Crack

HackTool.Win32.JPotato.fj removal guide

Malware Removal

The HackTool.Win32.JPotato.fj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool.Win32.JPotato.fj virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:2333
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine HackTool.Win32.JPotato.fj?


File Info:

name: A66361DD881C2E6A84E7.mlw
path: /opt/CAPEv2/storage/binaries/12dd1d88a09a041aaede809ae5afd9aaf1ea2fde0be68afc96204479cd30410c
crc32: 8FC66725
md5: a66361dd881c2e6a84e7a51b380e152a
sha1: adb4f8b63eb915ec1ca55a182cadf26fcdb15f3d
sha256: 12dd1d88a09a041aaede809ae5afd9aaf1ea2fde0be68afc96204479cd30410c
sha512: 50fcb2a11bfffe06d576e09aae494dab115680933d0078f9026a3f63c307077ddc08ee030101d2bffe54f0d0303d83f60b8a05ff717fff7f4a6520acd06b220d
ssdeep: 12288:BOcDchZuwpp8UzQDmz/V9plvdaFH87BAj8pYtguexpTC8OgMH:BOcDcB8MD7iDt2zOgMH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14365B990D1DF20E7EA4DA7F771055220A6FAF1333D1D07E599D032BC98B3686ED442AA
sha3_384: 3595c5b1994e452d7a7a8d8d851b00986efc432aed6e0545b406b22b0c4b345e95050d5ceab338219b23abc09627114b
ep_bytes: c70550c0520000000000e9a1fcffff90
timestamp: 2021-12-08 07:50:57

Version Info:

0: [No Data]

HackTool.Win32.JPotato.fj also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47600375
FireEyeTrojan.GenericKD.47600375
ALYacTrojan.GenericKD.47600375
MalwarebytesMalware.AI.2894709712
K7AntiVirusTrojan ( 0057e5a71 )
AlibabaTrojan:Win32/GenKryptik.3e388267
K7GWTrojan ( 0057e5a71 )
BitDefenderThetaGen:NN.ZexaF.34084.B9Z@aGNTQjk
CyrenW32/FakeAlert.5!Maximus
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FGSG
TrendMicro-HouseCallTROJ_GEN.R002H0CL821
Paloaltogeneric.ml
KasperskyHackTool.Win32.JPotato.fj
BitDefenderTrojan.GenericKD.47600375
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.47600375
EmsisoftTrojan.GenericKD.47600375 (B)
McAfee-GW-EditionGenericRXPO-CH!A66361DD881C
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
GDataTrojan.GenericKD.47600375
JiangminTrojan.Jobutyve.ci
AviraTR/Kryptik.lqqgf
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.GenKryptik
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D652F7
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
McAfeeGenericRXPO-CH!A66361DD881C
VBA32BScope.Backdoor.Meterpreter
eGambitUnsafe.AI_Score_100%
FortinetW32/GenKryptik.FGSG!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove HackTool.Win32.JPotato.fj?

HackTool.Win32.JPotato.fj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment