Trojan

Trojan:MSIL/DownPast!rfn removal tips

Malware Removal

The Trojan:MSIL/DownPast!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/DownPast!rfn virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/DownPast!rfn?


File Info:

name: F1A3682B6BBB72984EB3.mlw
path: /opt/CAPEv2/storage/binaries/1132fa68e50793893d0ce4d67f958444f9fc8446670f1cdb63ec3517db00196f
crc32: 0507FEFC
md5: f1a3682b6bbb72984eb30332a344fec1
sha1: 5ed5581c674b0dd64286a85dd0caa9c91ce8d203
sha256: 1132fa68e50793893d0ce4d67f958444f9fc8446670f1cdb63ec3517db00196f
sha512: 11e58fa3db81606a980314bdb800058f97093732eab1472e3d152b255c7d9741c709dae0f33a689fce8633a2035090faccda36ce9c476275397a71619ec3c27e
ssdeep: 96:s4KKKKKKKKK2Fe9aZLkNQs8USC8rwFygbfAz+Zxxqaa9ozNt:eswcUSLrKf+exqv9q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155F10D0FB399F932E85D0AF4885F0F303365AA5B081E6FDD14C920761BDEE850595AEB
sha3_384: 1f99adc53de6fa7526c8677c2dba218ad4ea0a07807e5cdb74d5b944ac3e9ec3df355f88d46ada52c0cd57514cfe1444
ep_bytes: ff250020400000000000000000000000
timestamp: 2082-04-22 00:33:24

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ConsoleApp1
FileVersion: 1.0.0.0
InternalName: ConsoleApp1.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: ConsoleApp1.exe
ProductName: ConsoleApp1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/DownPast!rfn also known as:

BkavW32.AIDetectMalware
LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Pafin.4
FireEyeGen:Variant.Pafin.4
ALYacGen:Variant.Pafin.4
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Pafin.4
SangforBackdoor.Msil.Bladabindi.Vuk4
K7AntiVirusTrojan ( 700000121 )
AlibabaBackdoor:MSIL/Bladabindi.612f262e
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZemsilF.36250.am0@aGdNflk
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.FXS
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Pafin.4
NANO-AntivirusTrojan.Win32.Bladabindi.hpikim
AvastWin32:KeyloggerX-gen [Trj]
TencentMsil.Trojan-Downloader.Ader.Hjgl
EmsisoftGen:Variant.Pafin.4 (B)
F-SecureHeuristic.HEUR/AGEN.1313749
DrWebTrojan.DownloaderNET.60
ZillyaDownloader.Agent.Win32.414556
McAfee-GW-EditionGenericRXJH-WA!F1A3682B6BBB
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Pafin.4
GoogleDetected
AviraHEUR/AGEN.1313749
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi
ArcabitTrojan.Pafin.4
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
MicrosoftTrojan:MSIL/DownPast!rfn
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C3487556
Acronissuspicious
McAfeeGenericRXJH-WA!F1A3682B6BBB
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL2:QiQgBZe6Xo2SBMU7DQll8Q)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.STK!tr
AVGWin32:KeyloggerX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/DownPast!rfn?

Trojan:MSIL/DownPast!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment