Trojan

Trojan:Win32/Persistence!rfn removal instruction

Malware Removal

The Trojan:Win32/Persistence!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Persistence!rfn virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

api.xp666.com
download.xp666.com

How to determine Trojan:Win32/Persistence!rfn?


File Info:

crc32: F7888839
md5: 23953fd6b89ac243be1de6bd2fa36910
name: ultrarecallprodt_6031.exe
sha1: 50e6188c419f2caf1e6649ddfc1cbeb33477d996
sha256: 5e5c47f5099439b0e177131282729637ddd6584d0d801413a00946bdb547c2bb
sha512: 9fe73f58ea748352440d0ce6e3f82f0d99c46a8ada7447c670ecda14acffa566b65da1badd5e18bd29517c16aa1177204ef2e631fdde5885673e7188c3d93a35
ssdeep: 24576:FRrOHojPSC1UjGxBTqZKgH9mwUcInBzpbrvga8dvA9T:FRrOHCPSC6jfKWGhpbudK
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
FileVersion: 3.9.0.234
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.9.0.210
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownload.exe
Translation: 0x0804 0x03a8

Trojan:Win32/Persistence!rfn also known as:

MicroWorld-eScanGen:Variant.Strictor.241869
FireEyeGen:Variant.Jacard.166143
McAfeeArtemis!23953FD6B89A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055e4261 )
BitDefenderGen:Variant.Strictor.241869
K7GWTrojan ( 0055e4261 )
Cybereasonmalicious.c419f2
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Strictor.241869
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Duote.hfdnox
RisingTrojan.Duote!8.11613 (TFE:5:c8rucJpw7uG)
Ad-AwareGen:Variant.Strictor.241869
SophosMal/Generic-S
F-SecureTrojan.TR/RedCap.ehpln
ZillyaTrojan.Duote.Win32.83
TrendMicroTROJ_GEN.R002C0DCO20
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Strictor.241869 (B)
IkarusTrojan.Win32.Duote
CyrenW32/Trojan.VFLL-9036
JiangminTrojan.Agentb.glb
WebrootW32.Adware.Gen
AviraTR/RedCap.ehpln
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ArcabitTrojan.Strictor.D3B0CD
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Persistence!rfn
ALYacGen:Variant.Jacard.166143
MAXmalware (ai score=99)
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Duote.A
TrendMicro-HouseCallTROJ_GEN.R002C0DCO20
TencentWin32.Trojan.Strictor.Hqlp
YandexTrojan.Duote!
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Doute.A!tr
BitDefenderThetaGen:NN.ZelphiF.34100.cnKfaaDaMkji
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Trojan:Win32/Persistence!rfn?

Trojan:Win32/Persistence!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment