Trojan

How to remove “Trojan:Win32/Asacky!rfn”?

Malware Removal

The Trojan:Win32/Asacky!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Asacky!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

cmps.58sky.com
cfg.jipinwan.com
bk.957wan.com
dld.jxwan.com

How to determine Trojan:Win32/Asacky!rfn?


File Info:

crc32: 17B82EC9
md5: 98b75095f1b7b733cb766a44676544e7
name: 98B75095F1B7B733CB766A44676544E7.mlw
sha1: ee104288cfc90d253286ed55af80522dc06af51d
sha256: de898dcd12dddb98ae613681eefd07e8ccc23929d01e02cf44f7ae5547781d54
sha512: 583dfff890dee97afc0fda43664af72a4e6e1f9ca8509a13d5694094fc11c399d32572e3af5ce4a904cc18ca845cba64a9ab2d4bcf684a79b05784ad56b08e33
ssdeep: 3072:7n+ozxWqPMlzDYPf80gmQf4FtoquaWnQK9sx0:NWqefJmQf4FJu9nF9sx0
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Trojan:Win32/Asacky!rfn also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.64585
FireEyeGeneric.mg.98b75095f1b7b733
McAfeeArtemis!98B75095F1B7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Reconyc.4!c
SangforMalware
K7AntiVirusTrojan ( 004f34121 )
BitDefenderGen:Variant.Barys.64585
K7GWTrojan ( 004f34121 )
Cybereasonmalicious.5f1b7b
BitDefenderThetaAI:Packer.38F4490918
CyrenW32/NewMalware-LSU-based!Maximu
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.TJJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Reconyc.hrbi
AlibabaTrojanDropper:Win32/Reconyc.47abcdaf
NANO-AntivirusTrojan.Win32.Reconyc.elndla
TencentMalware.Win32.Gencirc.10b36378
Ad-AwareGen:Variant.Barys.64585
SophosMal/Generic-S
ComodoTrojWare.Win32.Asacky.A@7xkh2s
DrWebTrojan.DownLoader23.53713
ZillyaTrojan.Reconyc.Win32.19135
TrendMicroTrojan.Win32.JACARD.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Barys.64585 (B)
IkarusTrojan.Win32.Regrun
JiangminTrojan.Reconyc.gbu
AviraTR/Dldr.Delphi.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Dropper]/Win32.Delf
KingsoftWin32.Troj.Reconyc.hr.(kcloud)
MicrosoftTrojan:Win32/Asacky!rfn
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Barys.DFC49
AhnLab-V3Trojan/Win32.Reconyc.C1766661
ZoneAlarmTrojan.Win32.Reconyc.hrbi
GDataGen:Variant.Barys.64585
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Reconyc
ALYacGen:Variant.Barys.64585
MalwarebytesMalware.AI.419090450
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.JACARD.SM
RisingTrojan.Delf!1.BA65 (CLOUD)
YandexTrojan.GenAsa!NADEeiVshPI
SentinelOneStatic AI – Malicious PE
FortinetW32/Delf.TJJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.62a

How to remove Trojan:Win32/Asacky!rfn?

Trojan:Win32/Asacky!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment