Trojan

Trojan:Win32/Raccrypt.GS!MTB malicious file

Malware Removal

The Trojan:Win32/Raccrypt.GS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccrypt.GS!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Morocco)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Trojan:Win32/Raccrypt.GS!MTB?


File Info:

crc32: 45BEAC9A
md5: 251f7a346d17e3deafc9c0deba82f71c
name: 251F7A346D17E3DEAFC9C0DEBA82F71C.mlw
sha1: 7b662f878d03292fb8f56f5cebd42f82832e7159
sha256: 1a57787821438ee75708c8921d11dd26d231881e3e075d1e9cd95b1d2ff0d505
sha512: ca935712a8879f06c679f155c26a7f39be721ef41f462811cdd8a6d9424b759d240e66f9858e2bb5f6f1f94c10566bf7f6f0b5ffeb99220e640e034de11f4e1f
ssdeep: 6144:4uZQcY5ww7hz56mk3MI/wJ9sEvfNIc9+WC9Y0JbM8fV8Upb:RZI7hz564I/utV2YK3mUpb
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

Translation: 0x1209 0x052d

Trojan:Win32/Raccrypt.GS!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005828bf1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader42.62977
CynetMalicious (score: 100)
ALYacGen:Variant.Fragtor.22696
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005828bf1 )
Cybereasonmalicious.78d032
CyrenW32/Kryptik.FHP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMNM
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Raccoon-9894356-1
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.Generic.30077180
MicroWorld-eScanGen:Variant.Fragtor.22696
TencentWin32.Exploit.Shellcode.Hoex
Ad-AwareGen:Variant.Fragtor.22696
SophosML/PE-A
ComodoTrojWare.Win32.UMal.apcxv@0
BitDefenderThetaGen:NN.ZexaF.34142.tuW@aSZgaGjO
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.251f7a346d17e3de
EmsisoftGen:Variant.Fragtor.22696 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.RedLineSteal.pmmmx
eGambitUnsafe.AI_Score_92%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Raccrypt.GS!MTB
GDataWin32.Trojan.PSE.1XYQCIZ
AhnLab-V3Trojan/Win.MalPE.R442032
Acronissuspicious
McAfeeRDN/Generic Exploit
MAXmalware (ai score=80)
VBA32Malware-Cryptor.Azorult.gen
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R06CH0CIJ21
RisingTrojan.Kryptik!1.D975 (CLASSIC)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMNP!tr
AVGWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/Raccrypt.GS!MTB?

Trojan:Win32/Raccrypt.GS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment