Trojan

Trojan:Win32/Raccoon.AMD!MTB (file analysis)

Malware Removal

The Trojan:Win32/Raccoon.AMD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccoon.AMD!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan:Win32/Raccoon.AMD!MTB?


File Info:

name: 30AC99C75DAD3CFBB00C.mlw
path: /opt/CAPEv2/storage/binaries/b4f8818abc5d31e19dd7aa39630c4658b06984dd57ef02c2580b2623b8e95156
crc32: 7477E72C
md5: 30ac99c75dad3cfbb00c67eddb6e5b6f
sha1: 3725f318a9cabe4df82b7be1d1051e3b315f46e2
sha256: b4f8818abc5d31e19dd7aa39630c4658b06984dd57ef02c2580b2623b8e95156
sha512: 5a44cfa78b39a695ab36dffd7e7722d5c6273ab3e81fa2ac4bacc533eaa9f463c87da922929e80cc20ccd6c0e47efba0064d1457c914d022ed2ce9c68f200060
ssdeep: 98304:Roc5swrA2XGxlHKcjTjNk3o659yrnfKtDrKIAyyks+Ctf8mQZVSq:i0LrA2kHKQHNk3og9unipQyOaOq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B26623B302551189E3D9CB398927FD9971F61F3E8BC1A87CD1AAFDD11832192E21364B
sha3_384: 0e99070e76cfe18bfcd3231ce1eac3bddb7753a725f425c95a03115ab6b38b860a6c6f9091048a5b6c6c5e1d7a665e62
ep_bytes: 529cbac00e674ae8c9d6f1ff4033d803
timestamp: 2013-07-24 15:48:49

Version Info:

0: [No Data]

Trojan:Win32/Raccoon.AMD!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.SMSSend.7666
MicroWorld-eScanGen:Variant.Zusy.540557
CAT-QuickHealTrojan.Raccoon
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!30AC99C75DAD
MalwarebytesTrojan.MalPack.PES
SangforTrojan.Win32.Agent.V57y
K7AntiVirusTrojan ( 0059f3ce1 )
BitDefenderGen:Variant.Zusy.540557
K7GWTrojan ( 0059f3ce1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.@JX@aSrMj!lO
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.AU suspicious
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Vmprotect-10023715-0
NANO-AntivirusTrojan.Win32.Drop.kkoiet
AvastWin32:Evo-gen [Trj]
RisingStealer.Raccoon!8.12279 (TFE:3:cRGeTUfM6SS)
EmsisoftGen:Variant.Zusy.540557 (B)
F-SecureHeuristic.HEUR/AGEN.1315126
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.30ac99c75dad3cfb
SophosMal/Generic-S
IkarusPUA.VMProtect
JiangminBackdoor.Plite.aaa
GoogleDetected
AviraHEUR/AGEN.1315126
MAXmalware (ai score=84)
Antiy-AVLTrojan[Packed]/Win32.VMProtect
GridinsoftTrojan.Heur!.03212021
MicrosoftTrojan:Win32/Raccoon.AMD!MTB
GDataWin32.Trojan.PSE.1AYJXUE
VaristW32/Raccoon.H.gen!Eldorado
AhnLab-V3Trojan/Win.Evo-gen.R639081
Cylanceunsafe
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10bfbce8
YandexRiskware.VMProtect!dHEusIR8ruI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudVirTool:Win/Obfuscate.SMC.Hep(dyn)

How to remove Trojan:Win32/Raccoon.AMD!MTB?

Trojan:Win32/Raccoon.AMD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment