Trojan

Trojan:Win32/Racealer.AA!MTB information

Malware Removal

The Trojan:Win32/Racealer.AA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Racealer.AA!MTB virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Bulgarian
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan:Win32/Racealer.AA!MTB?


File Info:

crc32: B6885D24
md5: 9ac7471c31fffb3c1ccb96a12f472903
name: 9AC7471C31FFFB3C1CCB96A12F472903.mlw
sha1: 26f2779bcc4b1a18e9b4fff68aac9d5fcdad7ce7
sha256: 84113794321f0537639784792578a1e9efa5ce046ee5823fbb4248e78b2ce99e
sha512: b6ac956dc7c72bf0a8a822aa99945d7d218e2cba896edc944ceb674e4aa343d6bebeb536f24184110942e2035b9f5787e38069afdcbe6ec1ac4f87b20471a47f
ssdeep: 24576:e0AjOom/djA/sCJZEa8LkQ4uuTv+M23RGRzQN69dZ0e:e0n5dpC0LD4FTv+z3R2QAF0e
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: namgpiamico.iwa
ProductVersion: 91.40.21.87
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0196 0x03fd

Trojan:Win32/Racealer.AA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056d16b1 )
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.26952
MicroWorld-eScanTrojan.Generic.31114754
ALYacTrojan.Generic.31114754
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.Generic.31114754
K7GWTrojan ( 0056d16b1 )
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNAD
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Danabot.gen
AlibabaTrojanBanker:Win32/Racealer.63a9edb6
Ad-AwareTrojan.Generic.31114754
SophosMal/Generic-R + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34266.iv0@aCJTttaG
TrendMicroTROJ_GEN.R011C0DJO21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.9ac7471c31fffb3c
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.pzilc
Antiy-AVLTrojan/Generic.ASMalwS.34BF561
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Racealer.AA!MTB
GDataTrojan.Generic.31114754
AhnLab-V3Ransomware/Win.STOP.R446694
Acronissuspicious
McAfeePacked-GDV!9AC7471C31FF
MAXmalware (ai score=80)
VBA32BScope.Backdoor.MSIL.NanoBot
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R011C0DJO21
RisingTrojan.Kryptik!1.DA21 (CLASSIC)
YandexTrojan.Kryptik!jaa6devs42g
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Packed.GDV!tr
PandaTrj/GdSda.A

How to remove Trojan:Win32/Racealer.AA!MTB?

Trojan:Win32/Racealer.AA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment