Trojan

How to remove “Trojan-PSW.Win32.Racealer.igj”?

Malware Removal

The Trojan-PSW.Win32.Racealer.igj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.igj virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
telete.in
apps.identrust.com
a.tomx.xyz

How to determine Trojan-PSW.Win32.Racealer.igj?


File Info:

crc32: 40831FAA
md5: 558dab496ca1a57bf6fdd7163350f314
name: upload_file
sha1: f01754b62b587ac5c2d93882b7eb2dcaf1683b32
sha256: 925f4b0f9cf7b51763ad5c9a89774a6a29834881a423c81f53b6cf2fed76d705
sha512: fded354d28df07c8eb9effcb6bbbf0cf6a5323d53946397a263532005718e71238315c0482a613c13462c7dd22165743baccca5ec5724e26661a6f338e80b1e9
ssdeep: 12288:T5NLxPf4coMo2Ezwvt04F7dChzLEJtvUtgjT0ROxczbJ+5PZylsvJXye:1NdPfttolzat0M7dJMQmkcx+5PZ5Ce
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009-11, 2015 Dave Brotherstone
InternalName: gpup
FileVersion: 1.3.5.0
Comments: A generic(ish) plugin ipdater, built initially for Notepad++
ProductName: gpup
ProductVersion: 1.3.5.0
FileDescription: gpup
OriginalFilename: gpup.exe
Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Racealer.igj also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.43575475
FireEyeGeneric.mg.558dab496ca1a57b
CAT-QuickHealTrojanpws.Racealer
McAfeeRDN/GuLoaderMLFNG
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Racealer.i!c
SangforMalware
K7AntiVirusTrojan ( 005652be1 )
BitDefenderTrojan.GenericKD.43575475
K7GWTrojan ( 005652be1 )
CrowdStrikewin/malicious_confidence_80% (W)
Invinceaheuristic
SymantecTrojan!im
APEXMalicious
AvastWin32:DangerousSig [Trj]
GDataTrojan.GenericKD.43575475
KasperskyTrojan-PSW.Win32.Racealer.igj
AlibabaTrojanPSW:Win32/Racealer.fa4a0b24
NANO-AntivirusTrojan.Win32.Racealer.hqdzox
RisingTrojan.Kryptik!1.C9B6 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43575475 (B)
F-SecureTrojan.TR/Crypt.Agent.zoqza
DrWebTrojan.PWS.Siggen2.51569
TrendMicroTROJ_GEN.R002C0PH220
SophosMal/EncPk-APV
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.DBNH-8295
AviraTR/Crypt.Agent.zoqza
MAXmalware (ai score=81)
Antiy-AVLTrojan[PSW]/Win32.Racealer
ArcabitTrojan.Generic.D298E8B3
ZoneAlarmTrojan-PSW.Win32.Racealer.igj
MicrosoftTrojan:Win32/Ymacco.AA92
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Inject
ALYacTrojan.GenericKD.43575475
Ad-AwareTrojan.GenericKD.43575475
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFHM
TrendMicro-HouseCallTROJ_GEN.R002C0PH220
TencentMalware.Win32.Gencirc.11aac179
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.EOOB!tr
BitDefenderThetaGen:NN.ZexaF.34152.1u1@aC3ZDffi
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.62b587
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.PSW.614

How to remove Trojan-PSW.Win32.Racealer.igj?

Trojan-PSW.Win32.Racealer.igj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment