Trojan

Should I remove “Trojan:Win32/Masson.A!rfn”?

Malware Removal

The Trojan:Win32/Masson.A!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Masson.A!rfn virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Masson.A!rfn?


File Info:

crc32: 3F827E07
md5: 47bc76bee5ad092b6a1143550f3af73d
name: Dead-Space-8v1.0.0.222Enjoy.exe
sha1: 1134dd95a06dcf73acdb3bd6f0cdc8a3ddc80da4
sha256: a0bdd8b9ae77fa739e082426be0a6cb52734e343cc2cb853ff584d0becab468a
sha512: 7ad2743a591a873544a6293945e690b6d09ceade3ee760d986ddebb11b0b51fd5ffcb06c0de0f139ef0f91924df3231f285eee61b3f44f6486cc521051fe4133
ssdeep: 24576:Vo9vNwFsVbFdSGvwPg/Wb3Zh/qwQ0dZ8FmMjhcmL8Y3J01EDGLZjRGeol3kwgfb:iUsVbDRoAWb3ZqFYYAzLFMeoHgj
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

FileVersion: 1.0.0.428
ProductVersion: 1.0.0.0
Translation: 0x0419 0x04e3

Trojan:Win32/Masson.A!rfn also known as:

MicroWorld-eScanGen:Variant.Strictor.198829
CAT-QuickHealTrojan.Agent
McAfeeArtemis!47BC76BEE5AD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.Strictor.1!c
BitDefenderGen:Variant.Strictor.198829
Cybereasonmalicious.ee5ad0
Invinceaheuristic
CyrenW32/Trojan.NBWL-3188
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.EFQ potentially unsafe
APEXMalicious
AlibabaHackTool:Win32/Generic.acb54b20
RisingTrojan.Azden!8.F0E3 (CLOUD)
Ad-AwareGen:Variant.Strictor.198829
EmsisoftGen:Variant.Strictor.198829 (B)
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.tc
FortinetW32/GameHack.CWL
Trapminesuspicious.low.ml.score
FireEyeGen:Variant.Strictor.198829
SophosGeneric PUA BB (PUA)
WebrootW32.Adware.Gen
Antiy-AVLTrojan/Win32.Azden
Endgamemalicious (moderate confidence)
ArcabitTrojan.Strictor.D308AD
SUPERAntiSpywareAdware.Jacard/Variant
MicrosoftTrojan:Win32/Masson.A!rfn
AhnLab-V3Malware/Win32.Generic.C3284957
Acronissuspicious
ALYacGen:Variant.Strictor.198829
VBA32TScope.Trojan.Delf
TrendMicro-HouseCallTROJ_GEN.R014H0CB820
GDataGen:Variant.Strictor.198829
MaxSecureTrojan.Malware.74292079.susgen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan:Win32/Masson.A!rfn?

Trojan:Win32/Masson.A!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment