Trojan

Trojan-PSW.Win32.Racealer.mqh removal

Malware Removal

The Trojan-PSW.Win32.Racealer.mqh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Racealer.mqh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Raccoon malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

wpad.local-net
t.me

How to determine Trojan-PSW.Win32.Racealer.mqh?


File Info:

name: D0DDB2F5894EA2F8BD39.mlw
path: /opt/CAPEv2/storage/binaries/604f0ab41564bde36e4620ceea380c3dcdd338bfc8a476059eafdfa76caceb03
crc32: 883BA654
md5: d0ddb2f5894ea2f8bd39f301b51558d9
sha1: bdcdcd9ee72fa304fd669fca5238f0670da7eac6
sha256: 604f0ab41564bde36e4620ceea380c3dcdd338bfc8a476059eafdfa76caceb03
sha512: 5cb94f17de396586ebef866053d9bd6e926f60505117878e8a46bbd13f5d8bb0084cd5088302b3422a2db797562bf7a49b6d55081729ae7cffc4de82f706657a
ssdeep: 24576:h4VQrPaCn/GqxiRKgZ0q82vLtEOBSKRWnS7fjTC8Lv/V:6VwJ5g38ypv2YH9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5352302AB0B6086FC1911B48B63CB5EB3B58FCEB5947393674EB32C3D377929096146
sha3_384: a82cf373603b4bb06a6a83149955361c7d583fc0e17fba14975f466caebed1a4b17e29ae041abdc2b8711dd5656e9369
ep_bytes: 6801204e00e801000000c3c31b9b75a6
timestamp: 2021-11-23 10:42:38

Version Info:

0: [No Data]

Trojan-PSW.Win32.Racealer.mqh also known as:

LionicTrojan.Win32.Injuke.4!c
MicroWorld-eScanTrojan.GenericKD.38101031
FireEyeGeneric.mg.d0ddb2f5894ea2f8
McAfeeArtemis!D0DDB2F5894E
MalwarebytesTrojan.Crypt
K7AntiVirusTrojan ( 0058acee1 )
AlibabaTrojanPSW:Win32/Racealer.9b092059
K7GWTrojan ( 0058acee1 )
Cybereasonmalicious.ee72fa
ArcabitTrojan.Generic.D2456027
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.NAX
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Racealer.mqh
BitDefenderTrojan.GenericKD.38101031
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.38101031
EmsisoftTrojan.GenericKD.38101031 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
SophosMal/Generic-S
IkarusTrojan.Win32.ASProtect
WebrootW32.Trojan.Gen
AviraTR/AD.StellarStealer.iirjc
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Script/Phonzy.C!ml
GDataWin32.Trojan-Stealer.Racealer.YUHH8H
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34294.dHWaambYdTii
ALYacTrojan.GenericKD.38101031
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Racealer
YandexTrojan.PWS.Racealer!pamobCowVgs
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-PSW.Win32.Racealer.mqh?

Trojan-PSW.Win32.Racealer.mqh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment