Backdoor

Backdoor:Win32/Predator removal

Malware Removal

The Backdoor:Win32/Predator is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Predator virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

travelups.co.ug
ip-api.com

How to determine Backdoor:Win32/Predator?


File Info:

crc32: FCEF30B3
md5: 496a8e6d036d76957305b1fa8441591a
name: 496A8E6D036D76957305B1FA8441591A.mlw
sha1: 8a2d4389ab6754bfcdc92b7df98b351079adc88f
sha256: c292f07f3962235311fbf48c6a233e457878f16760efe23e3e10337f15b80e61
sha512: a3a151c676beb60b766d62b1adc6d8c36a9f584052c5212b49509a9076393e5b94c1846f84f515a86dded6653c4d2ed5d8968073822c1c7874e46e05cb2d2b3b
ssdeep: 12288:ZICNvGdVPcaMMfKJjY2+3hAqnIvOux+SR9UrAzFcsAOY24:+QGd5caMMyO3hAqIGuUSR9MAOW
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2017, zeyuxot
FileVersion: 8.10.4.46
ProductVersion: 8.10.4.46
Translation: 0x0399 0x04b0

Backdoor:Win32/Predator also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005475d91 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop9.7522
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.53749
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirTool:Win32/CeeInject.8cad576e
K7GWTrojan ( 005475d91 )
Cybereasonmalicious.d036d7
CyrenW32/GandCrab.AG.gen!Eldorado
SymantecInfostealer.Rultazo
ESET-NOD32a variant of Win32/Kryptik.GPOC
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.53749
NANO-AntivirusTrojan.Win32.Kryptik.fmtapf
ViRobotTrojan.Win32.GandCrab.Gen.B
MicroWorld-eScanTrojan.GenericKDZ.53749
TencentMalware.Win32.Gencirc.114d9803
Ad-AwareTrojan.GenericKDZ.53749
SophosMal/Generic-S + Mal/GandCrab-G
ComodoMalware@#2nf5us5uhie5m
BitDefenderThetaGen:NN.ZexaF.34770.EmKfa4ilNgnO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.496a8e6d036d7695
EmsisoftTrojan.GenericKDZ.53749 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1140248
eGambitUnsafe.AI_Score_90%
Antiy-AVLTrojan/Generic.ASMalwS.2A850CD
MicrosoftBackdoor:Win32/Predator
ArcabitTrojan.Generic.DD1F5
AegisLabTrojan.Win32.Chapak.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKDZ.53749
TACHYONRansom/W32.GandCrab.562688.B
AhnLab-V3Trojan/Win32.Gandcrab.R254687
Acronissuspicious
McAfeeArtemis!496A8E6D036D
MAXmalware (ai score=87)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B5D8 (CLASSIC)
YandexTrojan.Chapak!o8kF89lKhvQ
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GPQE!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwsBEpsA

How to remove Backdoor:Win32/Predator?

Backdoor:Win32/Predator removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment