Backdoor

Backdoor:Win32/Predator.J!MTB information

Malware Removal

The Backdoor:Win32/Predator.J!MTB file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Backdoor:Win32/Predator.J!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovak
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Predator.J!MTB?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Malicious

File Info:

Name: starticon0.exe

Size: 808448

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 307c5b34037919495eb43810e867c16a

SHA1: 479ee357e4ea9430df252430a310f92d22e2a0a9

SH256: c84f1d6b8acb9807baf2a16dd480f64b307ade9b57b7a2d387a033e85cf5d83e

Version Info:

[No Data]

Backdoor:Win32/Predator.J!MTB also known as:

ALYacTrojan.GenericKD.32662699
APEXMalicious
AVGFileRepMetagen [Malware]
Acronissuspicious
Ad-AwareTrojan.GenericKD.32662699
AegisLabTrojan.Win32.Bandit.tqTK
AhnLab-V3Trojan/Win32.MalPe.R296515
AlibabaTrojan:Win32/Chapak.ccacd75d
Antiy-AVLTrojan[Backdoor]/Win32.Predator
ArcabitTrojan.Generic.D1F264AB
AvastFileRepMetagen [Malware]
AviraTR/AD.VidarStealer.cauu
BitDefenderTrojan.GenericKD.32662699
BitDefenderThetaGen:Trojan.Heur2.PPBB.3.0.XC0@c0oL48kG7d
CAT-QuickHealRansom.Stop.MP4
ClamAVWin.Packed.Generickdz-7357865-0
ComodoMalware@#109srza2n2cvr
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.7e4ea9
CylanceUnsafe
CyrenW32/Kryptik.ANT.gen!Eldorado
DrWebTrojan.PWS.Stealer.27284
ESET-NOD32a variant of Win32/Kryptik.GXTK
EmsisoftTrojan.GenericKD.32662699 (B)
Endgamemalicious (high confidence)
F-ProtW32/Kryptik.ANT.gen!Eldorado
F-SecureTrojan.TR/AD.VidarStealer.cauu
FireEyeGeneric.mg.307c5b3403791949
FortinetW32/GenKryptik.DWPH!tr
GDataTrojan.GenericKD.32662699
IkarusTrojan.Win32.Crypt
Invinceaheuristic
JiangminAdWare.Generic.jyiy
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyTrojan.Win32.Chapak.ebqm
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.GS
McAfeeRDN/Generic BackDoor
McAfee-GW-EditionRDN/Generic BackDoor
MicroWorld-eScanTrojan.GenericKD.32662699
MicrosoftBackdoor:Win32/Predator.J!MTB
Paloaltogeneric.ml
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.63c
RisingTrojan.Kryptik!1.BE9F (CLASSIC)
SentinelOneDFI – Suspicious PE
SophosMal/Generic-S
SymantecTrojan Horse
TrendMicroTROJ_FRS.VSNW1FJ19
TrendMicro-HouseCallTROJ_FRS.VSNW1FJ19
VBA32TrojanDropper.Agent
VIPRETrojan.Win32.Generic!BT
ViRobotTrojan.Win32.S.Agent.808448.A
WebrootW32.Trojan.Gen
ZillyaTrojan.Chapak.Win32.84672
ZoneAlarmTrojan.Win32.Chapak.ebqm

How to remove Backdoor:Win32/Predator.J!MTB?

Backdoor:Win32/Predator.J!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment