Trojan

Trojan-PSW.Win32.Racealer.kno malicious file

Malware Removal

The Trojan-PSW.Win32.Racealer.kno is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.kno virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Trojan-PSW.Win32.Racealer.kno?


File Info:

crc32: 18660C2C
md5: 50b4e71915c9d1036c76bed87705d866
name: 50B4E71915C9D1036C76BED87705D866.mlw
sha1: a64db8a2a5643ca2294bde9af4870ba2ea537bb5
sha256: d3e695ecc00f58dc280c1152699403ca51c4460057ef32871fba760acbfcac24
sha512: 1154ce45e7bb9e066a8ad0acfee444d436e2ddc42af2b455e71edcef56c857e82c2c9dc78ce285836a4e6c7b80e8662ff0827b0c4356e33d6097f0d2cfcca9e8
ssdeep: 98304:OHv3XZCnsST8rpX7RSthC/BUkQMcj5UbrPxyq8D6zRO2cZmbBNsv:03STapX7RStc/BUkQME5UvPx8D6zY2cT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2010, 2020 NVIDIA Corporation. All rights reserved.
Assembly Version: 2.0.0.0
InternalName: SETUP.exe
FileVersion: 2.0.0.0
CompanyName: NVIDIA Corporation
Comments: NVIDIA Install Application
ProductName: NVIDIA Install Application
ProductVersion: 2.0.0.0
FileDescription: NVIDIA Install Application
OriginalFilename: SETUP.exe

Trojan-PSW.Win32.Racealer.kno also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.45649151
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanSpy:Win32/Raccoon.9fcc6b88
K7GWSpyware ( 005768171 )
Cybereasonmalicious.2a5643
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Raccoon.A
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Ulise-7344017-0
KasperskyTrojan-PSW.Win32.Racealer.kno
BitDefenderTrojan.GenericKD.45649151
MicroWorld-eScanTrojan.GenericKD.45649151
TencentWin32.Trojan-qqpass.Qqrob.Suxo
Ad-AwareTrojan.GenericKD.45649151
SophosMal/Generic-S
ComodoMalware@#2mqzfwdeh888o
F-SecureTrojan.TR/AD.StellarStealer.jrevh
BitDefenderThetaGen:NN.ZexaF.34780.Ux2@auKudHl
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.50b4e71915c9d103
EmsisoftTrojan.GenericKD.45649151 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.StellarStealer.jrevh
MicrosoftTrojan:Win32/Caynamer.A!ml
ArcabitTrojan.Generic.D2B88CFF
ZoneAlarmTrojan-PSW.Win32.Racealer.kno
GDataWin32.Trojan-Stealer.Racealer.IAJJ8P
Acronissuspicious
MAXmalware (ai score=83)
MalwarebytesSpyware.RaccoonStealer
PandaTrj/GdSda.A
RisingSpyware.Agent!8.C6 (TFE:5:LEkrhCHv8nV)
IkarusTrojan.Win64.Themida
eGambitPE.Heur.InvalidSig
FortinetW32/Raccoon.A!tr.spy
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Raccoon.HxMB9nsA

How to remove Trojan-PSW.Win32.Racealer.kno?

Trojan-PSW.Win32.Racealer.kno removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment