Trojan

Trojan:Win32/Duote.G!MTB removal

Malware Removal

The Trojan:Win32/Duote.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Duote.G!MTB virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

api.xp666.com
download.xp666.com

How to determine Trojan:Win32/Duote.G!MTB?


File Info:

crc32: 09DE9C06
md5: 07d9c027a02c5a8b64957a5244b97746
name: ultrarecallprodt_6031.exe
sha1: 8ee3a10080873e2bd3ad5e1f9cf195521d76f921
sha256: 01188cd33fd2bb88d19c17633fb56be03fbb40837177360780f2839dfb3f6692
sha512: 7125a4e00364c0e388536a51c781ceca8176056ffb7292837c5f09123e774190cb16d9a2090db0cd4cd0795af5affd92dc848953ae684ce4c838355a083c775b
ssdeep: 24576:acyfzfGxYd1ar1rXYOQw1s2TZHDoGJE8dv99T:ahfzfGKoBCYDNJRdD
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
FileVersion: 3.9.0.247
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.9.0.210
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownload.exe
Translation: 0x0804 0x03a8

Trojan:Win32/Duote.G!MTB also known as:

MicroWorld-eScanGen:Variant.Strictor.241869
FireEyeGen:Variant.Jacard.166143
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!07D9C027A02C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e4261 )
BitDefenderGen:Variant.Strictor.241869
K7GWTrojan ( 0055e4261 )
BitDefenderThetaGen:NN.ZelphiF.34104.7mKfaWoVR7ei
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Strictor.241869
AlibabaTrojan:Win32/Tiggre.0b9355b8
NANO-AntivirusTrojan.Win32.Duote.hfdnox
AegisLabTrojan.Win32.Jacard.4!c
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Strictor.Hph
Ad-AwareGen:Variant.Strictor.241869
EmsisoftGen:Variant.Strictor.241869 (B)
F-SecureTrojan.TR/RedCap.jtxwp
TrendMicroTROJ_GEN.R002C0PCK20
McAfee-GW-EditionBehavesLike.Win32.DlHelper.dc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Duote
CyrenW32/Trojan.XIGJ-0921
JiangminTrojan.Agentb.glb
MaxSecureTrojan.Malware.74718171.susgen
AviraTR/RedCap.jtxwp
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ArcabitTrojan.Strictor.D3B0CD
MicrosoftTrojan:Win32/Duote.G!MTB
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Strictor.241869
MAXmalware (ai score=99)
ESET-NOD32a variant of Win32/Duote.A
TrendMicro-HouseCallTROJ_GEN.R002C0PCK20
RisingTrojan.Duote!8.11613 (CLOUD)
YandexTrojan.Duote!
SentinelOneDFI – Malicious PE
FortinetW32/Doute.A!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Trojan:Win32/Duote.G!MTB?

Trojan:Win32/Duote.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment