Backdoor

About “Backdoor:Win32/Predator.J!rfn” infection

Malware Removal

The Backdoor:Win32/Predator.J!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Predator.J!rfn virus can do?

  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Backdoor:Win32/Predator.J!rfn?


File Info:

crc32: 4A15CF60
md5: 99ce416a558e30839f7ed538aed66703
name: 99CE416A558E30839F7ED538AED66703.mlw
sha1: ba80a2ed977491707b4a98734ed1f84d3109a4f0
sha256: db2124cd7c6ff1a01a3d3c3fd026de2dd0e3e9d54ae7f45d41a1c86f58a57832
sha512: 209e2347960bbfa3ed7f986ca9c95ccc0b8047a8c418957aefc769b7836ef837964f2637b36fd05f7f34ff1708e8c11090bc6f23911ab233fba94a1be6e4ec1e
ssdeep: 12288:BpBDWAGR27dzcJgtE8LsZ6pVVttZ8Ea0+4zIr:BpBDrOMdvtE8LsirvZ8M+4zI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Predator.J!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00548ab11 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S5505789
ALYacGen:Variant.Ransom.1908
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Crysis.60e023cc
K7GWTrojan ( 00548ab11 )
Cybereasonmalicious.a558e3
CyrenW32/S-a0f476a0!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GQCY
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.addsub-6961201-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.1908
NANO-AntivirusTrojan.Win32.Kryptik.fnuxah
ViRobotTrojan.Win32.GandCrab.Gen.B
MicroWorld-eScanGen:Variant.Ransom.1908
TencentWin32.Trojan.Generic.Hwmw
Ad-AwareGen:Variant.Ransom.1908
ComodoTrojWare.Win32.Ransom.GrandCrypt.GQ@831jic
BitDefenderThetaGen:NN.ZexaF.34770.FmGfaG5opvmG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.99ce416a558e3083
EmsisoftGen:Variant.Ransom.1908 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Propagate.zg
AviraHEUR/AGEN.1109190
Antiy-AVLTrojan/Generic.ASMalwS.2ACF370
MicrosoftBackdoor:Win32/Predator.J!rfn
GDataGen:Variant.Ransom.1908
AhnLab-V3Trojan/Win32.Gandcrab.C3044577
Acronissuspicious
McAfeeArtemis!99CE416A558E
MAXmalware (ai score=83)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B5FD (CLASSIC)
YandexTrojan.GenAsa!5ZlhAKNIXxw
IkarusTrojan-PSW.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.HHUN!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.CrySiS.HwsBEpsA

How to remove Backdoor:Win32/Predator.J!rfn?

Backdoor:Win32/Predator.J!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment