Trojan

Should I remove “Trojan:Win32/Execution!rfn”?

Malware Removal

The Trojan:Win32/Execution!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Execution!rfn virus can do?

  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.aitlsbh.com

How to determine Trojan:Win32/Execution!rfn?


File Info:

crc32: E82F6418
md5: 225a2c3e9e109f805666c14da6dff25b
name: localsys.exe
sha1: d4e4afee934fc81dc0c2d55c5eca2c9b22962f6f
sha256: bef81d8f97edc536ac311b2808788ed5633b30ae0eb003279461925b94f962a3
sha512: 3f292d929926222530cd276df4a358924aedaffb961f3c1001a1067e7ce74655608dfa8873bb027a52c71322b34c7a0b69a08b8e5ea7254669a0115de000c04a
ssdeep: 24576:iYS9jYsaVvPxWDLBm5aG8AldY8ONQZt/FwEN2SIKIcbBon+Ku7y:zAugBmaAlbiIOkIcbmn+/7y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Execution!rfn also known as:

MicroWorld-eScanGen:Variant.Ulise.101741
FireEyeGeneric.mg.225a2c3e9e109f80
McAfeeGenericRXAA-AA!225A2C3E9E10
ALYacGen:Variant.Ulise.101741
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 004e008d1 )
BitDefenderGen:Variant.Ulise.101741
K7GWRiskware ( 004e008d1 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTROJ_GEN.R015C0WC220
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Ulise.101741
KasperskyHEUR:Trojan-PSW.Win32.Mimikatz.gen
AlibabaRiskWare:Win32/Mimikatz.71ae91cf
NANO-AntivirusTrojan.Win32.Mimikatz.hdfcco
ViRobotTrojan.Win32.Z.Razy.1161216.A
AegisLabTrojan.Win32.Mimikatz.i!c
RisingMalware.Strealer!8.1EF (TFE:5:Sv3gb4pbLsT)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.101741 (B)
ComodoMalware@#cs3zeib7y13b
DrWebTrojan.DownLoader33.7948
ZillyaTool.Mimikatz.Win32.1450
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
MaxSecureTrojan.Malware.9460437.susgen
Trapminemalicious.high.ml.score
SophosMal/Generic-S
CyrenW32/Trojan.DIOM-5996
JiangminTrojan.Chapak.zj
MAXmalware (ai score=99)
Antiy-AVLTrojan[PSW]/Win32.Mimikatz
ArcabitRiskware.Generic
ZoneAlarmHEUR:Trojan-PSW.Win32.Mimikatz.gen
MicrosoftTrojan:Win32/Execution!rfn
AhnLab-V3Trojan/Win32.Mimikatz.C4003767
Acronissuspicious
VBA32TrojanPSW.Mimikatz
Ad-AwareGen:Variant.Ulise.101741
MalwarebytesRiskWare.Mimikatz
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/RiskWare.Mimikatz.B
TrendMicro-HouseCallTROJ_GEN.R015C0WC220
TencentWin32.Trojan-qqpass.Qqrob.Hooo
YandexRiskWare.Mimikatz!
SentinelOneDFI – Malicious PE
eGambithacktool.mimikatz
FortinetRiskware/Mimikatz
BitDefenderThetaGen:NN.ZexaF.34098.gvW@aSDTLaai
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.e934fc
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.PSW.801

How to remove Trojan:Win32/Execution!rfn?

Trojan:Win32/Execution!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment