Trojan

TrojanDropper:Win32/Lamechi!rfn removal guide

Malware Removal

The TrojanDropper:Win32/Lamechi!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Lamechi!rfn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to disable or modify Explorer Folder Options
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine TrojanDropper:Win32/Lamechi!rfn?


File Info:

name: B84D49EBDF208D5C8247.mlw
path: /opt/CAPEv2/storage/binaries/bb8273095bdd1866df4c2bdc43e1921330bca66ee5acc87d6bc924b2e07b6db5
crc32: 486B3659
md5: b84d49ebdf208d5c8247811410cac5f5
sha1: 73fb87dc3b3e8c704ed96747a7622633c4090041
sha256: bb8273095bdd1866df4c2bdc43e1921330bca66ee5acc87d6bc924b2e07b6db5
sha512: 60cd3f76ff6ead2c064741b1cef0b081d0854c034d8cbc9b348ce906ffc27a932d25f7b042d6a5fc3e3086cc1b37c1bc55598a34a829d7e83028601b53fd4379
ssdeep: 384:9/06wayA+1mwnA353BXR+oGfP5d/ZBHXME+l93qPAqee/w6yt/EWD+S83BXR+oGU:9MpQNwC3BEddsEqOt/hytp+x3BEJwRrN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B73D643B752C680F54A6179688387A96753FD70AF037A075160FF3F3AB39A14E91B22
sha3_384: 217e1ef96ef65e693e96f995319953f823ffc5c129a40204a6db6981a6d9b4620c50e7adc9bda465f0a7e4ca5d1fb0df
ep_bytes: 68186d4000e8f0ffffff000000000000
timestamp: 2009-01-06 03:24:42

Version Info:

Translation: 0x0409 0x04b0
ProductName: Microsoft Windows
FileVersion: 1.00.0050
ProductVersion: 1.00.0050
InternalName: music
OriginalFilename: music.exe

TrojanDropper:Win32/Lamechi!rfn also known as:

BkavW32.FamVT.ViselCPM.Worm
LionicTrojan.Win32.Vilsel.lQNo
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74328
McAfeeVilsel.gen.o
MalwarebytesVB.Trojan.Generic.DDS
ZillyaTrojan.Vilsel.Win32.49226
SangforWorm.Win32.VB.pro3
K7AntiVirusTrojan ( 005640b91 )
K7GWP2PWorm ( 004e46c61 )
Cybereasonmalicious.bdf208
BitDefenderThetaAI:Packer.AD53139321
VirITTrojan.Win32.Generic.AZOV
CyrenW32/VB.DS.gen!Eldorado
SymantecTrojan.Dropper
tehtrisGeneric.Malware
ESET-NOD32Win32/VB.THB
APEXMalicious
ClamAVWin.Malware.Genpack-6989317-0
KasperskyTrojan.Win32.Vilsel.bpxe
BitDefenderTrojan.GenericKDZ.74328
NANO-AntivirusTrojan.Win32.Vilsel.cqkyek
AvastWin32:VB-AEMS [Trj]
TencentTrojan.Win32.VB.blb
SophosTroj/VB-EUH
BaiduWin32.Trojan.VB.h
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen2.50583
VIPRETrojan.GenericKDZ.74328
TrendMicroTROJ_VILSEL.AI
McAfee-GW-EditionBehavesLike.Win32.Vilsel.lt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b84d49ebdf208d5c
EmsisoftTrojan.GenericKDZ.74328 (B)
IkarusTrojan.Win32.Scar
GDataWin32.Trojan.Vilsel.A
JiangminTrojan.Vilsel.dat
WebrootW32.Rimod.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Vilsel
XcitiumTrojWare.Win32.Vilsel.ALY@4bdezk
ArcabitTrojan.Generic.D12258
ViRobotTrojan.Win.Z.Vilsel.78092.B
ZoneAlarmTrojan.Win32.Vilsel.bpxe
MicrosoftTrojanDropper:Win32/Lamechi!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Vilsel.R490586
VBA32Trojan.Vilsel
ALYacTrojan.GenericKDZ.74328
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Vilsel.AM
TrendMicro-HouseCallTROJ_VILSEL.AI
RisingTrojan.VB!1.BE89 (CLASSIC)
YandexTrojan.GenAsa!fpIOh2aUKFk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Vilsel.aly
FortinetW32/Agent.OZA!worm
AVGWin32:VB-AEMS [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDropper:Win32/Lamechi!rfn?

TrojanDropper:Win32/Lamechi!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment