4c2470
timestamp: 2006-12-09 19:31:54

Version Info:

0: [No Data]

TrojanDownloader:Win32/Wintrim!rfn also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Packed.685
MicroWorld-eScanGen:Variant.Adware.Navipromo.5
ClamAVWin.Downloader.78657-1
FireEyeGeneric.mg.8d69c461087b463e
SkyhighBehavesLike.Win32.PWSZbot.th
McAfeeDownloader-BPJ.gen.b
Cylanceunsafe
ZillyaDownloader.LiplerGen.Win32.12
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000041 )
AlibabaTrojanDownloader:Win32/Lipler.602234bd
K7GWTrojan ( 700000041 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaAI:Packer.D4B664491F
VirITTrojan.Win32.Generic.BXKF
SymantecPUA.LivePlayer!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Skintrim.EE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Lipler.iml
BitDefenderGen:Variant.Adware.Navipromo.5
NANO-AntivirusTrojan.Win32.Lipler.bjybw
SUPERAntiSpywareTrojan.Agent/Gen-Lipon
AvastWin32:Hrupka-A [Cryp]
TencentTrojan.Win32.DL.Lipler.b
EmsisoftGen:Variant.Adware.Navipromo.5 (B)
F-SecureAdware:W32/Wintrim.gen!P
VIPREGen:Variant.Adware.Navipromo.5
TrendMicroTROJ_LIPLER.SMT
Trapminemalicious.high.ml.score
SophosMal/Swizzor-H
IkarusTrojan-Downloader.Win32.Lipler
GDataGen:Variant.Adware.Navipromo.5
JiangminTrojanDownloader.Lipler.zp
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Downloader]/Win32.Lipler
KingsoftWin32.Troj.Undef.a
XcitiumPacked.Win32.Hrup.b@2hm02h
ArcabitTrojan.Adware.Navipromo.5
ZoneAlarmTrojan-Downloader.Win32.Lipler.iml
MicrosoftTrojanDownloader:Win32/Wintrim!rfn
VaristW32/Wintrim.C.gen!Eldorado
AhnLab-V3Win-Trojan/Lipler.Gen
VBA32SScope.Trojan.Lipler.03
ALYacGen:Variant.Adware.Navipromo.5
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware.AI.DDS
PandaAdware/NaviPromo
TrendMicro-HouseCallTROJ_LIPLER.SMT
RisingDownloader.Skintrim!1.9A1D (CLASSIC)
YandexTrojan.DL.Lipler!AqR2QIbAOl8
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Downloader.Lipler.IML
FortinetW32/Lipler.IML!tr.dldr
AVGWin32:Hrupka-A [Cryp]
Cybereasonmalicious.4edb9e
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Wintrim!rfn?

TrojanDownloader:Win32/Wintrim!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment