Trojan

Trojan:Win32/Predator.KZ!MTB (file analysis)

Malware Removal

The Trojan:Win32/Predator.KZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Predator.KZ!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Predator.KZ!MTB?


File Info:

crc32: CFCCE67D
md5: c5936b810b048e5241f7446e13cfeeca
name: C5936B810B048E5241F7446E13CFEECA.mlw
sha1: 3c9f6dfabf13626857ff9586f214db0b8bfbc923
sha256: 355883485077e697f02f7137437718ef0d07ec4735dd24ec244a077ea60dbfaf
sha512: ecf697b88fc6f8e914816b11ccf9601a8f4aebd833c3d0505cb27d8e9fba5891cc65d90ac15fc05c589f63320bf574327d208b68420b442387898c162aa558f5
ssdeep: 6144:Ds9/lD+ID+Twmt1vFBnZWhsdQ6wgAc52UWpTX:ydD+IEwmt19kEQRgAc52UWpTX
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan:Win32/Predator.KZ!MTB also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Loader.839
CynetMalicious (score: 100)
ALYacTrojan.Injector.DHU
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Formbook.1aefba4b
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.abf136
CyrenW32/Ninjector.J.gen!Camelot
SymantecPacked.Generic.610
ESET-NOD32Win32/Formbook.AA
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Androm.gen
BitDefenderTrojan.Injector.DHU
MicroWorld-eScanTrojan.Injector.DHU
TencentWin32.Backdoor.Androm.Syrj
Ad-AwareTrojan.Injector.DHU
SophosMal/Generic-S
ComodoMalware@#bl2s37nl3b2p
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DFD21
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.dc
FireEyeGeneric.mg.c5936b810b048e52
EmsisoftTrojan.Injector.DHU (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Swotter.aqisw
MicrosoftTrojan:Win32/Predator.KZ!MTB
SUPERAntiSpywareAdware.ConvertAd/Variant
GDataTrojan.Injector.DHU
McAfeeArtemis!C5936B810B04
MAXmalware (ai score=83)
VBA32Trojan.Wacatac
MalwarebytesTrojan.Dropper.NSIS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R011C0DFD21
RisingTrojan.Injector/NSIS!1.D743 (CLASSIC)
YandexTrojan.Igent.bV1Az6.40
FortinetW32/Kryptik.J!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/Predator.KZ!MTB?

Trojan:Win32/Predator.KZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment