Trojan

How to remove “Trojan:Win32/Raccrypt.GW!MTB”?

Malware Removal

The Trojan:Win32/Raccrypt.GW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccrypt.GW!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Divehi
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan:Win32/Raccrypt.GW!MTB?


File Info:

name: FDAA44E20D9178B55CBF.mlw
path: /opt/CAPEv2/storage/binaries/78621a9ca14f9c393e8f3c28c75fd0672e94aa0f0239acaead0aefcd0f7e0420
crc32: BD77DA5D
md5: fdaa44e20d9178b55cbf586a4fbf4103
sha1: cfe28dcf88b2c8f3d3339a72d838943a05e7bd92
sha256: 78621a9ca14f9c393e8f3c28c75fd0672e94aa0f0239acaead0aefcd0f7e0420
sha512: d549029de8a1d3b794b8fa984f38b7b97cb37ee5a8d9eea6c25ab0e0fa0fcaa601a3651ab70e25e132e6a37d2f9cd0865501093e01d25bdf54ceac5f1dc48393
ssdeep: 6144:4Gkw67eXJEMNz36btOochHoGjq3ZO03bFuc:4k67eZ3Nz36btOochHoGCk03bUc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2745B10BBA1C035F5B316F449B99279B52F7EE1AB2491CB53E52AED86355E0EC3030B
sha3_384: 8173369c0b8fcce3747e26c38f6e23914e08bfd8dd2f70b421d3a05671f0eaa9d19f3b7634bdfd3bb6ab8bccc3e373e6
ep_bytes: 8bff558bece886890000e8110000005d
timestamp: 2020-12-04 15:37:22

Version Info:

0: [No Data]

Trojan:Win32/Raccrypt.GW!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.21780
MicroWorld-eScanTrojan.GenericKD.47766722
FireEyeGeneric.mg.fdaa44e20d9178b5
ALYacTrojan.GenericKD.47766722
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Raccrypt.8fc8b7fd
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f88b2c
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNVO
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBL4Z
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Generic-9918587-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKD.47766722
TencentBackdoor.Win32.Tofsee.16000134
Ad-AwareTrojan.GenericKD.47766722
EmsisoftTrojan.Crypt (A)
TrendMicroTrojan.Win32.SMOKELOADER.YXBL4Z
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
SophosMal/Generic-S
Paloaltogeneric.ml
GDataWin32.Trojan.BSE.554AXK
JiangminTrojanSpy.Stealer.mea
AviraHEUR/AGEN.1210730
Antiy-AVLTrojan/Generic.ASMalwS.34FB7A6
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Raccrypt.GW!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R461540
Acronissuspicious
McAfeePacked-GEE!FDAA44E20D91
MAXmalware (ai score=85)
VBA32Trojan.Convagent
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Obscure!1.A3BB (CLASSIC)
YandexTrojan.Kryptik!FsPxv8K6pns
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Raccrypt.GW!MTB?

Trojan:Win32/Raccrypt.GW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment