Trojan

Trojan:Win32/BlaXeno!rfn removal instruction

Malware Removal

The Trojan:Win32/BlaXeno!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BlaXeno!rfn virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/BlaXeno!rfn?


File Info:

crc32: 83B74A4F
md5: 216c3eae24901482bfd26cb9dca1a833
name: 216C3EAE24901482BFD26CB9DCA1A833.mlw
sha1: f6000cc06cbc9f0e748b81cfac77eb2598f71e69
sha256: 8bdb3ce10dee7a3249a186050d7f804bca19859f292ddad7ae8c5afbb649a07b
sha512: 74cf449facf674c6cb6b5831830a598038ae09bc088da8af894fe79462b48ad02222a2d931233f731187c163c7629a920488efdd1f58692c4f3c9a64d1497a17
ssdeep: 24576:gwTJ6A1eP1Pm9zhTaUe0K9XXVYFEjd6/Gr+AK9hhEfSVgPCS3tMrMyj3F9hIF1S:r5ra0K9ndjd6/GXKvhISVE3tMx3FE1S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: Xenos.exe
FileVersion: 2.3.2.0
ProductName: Xenos
ProductVersion: 2.3.2.0
FileDescription: PE injector
OriginalFilename: Xenos.exe
Translation: 0x0400 0x04b0

Trojan:Win32/BlaXeno!rfn also known as:

BkavW32.AIDetectVM.malware2
K7AntiVirusUnwanted-Program ( 0052a82c1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.35817671
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1446784
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Kryptik.8b9a03f3
K7GWUnwanted-Program ( 0052a82c1 )
Cybereasonmalicious.e24901
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GAMH
APEXMalicious
AvastWin64:PUP-gen [PUP]
ClamAVWin.Packed.Detrahere-9761040-0
BitDefenderTrojan.GenericKD.35817671
NANO-AntivirusTrojan.Win32.Kryptik.fdyghi
SUPERAntiSpywareTrojan.Agent/Gen-PasswordStealer
MicroWorld-eScanTrojan.GenericKD.35817671
TencentMalware.Win32.Gencirc.11696b73
Ad-AwareTrojan.GenericKD.35817671
SophosMal/Generic-S
ComodoMalware@#1j01p5az8o0s8
F-SecureTrojan.TR/Crypt.Agent.pgzjb
BitDefenderThetaGen:NN.ZexaF.34760.hr0@a8oln0mO
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DJV20
McAfee-GW-EditionGenericRXFR-EM!216C3EAE2490
FireEyeGeneric.mg.216c3eae24901482
EmsisoftTrojan.GenericKD.35817671 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Agent.Gen
AviraTR/Crypt.Agent.pgzjb
Antiy-AVLTrojan/Win64.Detrahere
MicrosoftTrojan:Win32/BlaXeno!rfn
ArcabitTrojan.Generic.D22288C7
AegisLabTrojan.Win32.Malicious.4!c
GDataTrojan.GenericKD.35817671
McAfeeGenericRXFR-EM!216C3EAE2490
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DJV20
RisingHackTool.BlackBone!1.CF94 (CLASSIC)
YandexTrojan.Igent.bUUPtI.20
IkarusTrojan.Detrahere
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GAMH!tr
AVGWin64:PUP-gen [PUP]
Paloaltogeneric.ml
Qihoo-360Win32/Application.558

How to remove Trojan:Win32/BlaXeno!rfn?

Trojan:Win32/BlaXeno!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment