Trojan

Trojan-PSW.Win32.Predator.gsa information

Malware Removal

The Trojan-PSW.Win32.Predator.gsa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Predator.gsa virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Steals private information from local Internet browsers
  • The following process appear to have been packed with Themida: 1.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
j1041747.myjino.ru

How to determine Trojan-PSW.Win32.Predator.gsa?


File Info:

crc32: C648361A
md5: 4a544e86714b7ea0a29a12d79f5c14db
name: 1.exe
sha1: b4d40dec2e875736c43fcddc70489a746831b7e7
sha256: 1736e5bd6c50fdc62f441dd2065c51f7ddb23468d2d210c533038155829b17af
sha512: 326b860034c22505a8379233bd1481010ec4cb5f1a664114a53d417d6acfab319d502866be6fdedcafab304944c4f94e975e09168845bdb39639705280ca4fa1
ssdeep: 49152:cUTjGwDs4fD6FNO25OpLbpAeE2HJu2ojWbPVwkWDRgA9TnxTPPz8:dGwZ7Ppv/THJIjWGkWF197tXz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2019 Google LLC. All rights reserved.
InternalName: chrome_exe
CompanyShortName: Google
FileVersion: 79.0.3945.130
CompanyName: Google LLC
ProductShortName: Chrome
ProductName: Google Chrome
LastChange: e22de67c28798d98833a7137c0e22876237fc40a-refs/branch-heads/3945@#1047
ProductVersion: 79.0.3945.130
FileDescription: Google Chrome
OriginalFilename: chrome.exe
Official Build: 1
Translation: 0x0409 0x04b0

Trojan-PSW.Win32.Predator.gsa also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.33289990
FireEyeTrojan.GenericKD.33289990
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!4A544E86714B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055bc301 )
BitDefenderTrojan.GenericKD.33289990
K7GWTrojan ( 0055bc301 )
Cybereasonmalicious.6714b7
TrendMicroTROJ_GEN.R002C0GBQ20
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33289990
KasperskyTrojan-PSW.Win32.Predator.gsa
AlibabaTrojanPSW:Win32/Predator.06728a7e
NANO-AntivirusTrojan.Win32.Predator.hbkdav
AvastWin32:CrypterX-gen [Trj]
RisingTrojan.Occamy!8.F1CD (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33289990 (B)
F-SecureTrojan.TR/Crypt.TPM.Gen
ZillyaTrojan.Themida.Win32.9048
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Themida
CyrenW32/Trojan.LGUU-7423
JiangminTrojan.PSW.Predator.axy
AviraTR/Crypt.TPM.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1FBF706
ZoneAlarmTrojan-PSW.Win32.Predator.gsa
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.GenericKD.33289990
Ad-AwareTrojan.GenericKD.33289990
ESET-NOD32a variant of Win32/Packed.Themida.HFL
TrendMicro-HouseCallTROJ_GEN.R002C0GBQ20
TencentWin32.Trojan-qqpass.Qqrob.Pdmi
YandexTrojan.Themida!
MaxSecureTrojan.Malware.74839980.susgen
FortinetW32/Predator.GSA!tr.pws
BitDefenderThetaGen:NN.ZexaF.34098.FE2aamYOSRgi
AVGWin32:CrypterX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.PSW.809

How to remove Trojan-PSW.Win32.Predator.gsa?

Trojan-PSW.Win32.Predator.gsa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment