Trojan

Trojan:Win32/Olsa!rfn removal tips

Malware Removal

The Trojan:Win32/Olsa!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Olsa!rfn virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Olsa!rfn?


File Info:

crc32: 9320883E
md5: d12bdb084f1b6e80643a827a12cdbd60
name: D12BDB084F1B6E80643A827A12CDBD60.mlw
sha1: 09848451da3024e38c4022a02ca976132bd149d5
sha256: a4414a4fd06be37e66b82e8bce6073c710d0c7a919bb9389401b3afebcfaa87d
sha512: 365096207a4f66b80e287bda803520038d8a9e3d1606acc0457fc5f19511b7ab377b257342df5d721d3316b0ed9f976bb5bdc0a03cb3aaf6db894f6fe86d4b02
ssdeep: 24576:02F7eRbp8iVtGVcG9pV1OqVtFnSQT3Q5N:0AEbVG9BSIgz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Olsa!rfn also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Bat.Salo.A
FireEyeGeneric.mg.d12bdb084f1b6e80
CAT-QuickHealTrojan.Orsam.A4
Qihoo-360HEUR/QVM20.1.5CA1.Malware.Gen
ALYacTrojan.Bat.Salo.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004c4cd31 )
BitDefenderTrojan.Bat.Salo.A
K7GWTrojan ( 004c4cd31 )
Cybereasonmalicious.84f1b6
TrendMicroTROJ_DROPPER.QBZ
CyrenW32/Imaut.A.gen!Eldorado
SymantecTrojan.Gen.2
TotalDefenseWin32/SillyAutorun.AIL
BaiduMulti.Threats.InArchive
APEXMalicious
ClamAVWin.Trojan.Pcclient-4245
KasperskyTrojan.Script.Jobber.d
NANO-AntivirusTrojan.Win32.PcClient.dgwtmn
RisingVirus.Olsa!1.A24F (CLASSIC)
Ad-AwareDropped:Trojan.Generic.1624094
SophosTroj/Olsa-A
ComodoMalware@#nncvvfqmcjsy
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.PcClient.3131
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bc
EmsisoftTrojan.Bat.Salo.A (B)
JiangminTrojanDropper.Agent.acdm
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.DeepScan.a.(kcloud)
MicrosoftTrojan:Win32/Olsa!rfn
ArcabitTrojan.Generic.D18C81E
AhnLab-V3Dropper/PcClient.Gen
ZoneAlarmTrojan.Script.Jobber.d
GDataDropped:Trojan.Generic.1624094 (2x)
CynetMalicious (score: 100)
ESET-NOD32multiple detections
McAfeeArtemis!D12BDB084F1B
VBA32Win32.Trojan.Dropper.Heur
MalwarebytesTrojan.Dropper.SFXAI
TrendMicro-HouseCallTROJ_DROPPER.QBZ
TencentVirus.Win32.SOLA.c
YandexBackdoor.PcClient!Whun8uuq72A
IkarusTrojan.SuspectCRC
FortinetW32/PcClient.FED!tr
AVGVBS:Agent-ED [Trj]
AvastVBS:Agent-ED [Trj]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Trojan:Win32/Olsa!rfn?

Trojan:Win32/Olsa!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment