Backdoor

What is “Backdoor:Win32/Bedep!rfn”?

Malware Removal

The Backdoor:Win32/Bedep!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bedep!rfn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Bedep!rfn?


File Info:

name: 6FFEBC0D33231051182C.mlw
path: /opt/CAPEv2/storage/binaries/fc861c0f59db085400d4337f5b20b36c6f88a28c3703a1caeb319d34cb4d75da
crc32: 862F6D2E
md5: 6ffebc0d33231051182c95b27e9eb9e4
sha1: 6357116ee744b08561d5162f6a255a33b1a481ba
sha256: fc861c0f59db085400d4337f5b20b36c6f88a28c3703a1caeb319d34cb4d75da
sha512: 3bec0b6e8d5f678492a5d3696c08e747a942ebadc5e6c48b9df48cd4fcf5ea8ae14668f6be9322ee45eb107cbf083dfc5fa961d404e865080735a9e9999cb313
ssdeep: 6144:9K6TGzkUdWU0YVBZ0+iCxxS5NRlKda+OtdGC3trJiSGF3:HTtT8r0bfCs+OrGC3znGB
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T18D64355AAE46C97DC0F9963EC4C613B976207408C9C15FDAF35BAA0908716E82D73B4F
sha3_384: 6107fc33f5cd325e8f7fe83d1f886e2c131186a6f0dd0622520ebe902355744afcd03c73597f52b9e35ffed77cce19bf
ep_bytes: e88df9ffffe95f040000e85328000077
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Jet Expression Service
FileVersion: 4.00.9756.0
InternalName: MSJTES40
LegalCopyright: Copyright (C) Microsoft Corp. 1997-1999
OriginalFilename: MSJTES40.DLL
ProductName: Microsoft (R) Jet
ProductVersion: 4.00.9756.0
Translation: 0x0000 0x04b0

Backdoor:Win32/Bedep!rfn also known as:

LionicTrojan.Win32.Bedep.mE1F
tehtrisGeneric.Malware
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Packed.fc
McAfeeBackDoor-FCZO!6FFEBC0D3323
Cylanceunsafe
SangforTrojan.Win32.Kryptik.Vjhh
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Kryptik.cd2fce68
K7GWTrojan ( 0055dd191 )
K7AntiVirusTrojan ( 0055dd191 )
ArcabitTrojan.Mikey.D1B9A6
BitDefenderThetaAI:Packer.40EA9D7D26
VirITTrojan.Win32.Atros2.BDUU
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.EETT
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mikey.113062
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Mikey.113062
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114db02e
EmsisoftGen:Variant.Mikey.113062 (B)
BaiduWin32.Trojan.Kryptik.rz
F-SecureHeuristic.HEUR/AGEN.1372711
DrWebTrojan.Bedep.62
VIPREGen:Variant.Mikey.113062
FireEyeGeneric.mg.6ffebc0d33231051
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1372711
Antiy-AVLTrojan[Backdoor]/Win32.Bedep
XcitiumMalware@#176ffdrbu4xca
MicrosoftBackdoor:Win32/Bedep!rfn
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Mikey.113062
VBA32Backdoor.Bedep
ALYacGen:Variant.Mikey.113062
MAXmalware (ai score=89)
PandaGeneric Suspicious
RisingMalware.Undefined!8.C (TFE:4:YHif3dJx0SB)
YandexTrojan.GenAsa!Y2DoEII7d1c
IkarusWin32.Outbreak
FortinetW32/Kryptik.EFEC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Bedep

How to remove Backdoor:Win32/Bedep!rfn?

Backdoor:Win32/Bedep!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment