Categories: Trojan

Trojan:Win32/Racealer.AA!MTB information

The Trojan:Win32/Racealer.AA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Racealer.AA!MTB virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Bulgarian
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan:Win32/Racealer.AA!MTB?


File Info:

crc32: B6885D24md5: 9ac7471c31fffb3c1ccb96a12f472903name: 9AC7471C31FFFB3C1CCB96A12F472903.mlwsha1: 26f2779bcc4b1a18e9b4fff68aac9d5fcdad7ce7sha256: 84113794321f0537639784792578a1e9efa5ce046ee5823fbb4248e78b2ce99esha512: b6ac956dc7c72bf0a8a822aa99945d7d218e2cba896edc944ceb674e4aa343d6bebeb536f24184110942e2035b9f5787e38069afdcbe6ec1ac4f87b20471a47fssdeep: 24576:e0AjOom/djA/sCJZEa8LkQ4uuTv+M23RGRzQN69dZ0e:e0n5dpC0LD4FTv+z3R2QAF0etype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: namgpiamico.iwaProductVersion: 91.40.21.87Copyright: Copyrighz (C) 2021, fudkagatTranslation: 0x0196 0x03fd

Trojan:Win32/Racealer.AA!MTB also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Trojan ( 0056d16b1 )
Lionic Trojan.Win32.Convagent.4!c
Elastic malicious (high confidence)
DrWeb Trojan.PWS.Stealer.26952
MicroWorld-eScan Trojan.Generic.31114754
ALYac Trojan.Generic.31114754
Cylance Unsafe
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.Generic.31114754
K7GW Trojan ( 0056d16b1 )
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HNAD
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Banker.Win32.Danabot.gen
Alibaba TrojanBanker:Win32/Racealer.63a9edb6
Ad-Aware Trojan.Generic.31114754
Sophos Mal/Generic-R + Troj/Krypt-BO
BitDefenderTheta Gen:NN.ZexaF.34266.iv0@aCJTttaG
TrendMicro TROJ_GEN.R011C0DJO21
McAfee-GW-Edition BehavesLike.Win32.Lockbit.tc
FireEye Generic.mg.9ac7471c31fffb3c
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI – Malicious PE
Avira TR/Crypt.Agent.pzilc
Antiy-AVL Trojan/Generic.ASMalwS.34BF561
Kingsoft Win32.Troj.Banker.(kcloud)
Microsoft Trojan:Win32/Racealer.AA!MTB
GData Trojan.Generic.31114754
AhnLab-V3 Ransomware/Win.STOP.R446694
Acronis suspicious
McAfee Packed-GDV!9AC7471C31FF
MAX malware (ai score=80)
VBA32 BScope.Backdoor.MSIL.NanoBot
Malwarebytes Trojan.MalPack.GS
TrendMicro-HouseCall TROJ_GEN.R011C0DJO21
Rising Trojan.Kryptik!1.DA21 (CLASSIC)
Yandex Trojan.Kryptik!jaa6devs42g
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Packed.GDV!tr
Panda Trj/GdSda.A

How to remove Trojan:Win32/Racealer.AA!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.4183435755 information

The Malware.AI.4183435755 is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Dropped:Application.Generic.3571726 removal instruction

The Dropped:Application.Generic.3571726 is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

What is “Trojan.Generic.35245150”?

The Trojan.Generic.35245150 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Malware.AI.1658877817 removal tips

The Malware.AI.1658877817 is considered dangerous by lots of security experts. When this infection is active,…

29 mins ago

About “Win32/Pronny.JI” infection

The Win32/Pronny.JI is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

Adware.Ursu.14752 removal

The Adware.Ursu.14752 is considered dangerous by lots of security experts. When this infection is active,…

50 mins ago