Worm

Worm:Win32/Goldrv!rfn removal tips

Malware Removal

The Worm:Win32/Goldrv!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Goldrv!rfn virus can do?

  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm:Win32/Goldrv!rfn?


File Info:

crc32: 14FA8B5B
md5: 194ca196f65dbbec9fe99f603bbb5fdf
name: 194CA196F65DBBEC9FE99F603BBB5FDF.mlw
sha1: 19f36d462a3bfefa0cb7736c9fee126b506578d1
sha256: c69546dca49516d9fd088d9cacf897aafc6774c727d3c7059f670db50f27491b
sha512: a8e16ff0aa19d6b86597e99a99a4431c7677b46fb2fd5c1087c0973f438f8e64e25b2f757dd3cd54406e5c464a2b735288c6e23475af2c36df77c3b8a527a903
ssdeep: 768:uBD3mjGRH0pZU9nzSHO+wdUuO8Hvmcrs3i6E5nXfUWPYfIc/Qi3qEBQp:MK6RHMU9Qy1O8ecQ3i6EBXlLOUp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Goldrv!rfn also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.8575
ClamAVWin.Trojan.Ransom-9179
ALYacGen:Variant.Graftor.173664
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.19256
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Blocker.5fd5b1d6
K7GWTrojan ( 000b03011 )
K7AntiVirusTrojan ( 000b03011 )
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Agent.NPN
ZonerTrojan.Win32.87169
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.jboe
BitDefenderGen:Variant.Graftor.173664
NANO-AntivirusTrojan.Win32.Blocker.dgyxih
ViRobotTrojan.Win32.Agent.81408.AH
MicroWorld-eScanGen:Variant.Graftor.173664
TencentTrojan-ransom.Win32.Blocker.endf
Ad-AwareGen:Variant.Graftor.173664
SophosMal/Generic-S
ComodoTrojWare.Win32.Dapato.DFS@5hy5o0
F-SecureWorm.WORM/Agent.rxdas
BitDefenderThetaGen:NN.ZexaF.34058.duW@aWiOjYn
McAfee-GW-EditionBehavesLike.Win32.Generic.qm
FireEyeGeneric.mg.194ca196f65dbbec
EmsisoftGen:Variant.Graftor.173664 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.kkb
AviraWORM/Agent.rxdas
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftWorm:Win32/Goldrv!rfn
ArcabitTrojan.Graftor.D2A660
ZoneAlarmTrojan-Ransom.Win32.Blocker.jboe
GDataGen:Variant.Graftor.173664
TACHYONTrojan/W32.Blocker.55296.I
AhnLab-V3Trojan/Win32.Backdoor.R121743
McAfeeGenericRXAA-FA!194CA196F65D
MAXmalware (ai score=99)
MalwarebytesMalware.AI.1065446175
PandaTrj/CI.A
RisingTrojan.Generic@ML.80 (RDML:L1jQjb+RvkouQBNEC8VMhA)
YandexTrojan.Blocker!HAeFdN2YQOs
IkarusTrojan-Ransom.CryptoWall
MaxSecureTrojan.Malware.7097212.susgen
FortinetW32/Generic.AC.17E73!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwoCEpsA

How to remove Worm:Win32/Goldrv!rfn?

Worm:Win32/Goldrv!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment