Categories: Backdoor

Backdoor:Win32/Predator.J!MTB information

The Backdoor:Win32/Predator.J!MTB file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Backdoor:Win32/Predator.J!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovak
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Predator.J!MTB?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Malicious

File Info:

Name: starticon0.exe

Size: 808448

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 307c5b34037919495eb43810e867c16a

SHA1: 479ee357e4ea9430df252430a310f92d22e2a0a9

SH256: c84f1d6b8acb9807baf2a16dd480f64b307ade9b57b7a2d387a033e85cf5d83e

Version Info:

[No Data]

Backdoor:Win32/Predator.J!MTB also known as:

ALYac Trojan.GenericKD.32662699
APEX Malicious
AVG FileRepMetagen [Malware]
Acronis suspicious
Ad-Aware Trojan.GenericKD.32662699
AegisLab Trojan.Win32.Bandit.tqTK
AhnLab-V3 Trojan/Win32.MalPe.R296515
Alibaba Trojan:Win32/Chapak.ccacd75d
Antiy-AVL Trojan[Backdoor]/Win32.Predator
Arcabit Trojan.Generic.D1F264AB
Avast FileRepMetagen [Malware]
Avira TR/AD.VidarStealer.cauu
BitDefender Trojan.GenericKD.32662699
BitDefenderTheta Gen:Trojan.Heur2.PPBB.3.0.XC0@c0oL48kG7d
CAT-QuickHeal Ransom.Stop.MP4
ClamAV Win.Packed.Generickdz-7357865-0
Comodo Malware@#109srza2n2cvr
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.7e4ea9
Cylance Unsafe
Cyren W32/Kryptik.ANT.gen!Eldorado
DrWeb Trojan.PWS.Stealer.27284
ESET-NOD32 a variant of Win32/Kryptik.GXTK
Emsisoft Trojan.GenericKD.32662699 (B)
Endgame malicious (high confidence)
F-Prot W32/Kryptik.ANT.gen!Eldorado
F-Secure Trojan.TR/AD.VidarStealer.cauu
FireEye Generic.mg.307c5b3403791949
Fortinet W32/GenKryptik.DWPH!tr
GData Trojan.GenericKD.32662699
Ikarus Trojan.Win32.Crypt
Invincea heuristic
Jiangmin AdWare.Generic.jyiy
K7AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky Trojan.Win32.Chapak.ebqm
MAX malware (ai score=80)
Malwarebytes Trojan.MalPack.GS
McAfee RDN/Generic BackDoor
McAfee-GW-Edition RDN/Generic BackDoor
MicroWorld-eScan Trojan.GenericKD.32662699
Microsoft Backdoor:Win32/Predator.J!MTB
Paloalto generic.ml
Panda Trj/GdSda.A
Qihoo-360 Win32/Trojan.63c
Rising Trojan.Kryptik!1.BE9F (CLASSIC)
SentinelOne DFI – Suspicious PE
Sophos Mal/Generic-S
Symantec Trojan Horse
TrendMicro TROJ_FRS.VSNW1FJ19
TrendMicro-HouseCall TROJ_FRS.VSNW1FJ19
VBA32 TrojanDropper.Agent
VIPRE Trojan.Win32.Generic!BT
ViRobot Trojan.Win32.S.Agent.808448.A
Webroot W32.Trojan.Gen
Zillya Trojan.Chapak.Win32.84672
ZoneAlarm Trojan.Win32.Chapak.ebqm

How to remove Backdoor:Win32/Predator.J!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “TrojanDownloader:Win32/Beebone.IR”?

The TrojanDownloader:Win32/Beebone.IR is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

How to remove “Malware.AI.3856697558”?

The Malware.AI.3856697558 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

BrowseFox.Adware.AdInjector.DDS information

The BrowseFox.Adware.AdInjector.DDS is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

Win32:AutoRun-BSW [Wrm] malicious file

The Win32:AutoRun-BSW [Wrm] is considered dangerous by lots of security experts. When this infection is…

1 hour ago

About “MSIL/TrojanDownloader.Agent.QQN” infection

The MSIL/TrojanDownloader.Agent.QQN is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.975225574 removal

The Malware.AI.975225574 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago