Trojan

Trojan-PSW.Win32.Racealer.luc removal instruction

Malware Removal

The Trojan-PSW.Win32.Racealer.luc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.luc virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Collects information to fingerprint the system

Related domains:

telete.in
apps.identrust.com

How to determine Trojan-PSW.Win32.Racealer.luc?


File Info:

crc32: 535222D8
md5: 24d31ce120e3740d10f7335a55504b2d
name: 24D31CE120E3740D10F7335A55504B2D.mlw
sha1: 820270029109394983d9d3d1b2c1d54ef648fb0f
sha256: 486658750c2204bf7924086f67e9228d7d604deae84dfc5caaa66ea7d2222179
sha512: b4644251124f45cb716a1c615c6107b5dd95376b7b68fecffe7990443f08de78aab75d0c322c991d167fbeadc64ede8dc5b1a141802955a058f5c38d70417166
ssdeep: 49152:VLe9+2YUKl9RSn8CEtKfxWcHPrAu/GiSH2Zn+08HH/XtjY:VL6EKn8CHPTc2x+pHf
type: MS-DOS executable, MZ for MS-DOS

Version Info:

LegalCopyright: Copyright (C) 2017 Realtek Semiconductor Corp.
InternalName: RtlUpd
FileVersion: 3, 2, 0, 0
CompanyName: Realtek Semiconductor Corp.
Comments: Developed by Archeng
ProductName: Realtek HD Auido Update and remove driver Tool
ProductVersion: 3, 2, 0, 0
FileDescription: Driver Setup API for Realtek HD Audio
OriginalFilename: RtlUpd.EXE
Translation: 0x0409 0x04b0

Trojan-PSW.Win32.Racealer.luc also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanPSW:Win32/Racealer.c0a35439
K7GWTrojan ( 005797481 )
ESET-NOD32a variant of Win32/Kryptik.HIYJ
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-PSW.Win32.Racealer.luc
BitDefenderTrojan.GenericKD.37540109
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34126.!nuaaWVg6Hai
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.24d31ce120e3740d
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataWin32.Trojan-Stealer.Racealer.R2M9C9
McAfeeArtemis!24D31CE120E3
IkarusWin32.Outbreak
FortinetW32/Kryptik.HIYJ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Racealer.luc?

Trojan-PSW.Win32.Racealer.luc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment