Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Should I remove “Trojan:Win32/Predator.EFG!MTB”?

Published May 3, 2024 Trojan category 3 min read
Report context

What to verify before removal

Use this report for a controlled check of Should I remove “Trojan:Win32/Predator.EFG!MTB”? when the affected machine shows suspicious processes, dropped files, or payload delivery behavior. The goal is to verify the exact file and persistence path before quarantine.

Start by comparing the local file name with 2D072D9730D04FE07B02.mlw, then review the behavior notes for persistence entries, dropped files, unusual processes, and browser or network changes. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
2D072D9730D04FE07B02.mlw
  • Compare the suspicious file name with 2D072D9730D04FE07B02.mlw.
  • Confirm the detection name matches Should I remove “Trojan:Win32/Predator.EFG!MTB”? before removing related files.
  • Review the report for persistence entries, dropped files, unusual processes, and browser or network changes so the cleanup is based on observed behavior, not only the label.
  • Run a full scan, quarantine confirmed detections, and restart before signing back in to sensitive accounts.

The Trojan:Win32/Predator.EFG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan:Win32/Predator.EFG!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine Trojan:Win32/Predator.EFG!MTB?


File Info:

name: 2D072D9730D04FE07B02.mlw
path: /opt/CAPEv2/storage/binaries/b504779a461b908fa21d4353471167841bcc3970481f29a96ee31600e17da9f6
crc32: 995608B7
md5: 2d072d9730d04fe07b02409ca8052515
sha1: e9d3a79bc9c2849bac92bb813868a28a01226672
sha256: b504779a461b908fa21d4353471167841bcc3970481f29a96ee31600e17da9f6
sha512: 9d99184970be94e11312cc08a5aebdf8b0ffccccfa188950ec1b4052d54082f6161c676a6a7a6e8ad81faa88567b8a4abdb16d89d9e779a4e868ceec960398f3
ssdeep: 6144:xyCLqrHh2n2A/Wy51N/eVO7rCZ85gYdsiirWXbO:xHLGk2A/B1NWVkCZ4gYb/bO
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T15F745C00FA91C038F4FB01F566B696AA9D3D797057BC85CB93C1599E0A34AE1EE30B17
sha3_384: f17139979ea8198f3d419da7000b39598b054068b629ba558933b3dacb758f030fd565e887b690735c3dcb8f76ba98b7
ep_bytes: 558bec837d0c017505e8d20501008b45
timestamp: 2019-10-17 01:41:36

Version Info:

0: [No Data]

Trojan:Win32/Predator.EFG!MTB also known as:

Lionic Trojan.Win32.Korplug.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.124307
FireEye Generic.mg.2d072d9730d04fe0
Skyhigh GenericRXTT-VY!2D072D9730D0
McAfee GenericRXTT-VY!2D072D9730D0
Malwarebytes Malware.AI.1511442114
Zillya Trojan.Generic.Win32.1031495
Sangfor Trojan.Win32.Predator.Vyc1
K7AntiVirus Trojan ( 005666dc1 )
Alibaba Trojan:Win32/Predator.0375c09c
K7GW Trojan ( 005666dc1 )
BitDefenderTheta Gen:NN.ZedlaF.36804.vu6@amaXjLni
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win32/Agent.ABXE
TrendMicro-HouseCall TROJ_GEN.R002C0DD524
Avast Win32:Malware-gen
ClamAV Win.Malware.Agent-7785027-0
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Fragtor.124307
NANO-Antivirus Trojan.Win32.Korplug.irzrsv
Tencent Malware.Win32.Gencirc.10bea422
Emsisoft Gen:Variant.Fragtor.124307 (B)
F-Secure Trojan.TR/AD.Korplug.zwtql
DrWeb Trojan.Siggen18.44853
VIPRE Gen:Variant.Fragtor.124307
TrendMicro TROJ_GEN.R002C0DD524
Sophos Mal/Generic-S
Paloalto generic.ml
MAX malware (ai score=100)
Jiangmin Trojan.Script.avgx
Google Detected
Avira TR/AD.Korplug.zwtql
Varist W32/ABRisk.KTHJ-2480
Antiy-AVL Trojan/Win32.AGeneric
Microsoft Trojan:Win32/Predator.EFG!MTB
Arcabit Trojan.Fragtor.D1E593
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Gen:Variant.Fragtor.124307
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.Generic.C4108046
VBA32 Adware.Presenoker
ALYac Gen:Variant.Fragtor.124307
Cylance unsafe
Panda Trj/GdSda.A
Rising Trojan.AgentTesla!8.104D5 (TFE:6:jjwacq8CYMM)
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.7164915.susgen
Fortinet W32/PossibleThreat
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Trojan.Win.UnkAgent

How to remove Trojan:Win32/Predator.EFG!MTB?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.