Trojan

Trojan:Win32/Malagent!rfn removal guide

Malware Removal

The Trojan:Win32/Malagent!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Malagent!rfn virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
driftek.com

How to determine Trojan:Win32/Malagent!rfn?


File Info:

crc32: 59D5D3C5
md5: 706cf2bcfc513acb0985c4b84a1d5f03
name: 706CF2BCFC513ACB0985C4B84A1D5F03.mlw
sha1: b19f2f7ea7ec4232f235584656bd78db668b7e0c
sha256: 06ffe0d16ea6c8387e7b6bfb980117d42274205c06e81a872e5e04cdc8c5abab
sha512: 61310d60d29a18104a0db03dd66ceaa974935d845793dc640888b4ca5843749fe98fd86e35cab241f3a8f0a66f2473f1a428af546ac5458e39c9290c438b174c
ssdeep: 12288:ehkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4aC2v/J:uRmJkcoQricOIQxiZY1iaC2vR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Trojan:Win32/Malagent!rfn also known as:

BkavW32.AIDetectVM.malware1
CynetMalicious (score: 100)
FireEyeGeneric.mg.706cf2bcfc513acb
McAfeeArtemis!706CF2BCFC51
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.Autoit.JEL
K7GWTrojan ( 700000111 )
Cybereasonmalicious.cfc513
BitDefenderThetaAI:Packer.CF65E5A615
CyrenW32/AutoIt.QH.gen!Eldorado
SymantecTrojan.Gen.MBT
TotalDefenseWin32/Tnega.XAHS!suspicious
APEXMalicious
AvastAutoIt:MalOb-EE [Trj]
KasperskyTrojan-Banker.Win32.AutoIt.bi
AlibabaTrojanBanker:Win32/Obfuscator.dda881a4
NANO-AntivirusTrojan.Win32.Inject.crntpc
AegisLabTrojan.Win32.Inject.4!c
MicroWorld-eScanTrojan.Autoit.JEL
Ad-AwareTrojan.Autoit.JEL
SophosMal/Generic-R + Troj/Tiotua-DY
ComodoMalware@#3084tzwdqwlns
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader10.30740
ZillyaTrojan.Agent.Win32.545384
TrendMicroTROJ_GEN.R002C0DLL20
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
EmsisoftTrojan.Autoit.JEL (B)
MaxSecureTrojan.Autoit.AZA
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
KingsoftWin32.Troj.Inject.gt.(kcloud)
MicrosoftTrojan:Win32/Malagent!rfn
ArcabitTrojan.Autoit.JEL
ZoneAlarmTrojan-Banker.Win32.AutoIt.bi
GDataTrojan.Autoit.JEL
AhnLab-V3Trojan/Win32.AutoIt.C222223
VBA32TrojanBanker.AutoIt
ALYacTrojan.Autoit.JEL
MalwarebytesMalware.AI.1814471627
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.DAA
TrendMicro-HouseCallTROJ_GEN.R002C0DLL20
TencentWin32.Trojan-banker.Autoit.Aexw
IkarusTrojan.Win32.Obfuscated
FortinetW32/Injector.KL!tr
AVGAutoIt:MalOb-EE [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM10.Gen

How to remove Trojan:Win32/Malagent!rfn?

Trojan:Win32/Malagent!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment