Trojan

Trojan:Win32/Raccoon.NEAB!MTB removal instruction

Malware Removal

The Trojan:Win32/Raccoon.NEAB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccoon.NEAB!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Saami
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan:Win32/Raccoon.NEAB!MTB?


File Info:

name: 41EEF04DB755DF557CA0.mlw
path: /opt/CAPEv2/storage/binaries/ad176b78fc926be4bcf4b28dc9c0be60f33d86bd98f63b1790d01ca00adf3b79
crc32: F33F3C98
md5: 41eef04db755df557ca0312a759496aa
sha1: 8afccfe1b3b5474b6d7dc75eff12b5514e425233
sha256: ad176b78fc926be4bcf4b28dc9c0be60f33d86bd98f63b1790d01ca00adf3b79
sha512: bb350fa51b680ab4ec5fb4f010afa434fdf453ee078f6b84400f89120f6a46eb6922a0dc8812c4bf18f0ce65a33c293123eaea6a9b739e255895960a8da78e4e
ssdeep: 3072:CR5Jc26kYbugIwjpIVQ8eVT7HxjaxsiIM8yTO6PGvY+JI0Ka:2L6digIwODmT7H9ax3PB+C0K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13404AE1176B1D037E17219304C36C2F52B2ABDA3AA74A5CF3390BB2E5DB12C14A72767
sha3_384: 1a23449ee196d45704927feadd1720cb68d884722e28782fecfab5985ee09aca317aa1df121cc6dfd5a9486b5e083dd8
ep_bytes: e892470000e989feffff2da403000074
timestamp: 2021-09-10 06:20:18

Version Info:

CompanyName: PakistanFood
FileDescription: Morricone
FileVersion: 25.71.48.45
InternalName: GorgerousVar.exe
LegalTrademarks1: consultated
OriginalFilename: pskodkfgnosfd.exe
Translation: 0x4042 0x0564

Trojan:Win32/Raccoon.NEAB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.65786579
CAT-QuickHealTrojan.GenericRI.S30113006
McAfeeLockbit-FSWW!41EEF04DB755
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4058046
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059fbbd1 )
AlibabaTrojanSpy:Win32/Stealer.798ad921
K7GWTrojan ( 0059fbbd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Kryptik.jm
VirITTrojan.Win32.Genus.ODR
CyrenW32/Convagent.BP.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HSXY
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.65786579
NANO-AntivirusTrojan.Win32.Stealer.jvhgnq
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
EmsisoftTrojan.GenericKD.65786579 (B)
F-SecureTrojan.TR/Spy.Stealer.mfjrw
DrWebTrojan.PWS.Stealer.35775
VIPRETrojan.GenericKD.65786579
TrendMicroTROJ_GEN.R067C0DC723
McAfee-GW-EditionBehavesLike.Win32.Lockbit.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.41eef04db755df55
SophosTroj/Krypt-VE
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.65786579
WebrootW32.Trojan.Gen
AviraTR/Spy.Stealer.mfjrw
Antiy-AVLTrojan/Win32.Wacatac
XcitiumMalware@#3iyruwqr4jwi6
ArcabitTrojan.Generic.D3EBD2D3
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Raccoon.NEAB!MTB
GoogleDetected
AhnLab-V3Infostealer/Win.SmokeLoader.R561084
ALYacTrojan.GenericKD.65786579
MAXmalware (ai score=87)
VBA32BScope.TrojanDownloader.Deyma
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R067C0DC723
RisingStealer.Agent!8.C2 (TFE:5:z8xpky9FqpM)
YandexTrojan.Kryptik!VzXaLfPPa70
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Kryptik.HSYD!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.1b3b54
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Raccoon.NEAB!MTB?

Trojan:Win32/Raccoon.NEAB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment