Trojan

What is “Trojan:Win32/Raccrypt.GR!MTB”?

Malware Removal

The Trojan:Win32/Raccrypt.GR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccrypt.GR!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Trojan:Win32/Raccrypt.GR!MTB?


File Info:

crc32: 39F50689
md5: bdb8002a5c5d8880ba2133d765d44193
name: BDB8002A5C5D8880BA2133D765D44193.mlw
sha1: bc8f1ad4fb372d8ae17be2f20cfa9fad3a2679f8
sha256: 254c28cd968abd1048e5baa80c9aff405e32de2d840d5b0e5882515ad6d47be2
sha512: 6b2ae36779a6a721c8b39928f16857677c81c40a4b6dc69f74aa5ac5feb2c70595dd76810dc10a2c2302561b2702e1b753a07b6bd4dc499721a225afabebc8a4
ssdeep: 12288:sMyXcpXC3XphQAFoveV21dpA/zIE7L65qF/0uCz/sHqHfhLi0q:AMpXGtfadpW1W5OZ4o8E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020b 0x0549

Trojan:Win32/Raccrypt.GR!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader41.8982
ClamAVWin.Dropper.Generickdz-9885122-0
ALYacTrojan.GenericKDZ.76940
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.ETY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMAL
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.76940
MicroWorld-eScanTrojan.GenericKDZ.76940
Ad-AwareTrojan.GenericKDZ.76940
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34058.LuW@amLJxxmG
TrendMicroRansom_Stop.R06CC0DHD21
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.bdb8002a5c5d8880
EmsisoftTrojan.GenericKDZ.76940 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.nwobc
eGambitUnsafe.AI_Score_93%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Raccrypt.GR!MTB
GDataWin32.Trojan.PSE.151EN8O
AhnLab-V3Trojan/Win.MalPE.R436435
Acronissuspicious
McAfeePacked-GDT!BDB8002A5C5D
MAXmalware (ai score=82)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Stop.R06CC0DHD21
RisingTrojan.Kryptik!1.C6FC (CLASSIC)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMAV!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Stop.HwoCQXcA

How to remove Trojan:Win32/Raccrypt.GR!MTB?

Trojan:Win32/Raccrypt.GR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment