Trojan

Should I remove “Trojan:Win32/Autorun!rfn”?

Malware Removal

The Trojan:Win32/Autorun!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Autorun!rfn virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Autorun!rfn?


File Info:

crc32: 08075D65
md5: e02a33f56067937fc276f86418696f98
name: E02A33F56067937FC276F86418696F98.mlw
sha1: 807fe56b421ad3e13ccc7a1c523a65a6bfba5cfe
sha256: 4d304a8cac44e5d216d8d011a5ab4a7c4f6f28a944a3f121d731c4dfa47f5c88
sha512: 394523e2d686c31f04c50a8d1189ef2b5fb9455ea1eb8ec9df9a8081ba11dbbe039a61c82bed10c76d84965e8ecda15536979ac3c3e3a8cb4cc6d3e9c7df6832
ssdeep: 6144:MO/DVuhywMptQmZp2Dy/CA02HsQ2S1Zj93cDIjMBo:b/DohTMSe/CA04+4Zhw6
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: xffa9 Microsoft Corporation. All rights reserved.
InternalName: CLIPSRV.EXE
FileVersion: 5.1.2600.5512
CompanyName: Microsoft Corporation
PrivateBuild: CLIPSRV.EXE
LegalTrademarks: xffa9 Microsoft Corporation. All rights reserved.
Comments:
ProductName: Microsoftxffae Windowsxffae Operating System
SpecialBuild: 5.1.2600.5512
ProductVersion: 5.1.2600.5512
FileDescription: Windows NT DDE Server
OriginalFilename: CLIPSRV.EXE
Translation: 0x0409 0x04b0

Trojan:Win32/Autorun!rfn also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Graftor.742988
FireEyeGeneric.mg.e02a33f56067937f
McAfeeDownloader-FIK!E02A33F56067
CylanceUnsafe
VIPRETrojan.Win32.Small.bhm (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003e826e1 )
BitDefenderGen:Variant.Graftor.742988
K7GWTrojan ( 003e826e1 )
Cybereasonmalicious.560679
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Rodecap-F [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.bvxm
NANO-AntivirusTrojan.Win32.Blocker.chwsks
Ad-AwareGen:Variant.Graftor.742988
EmsisoftGen:Variant.Graftor.742988 (B)
F-SecureTrojan.TR/Small.bhoumb
DrWebTrojan.DownLoader9.44777
ZillyaTrojan.Rodecap.Win32.1732
TrendMicroTROJ_RODECAP.SMO
McAfee-GW-EditionBehavesLike.Win32.PUPXAX.fm
SophosMal/Generic-R + Mal/Qbot-P
IkarusTrojan.Win32.Small
JiangminTrojan.Blocker.pbu
AviraTR/Small.bhoumb
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
MicrosoftTrojan:Win32/Autorun!rfn
ArcabitTrojan.Graftor.DB564C
ZoneAlarmTrojan-Ransom.Win32.Blocker.bvxm
GDataGen:Variant.Graftor.742988
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.C2717007
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.yu0@aK67nmoi
ALYacGen:Variant.Graftor.742988
VBA32TrojanRansom.Blocker
MalwarebytesMalware.AI.1509252815
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Rodecap.BB
TrendMicro-HouseCallTROJ_RODECAP.SMO
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!6KhuQuHc76g
SentinelOneStatic AI – Malicious PE
FortinetW32/Rodecap.BB!tr
AVGWin32:Rodecap-F [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.f7c

How to remove Trojan:Win32/Autorun!rfn?

Trojan:Win32/Autorun!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment