Trojan

Trojan:Win32/Provis!rfn removal guide

Malware Removal

The Trojan:Win32/Provis!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Provis!rfn virus can do?

  • Executable code extraction
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Provis!rfn?


File Info:

crc32: A969924C
md5: 4cd9a6beb7518db6d801971d3b709ce9
name: 4CD9A6BEB7518DB6D801971D3B709CE9.mlw
sha1: 28f54116d2464df3201727e6ad4fb70870c62680
sha256: 9b12d412d2bf8611e67d1560cc889da6bb1f8f946ab9d38584f3a7a887a5c8b9
sha512: 5fb889710fcc5d9d8f069de907db3e1e28cf6562bf9475088e5f4051bacf711381650531d4759afa32766ffcab2442245e745f6e13841f51521d742cb61f55a8
ssdeep: 12288:hBGIkryOrtRyWjHWGkSHCO5ZkqseNlr8KjeQFBwhN3VEkNw5MG5KVoSGeF:+rtRy4HWPSiWZvxjeQFBwjVEkNkMG5U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: x79bbx4e0dx5f00x7535x8111(Creep)
InternalName: SET_AHK
FileVersion: 1.01.0002
CompanyName: 56q.5d6d.com
Comments: x8fdex53d1x8bbex7f6ex751fx6210x5de5x5177(DNF-AHK)
ProductName: x8fdex53d1x8bbex7f6ex751fx6210x5de5x5177(DNF-AHK)
ProductVersion: 1.01.0002
FileDescription: x8fdex53d1x8bbex7f6ex751fx6210x5de5x5177(DNF-AHK)
OriginalFilename: SET_AHK.exe

Trojan:Win32/Provis!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003d23081 )
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.453
CylanceUnsafe
ZillyaTrojan.VB.Win32.31375
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaHackTool:Win32/vbpws.683b5af3
K7GWTrojan ( 003d23081 )
Cybereasonmalicious.6d2464
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GameHack.AZ potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-1127879
NANO-AntivirusTrojan.Win32.VB.fiazgj
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.USEGB28
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.4cd9a6beb7518db6
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.49D926
MicrosoftTrojan:Win32/Provis!rfn
GridinsoftTrojan.Win32.Agent.dg
AegisLabTrojan.Win32.Generic.4!c
McAfeeGeneric.bob
MAXmalware (ai score=99)
VBA32MAS.Trojan.VB.0857
PandaAdware/AccesMembre
TrendMicro-HouseCallTROJ_GEN.USEGB28
RisingTrojan.Provis!8.A8E (CLOUD)
YandexTrojan.GenAsa!ICvkO8jquGc
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Malware-gen

How to remove Trojan:Win32/Provis!rfn?

Trojan:Win32/Provis!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment