Trojan

How to remove “Trojan:Win32/Predator.AR!MTB”?

Malware Removal

The Trojan:Win32/Predator.AR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Predator.AR!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

ufok.duckdns.org

How to determine Trojan:Win32/Predator.AR!MTB?


File Info:

crc32: 678EE0FF
md5: 85853b825ebeac83aae857818788010b
name: photo.exe
sha1: 1b429c9c23b1c7fb4bb827e117a1576369c61a97
sha256: 7534b9f48d70953ed739b74ace44c5fdeae45b300c350f970b16969cce9e2c10
sha512: ffb94903101d26d67882d44223322d501df69660414c3b331ace5a47338985fcc3152d64031c5b8019973c4536c3bdfd1d28b78fbc1009ab143def907d1fd4b7
ssdeep: 24576:0Cdxte/80jYLT3U1jfsWaI2+0GYVkY0ihbYDwHq1HlsDw3ecaWeQ:lw80cTsjkWaI2+yzZYDwHqcsOM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/Predator.AR!MTB also known as:

MicroWorld-eScanTrojan.AutoIT.Agent.AAJ
FireEyeGeneric.mg.85853b825ebeac83
McAfeeTrojan-AitInject.aq
BitDefenderTrojan.AutoIT.Agent.AAJ
Cybereasonmalicious.c23b1c
Invinceaheuristic
F-ProtW32/AutoIt.LU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.AutoIT.Agent.AAJ
Endgamemalicious (high confidence)
SophosTroj/AutoIt-DAN
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.AutoIT.Agent.AAJ (B)
IkarusTrojan.Autoit
CyrenW32/AutoIt.LU.gen!Eldorado
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Autoit.BinToStr.a
ArcabitTrojan.AutoIT.Agent.AAJ
MicrosoftTrojan:Win32/Predator.AR!MTB
Acronissuspicious
ESET-NOD32a variant of Win32/Injector.Autoit.FFD
RisingTrojan.Obfus/Autoit!1.C408 (CLASSIC)
eGambitUnsafe.AI_Score_55%
FortinetAutoIt/Injector.FFA!tr
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Predator.AR!MTB?

Trojan:Win32/Predator.AR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment