Trojan

How to remove “Trojan-PSW.Win32.Racealer.jmc”?

Malware Removal

The Trojan-PSW.Win32.Racealer.jmc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.jmc virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-PSW.Win32.Racealer.jmc?


File Info:

crc32: 0DED59E3
md5: 24f43a2513184cc3ed860813c7312a22
name: upload_file
sha1: 8b1064c0b703c18fed99258fe208692c438e3d56
sha256: 2a3dcbe001c250ee2741d14d5fe2eaec34de0392c476c79206e350ceb3211c9d
sha512: 9f6c6a302681f47ac53c32eb526c15eb79d74b458b8471a1067d623b67bc7614d373bd8902760f2c5fca1968e9e2aaba93d6818b866f66725d351788e4bfeade
ssdeep: 98304:YX435ugyZvng/ZRJwPPJNh2Uk8PjtqVBbnmDTTN8oAXGxsAYsm:mWmZoxjwJNh2UkspQBbmhbiHAO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2015 AAF. All rights reserved.
FileVersion: 3.0.33.0
CompanyName: 2015 AAF. All rights reserved.
Comments: This installation was built with Inno Setup.
ProductName: Installer
ProductVersion: 3.0.33.0
FileDescription: Installer Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Trojan-PSW.Win32.Racealer.jmc also known as:

DrWebTrojan.PWS.Stealer.29183
MicroWorld-eScanTrojan.GenericKD.44016322
CAT-QuickHealTrojanpws.Racealer
ALYacTrojan.PSW.Racealer
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.44016322
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
InvinceaMal/Generic-S
SymantecTrojan Horse
ESET-NOD32Win32/Spy.Agent.PQZ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Racealer.jmc
AlibabaTrojanPSW:Win32/Racealer.9d38d0d2
ViRobotTrojan.Win32.Z.Racealer.4421872
Ad-AwareTrojan.GenericKD.44016322
EmsisoftMalCert.A (A)
ComodoMalware@#38fpt8ltepoxi
F-SecureTrojan.TR/PSW.Stealer.ergux
TrendMicroTROJ_GEN.R057C0DJA20
FireEyeTrojan.GenericKD.44016322
SophosMal/Generic-S
GDataTrojan.GenericKD.44016322
AviraTR/PSW.Stealer.ergux
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D29FA2C2
AegisLabTrojan.Win32.Racealer.i!c
ZoneAlarmTrojan-PSW.Win32.Racealer.jmc
MicrosoftTrojan:Win32/CryptInject!MSR
VBA32TrojanPSW.Racealer
MalwarebytesSpyware.RaccoonStealer.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R057C0DJA20
IkarusTrojan.PSW.Stealer
MaxSecureTrojan.Malware.107817069.susgen
FortinetW32/Racealer.JMC!tr.pws
WebrootAdware.Gen
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.PSW.e21

How to remove Trojan-PSW.Win32.Racealer.jmc?

Trojan-PSW.Win32.Racealer.jmc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment