Trojan

Should I remove “Trojan-PSW.Win32.Racealer.lsz”?

Malware Removal

The Trojan-PSW.Win32.Racealer.lsz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.lsz virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Trojan-PSW.Win32.Racealer.lsz?


File Info:

crc32: 9D45F6AA
md5: 062abd2ebe1c0edb0dafa021e95c4fa7
name: 062ABD2EBE1C0EDB0DAFA021E95C4FA7.mlw
sha1: c5a0295a500e8d9b7ce0251188fba9b2047003ef
sha256: 6c9063a9eff83a71d5cf09591de3f3cb09fc9a209ea67901b939e53cf16eea4d
sha512: d5b20a60e91abbe6b26cae1f76e354398a1b3001dbc6e860af4404aff8186da383ca1e4ecb9555094d27403d1c5d1f9a80ff92de294beff02ad0cb5288ef7274
ssdeep: 24576:6ZZn6rg7mqeZPQ3uYaQx7SD95AuT1PVeT5u+aFAKDKf2iI9q3HCrchjfL1fZXzwo:6Wrg7eQ3uk7SDLneDxdC4ZL1VzwJa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Racealer.lsz also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
ClamAVWin.Packed.Enigma-9837395-0
ALYacTrojan.GenericKD.46837854
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaPacked:Win32/EnigmaProtector.b2d1c74c
K7GWTrojan ( 004befdb1 )
K7AntiVirusTrojan ( 004befdb1 )
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Racealer.lsz
BitDefenderTrojan.GenericKD.46837854
MicroWorld-eScanTrojan.GenericKD.46837854
Ad-AwareTrojan.GenericKD.46837854
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1142958
BitDefenderThetaGen:NN.ZexaF.34126.CHX@aee1TFoG
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.062abd2ebe1c0edb
EmsisoftTrojan.GenericKD.46837854 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1142958
eGambitUnsafe.AI_Score_98%
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tnega!ml
GridinsoftTrojan.Win32.Packed.oa!s1
ArcabitTrojan.Generic.D2CAB05E
GDataTrojan.GenericKD.46837854
AhnLab-V3Trojan/Win.Generic.R438277
McAfeeArtemis!062ABD2EBE1C
MAXmalware (ai score=82)
VBA32Trojan.Zpevdo
MalwarebytesSpyware.RaccoonStealer
PandaTrj/CI.A
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
IkarusPUA.EnigmaProtector
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Racealer.lsz?

Trojan-PSW.Win32.Racealer.lsz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment